I3eka commented on code in PR #44456:
URL: https://github.com/apache/superset/pull/44456#discussion_r4059710485


##########
superset-frontend/src/pages/Home/index.tsx:
##########
@@ -448,4 +450,17 @@ function Welcome({ user, addDangerToast }: WelcomeProps) {
   );
 }
 
-export default withToasts(Welcome);
+function WelcomePage(props: WelcomeProps) {
+  const hasUserId = Boolean(props.user?.userId);
+
+  useEffect(() => {
+    if (!hasUserId) {
+      // SPA navigation can bypass the welcome view's server-side login check.
+      redirect(RoutePaths.HOME);
+    }
+  }, [hasUserId]);
+
+  return hasUserId ? <Welcome {...props} /> : null;

Review Comment:
   Fixed in 6594bdc634. Only the page wrapper's `user` prop is optional; the 
personalized `Welcome` component still requires a user, and the runtime guard 
narrows it before rendering. No non-null assertion or broader relaxation of the 
inner props was added.
   
   Re-ran the Home desktop/mobile, navigation helper, and routes suites: **107 
passed across 4 suites**. All applicable pre-commit checks passed, including 
TypeScript, linting and formatting.
   
   I also checked the route-string suggestion in the review summary. I'm 
keeping the literal `/welcome/` assertion: it independently checks the server 
route contract, and changing the production route constant without updating 
that contract would fail this test rather than silently diverge.
   



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to