|
|
|
|
|
by michaelt
973 days ago
|
|
It's kinda normal that you'd want to let a user log in and return them to the page they were at. For example, if you're making a shopping website and a user asks to put something in their basket and you send them to log in, you'd want to return them to the item they were about to buy, not dump them back at the homepage. What's the proper way of doing this, without "abusing state" ? |
|
Ideally you would 'consume' the token before redirecting, and not send it to the second redirecting url.