footer sign-in link; sign-in, invite and reset land on the console

One quiet 'Sign in · leaders & families' in the public footer, after the
site's own links and before Join, which stays the only call to action.
Nothing on the public site pointed at /login before; the only ways in
were typing the URL or an invite link. A fresh sign-in, an accepted
invite and a used reset link now land on /leaders/, which sends a
member on to Family and a leader to Summary. tests/smoke_identity.py
123 -> 125.
This commit is contained in:
2026-09-04 20:39:45 -04:00
parent 752fb08d73
commit 77dd250436
4 changed files with 19 additions and 11 deletions
+1 -1
View File
@@ -692,7 +692,7 @@ def consume_invite(token, full_name, password, preferred_name=None, phone=None,
# Rows, not signed cookies. A leader stepping down has to be revocable now
# rather than at token expiry, and "sign out everywhere" has to be possible.
def safe_next(value, default="/account"):
def safe_next(value, default="/leaders/"):
"""Where to send someone after login. Only a same-origin relative path
survives: a single leading slash, no scheme, no protocol-relative `//`,
no backslash or control character that a browser might normalise into