Fix 500 on failed login by encoding the redirect parameters

After a rejected login the site redirects back to /login carrying the API's
error message in the query string. That message is Persian, and HTTP header
values must be ASCII, so Kestrel threw InvalidOperationException and the user
got an error page instead of the login form with the reason for the failure.
Encode both the path and the message.

Not noticed before because IIS Express tolerates the non-ASCII Location header;
it surfaces as soon as the site is run on Kestrel.
This commit is contained in:
Ehsan Mohandesi 2026-09-13 22:16:18 -05:00
parent 7f76c5c9c1
commit e7fbc6559d

View File

@ -170,7 +170,9 @@ namespace GanjooRazor.Pages
if (!response.IsSuccessStatusCode)
{
return Redirect($"/login?redirect={Request.Path}&error={JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync())}");
// the API's error text is Persian and Location headers must be ASCII, so it is encoded
string loginError = JsonConvert.DeserializeObject<string>(await response.Content.ReadAsStringAsync());
return Redirect($"/login?redirect={Uri.EscapeDataString(Request.Path)}&error={Uri.EscapeDataString(loginError ?? "")}");
}
LoggedOnUserModelEx loggedOnUser = JsonConvert.DeserializeObject<LoggedOnUserModelEx>(await response.Content.ReadAsStringAsync());