fix: guest reload page to accessed MemberDashboard

This commit is contained in:
2026-06-22 12:45:29 +07:00
parent 01d6d7439f
commit 29c19c6372
16 changed files with 33 additions and 19 deletions
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
File diff suppressed because one or more lines are too long
+1 -1
View File
@@ -6,7 +6,7 @@
<link rel="icon" type="image/x-icon" href="/favicon.ico" />
<script src="https://accounts.google.com/gsi/client" async defer></script>
<title>Travel Planner</title>
<script type="module" crossorigin src="/assets/index-DtsqetSG.js"></script>
<script type="module" crossorigin src="/assets/index-BwN9EkVY.js"></script>
<link rel="stylesheet" crossorigin href="/assets/index-sqDjZKsa.css">
</head>
<body>
+17 -5
View File
@@ -68,13 +68,12 @@ function App() {
} else if (viewTourId) {
setCurrentPage('tourDetail');
} else {
// Check if only guest token exists (no real login)
const isGuestOnly = guestToken && !token;
if (isGuestOnly) {
// Guest user trying to access dashboard - redirect to landing
// CRITICAL: Check for guest token FIRST - guests should NEVER access dashboard
// regardless of whether they also have other tokens
if (guestToken) {
setCurrentPage('landing');
} else if (loggedInUser) {
// Real authenticated user
// Real authenticated user (no guest token)
if (loggedInUser.isAdmin) {
setCurrentPage('admin');
} else {
@@ -229,6 +228,19 @@ function App() {
}
if (currentPage === 'dashboard') {
// SECURITY: Prevent any guest from accessing dashboard
const guestToken = localStorage.getItem('guest_token');
if (guestToken) {
console.warn('[App] Guest user attempted to access dashboard - forcing redirect to landing');
setCurrentPage('landing');
return (
<LandingPage
onLoginSuccess={handleLoginSuccess}
onGoToSignup={() => setCurrentPage('signup')}
/>
);
}
return (
<MemberDashboard
user={user}
+9 -7
View File
@@ -142,19 +142,21 @@ export const AddPhotoModal: React.FC<AddPhotoModalProps> = ({ isOpen, onClose, t
setSelectedFiles([]);
setPreviews([]);
// For public users: redirect to landing page after upload
// For authenticated users: refresh tour data and close modal
// Refresh tour data (applies to both authenticated and public users)
// This ensures newly uploaded photos appear immediately without requiring a page reload
fetchTour(tourId);
if (onSuccess) onSuccess();
// For public users: redirect to landing page after upload (after data refresh)
// For authenticated users: close modal and show updated tour
if (isPublicView) {
onClose();
// Give time for notification to show before redirecting
// Set flag so App.tsx knows to redirect to landing even if user is logged in
// Give time for tour data to refresh before redirecting
setTimeout(() => {
localStorage.setItem('fromPublicUpload', 'true');
window.location.href = '/';
}, 1000);
}, 1500);
} else {
fetchTour(tourId);
if (onSuccess) onSuccess();
onClose();
}
} catch (error) {