Revert the / and /Events public routes

Rolls src/App.jsx back to the state at 015da4e, keeping only the public
/LandingPage route. Reverts:

  878ebca  Open /Events without a Base44 login
  cbc9357  Show the landing page at / for signed-out visitors

/ returns to rendering Dashboard behind the auth gate, and /Events returns to
requiring a login rather than serving an empty shell.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
2026-08-17 20:55:08 +05:30
parent 878ebca143
commit 0ddbd35c8b

View File

@@ -50,56 +50,32 @@ const LayoutWrapper = ({ children, currentPageName }) => Layout ?
<Layout currentPageName={currentPageName}>{children}</Layout> <Layout currentPageName={currentPageName}>{children}</Layout>
: <>{children}</>; : <>{children}</>;
// Paths that render for anyone, signed in or not, skipping the auth gate below. // Routes that render for anyone, signed in or not. LandingPage is pure marketing
// // markup — it reads no entities and never touches useAuth — so the only thing the
// LandingPage is genuinely public: pure marketing markup, no entity reads, so it // auth gate ever did for it was bounce visitors to a Google login before they
// needs nothing from Base44. Events is not — it lists Event, Staff and VendorRate, // could read what the product is. Its CTAs point at /Dashboard, which is still
// all of which stay behind Base44 auth. Opening the route only removes the login // gated, so signing in stays one click away.
// redirect; a signed-out visitor gets the page shell with empty lists, because const PUBLIC_ROUTES = new Set(['/LandingPage']);
// skipping the gate cannot grant data the backend still refuses to serve.
const PUBLIC_ROUTES = new Map([
['/LandingPage', LandingPage],
['/Events', Pages['Events']],
]);
const getPublicPage = (pathname) => { const isPublicRoute = (pathname) => {
// Tolerate a trailing slash, and compare case-insensitively so /events lands on // Tolerate a trailing slash so /LandingPage/ isn't quietly sent to login.
// the same page as /Events — that is how React Router already matches the gated const normalized = pathname.length > 1 ? pathname.replace(/\/+$/, '') : pathname;
// routes, and a mismatch here would send one casing to login and not the other. return PUBLIC_ROUTES.has(normalized);
const trimmed = pathname.length > 1 ? pathname.replace(/\/+$/, '') : pathname;
const normalized = trimmed.toLowerCase();
for (const [path, Page] of PUBLIC_ROUTES) {
if (path.toLowerCase() === normalized) {
return Page;
}
}
return null;
}; };
// The bare domain is the front door, so it can't be allowed to bounce anonymous
// visitors to Google — signed out it shows the marketing page, signed in it shows
// the dashboard as before.
const ROOT_PATH = '/';
const AuthenticatedApp = () => { const AuthenticatedApp = () => {
const { isLoadingAuth, isLoadingPublicSettings, authError, isAuthenticated, navigateToLogin } = useAuth(); const { isLoadingAuth, isLoadingPublicSettings, authError, isAuthenticated, navigateToLogin } = useAuth();
const location = useLocation(); const location = useLocation();
// Ahead of both gates below. The spinner would stall these pages on a network // Ahead of both gates below. The spinner would stall this page on a network
// round-trip, and the auth gate would redirect away from them — either one // round-trip it has no use for, and the auth gate would redirect away from it —
// defeats the point of a public route. Rendered bare, without LayoutWrapper, // either one defeats the point of a public page.
// so the nav chrome doesn't fire its own authenticated queries here. if (isPublicRoute(location.pathname)) {
const PublicPage = getPublicPage(location.pathname); return (
if (PublicPage) { <Routes>
return <PublicPage />; <Route path="/LandingPage" element={<LandingPage />} />
} </Routes>
);
// Decided on the token rather than on the resolved auth state, so it settles
// synchronously: a visitor with no session gets the marketing page on the first
// paint instead of watching a spinner for a bootstrap request whose only
// possible outcome, for them, is a redirect away.
if (location.pathname === ROOT_PATH && !appParams.token) {
return <LandingPage />;
} }
// Show loading spinner while checking app public settings or auth // Show loading spinner while checking app public settings or auth
@@ -116,12 +92,6 @@ const AuthenticatedApp = () => {
if (authError.type === 'user_not_registered') { if (authError.type === 'user_not_registered') {
return <UserNotRegisteredError />; return <UserNotRegisteredError />;
} else if (authError.type === 'auth_required') { } else if (authError.type === 'auth_required') {
// Reaching here on the root path means a token existed but is no longer
// good — expired, revoked, or for another app. Treating that as signed out
// keeps the front door open instead of trapping it in a login redirect.
if (location.pathname === ROOT_PATH) {
return <LandingPage />;
}
// Redirect to login automatically // Redirect to login automatically
navigateToLogin(); navigateToLogin();
return null; return null;