From e7fbc6559d364941f6aa1ecd7c78ce27c28172e2 Mon Sep 17 00:00:00 2001 From: Ehsan Mohandesi Date: Sun, 13 Sep 2026 22:16:18 -0500 Subject: [PATCH] Fix 500 on failed login by encoding the redirect parameters After a rejected login the site redirects back to /login carrying the API's error message in the query string. That message is Persian, and HTTP header values must be ASCII, so Kestrel threw InvalidOperationException and the user got an error page instead of the login form with the reason for the failure. Encode both the path and the message. Not noticed before because IIS Express tolerates the non-ASCII Location header; it surfaces as soon as the site is run on Kestrel. --- GanjooRazor/Pages/LoginPartialEnabledPageModel.cs | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/GanjooRazor/Pages/LoginPartialEnabledPageModel.cs b/GanjooRazor/Pages/LoginPartialEnabledPageModel.cs index d2cef21d..f9283d11 100644 --- a/GanjooRazor/Pages/LoginPartialEnabledPageModel.cs +++ b/GanjooRazor/Pages/LoginPartialEnabledPageModel.cs @@ -170,7 +170,9 @@ namespace GanjooRazor.Pages if (!response.IsSuccessStatusCode) { - return Redirect($"/login?redirect={Request.Path}&error={JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync())}"); + // the API's error text is Persian and Location headers must be ASCII, so it is encoded + string loginError = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync()); + return Redirect($"/login?redirect={Uri.EscapeDataString(Request.Path)}&error={Uri.EscapeDataString(loginError ?? "")}"); } LoggedOnUserModelEx loggedOnUser = JsonConvert.DeserializeObject(await response.Content.ReadAsStringAsync());