Link a signed-in visitor to the configured continue page #134

Merged
thatguygriff merged 3 commits from feature/registration-logged-in-continue-link into main 2026-07-29 02:18:21 +00:00
3 changed files with 61 additions and 13 deletions
Showing only changes of commit 8a985f04d6 - Show all commits
+1 -1
View File
@@ -132,7 +132,7 @@ recorded in `us_policy_acceptances` with `registration_type = account` and
The block's **After registration** panel picks the page a student continues to once The block's **After registration** panel picks the page a student continues to once
registration finishes, and whether they get there by hand or automatically. registration finishes, and whether they get there by hand or automatically.
- **Sign-in page** (`loginPageId` / `login_page_id`) — the target of the "Sign in to your account" link shown after email confirmation (`?us_confirmed=1|ready`, falling back to the WordPress login screen) and of the "Continue to your account" link an invited student sees on the spot (`?us_registered=invite`; no link at all with no page chosen, since an already-signed-in student has no use for the login screen). - **Sign-in page** (`loginPageId` / `login_page_id`) — the target of the "Sign in to your account" link shown after email confirmation (`?us_confirmed=1|ready`, falling back to the WordPress login screen) and of the "Continue to your account" link every **logged-in** visitor gets (`RegistrationPage::continueLink()`): an invited student who just finished signing up (`?us_registered=invite`), and anyone who simply arrives at the registration page already signed in. Neither gets the WordPress-login-screen fallback — with no page chosen there is no link at all, since sending someone already signed in to the login screen is the same dead end with extra steps.
- **Redirect automatically** (`autoRedirect`, block only) — sends the student to that page instead of showing the link, via `BlockRegistrar::maybeAutoRedirect()` on `template_redirect`. It fires only on those two finished states (`RegistrationPage::isRegistrationComplete()`), so the "check your email" step, a validation error, and an `expired` confirmation link are always shown rather than redirected past. With no page chosen nothing happens — there is deliberately no login-screen fallback for the redirect. See `editor-blocks.md`. - **Redirect automatically** (`autoRedirect`, block only) — sends the student to that page instead of showing the link, via `BlockRegistrar::maybeAutoRedirect()` on `template_redirect`. It fires only on those two finished states (`RegistrationPage::isRegistrationComplete()`), so the "check your email" step, a validation error, and an `expired` confirmation link are always shown rather than redirected past. With no page chosen nothing happens — there is deliberately no login-screen fallback for the redirect. See `editor-blocks.md`.
## Token Redirect ## Token Redirect
+29 -12
View File
@@ -65,24 +65,21 @@ class RegistrationPage {
$registered = sanitize_key( Val::string( wp_unslash( $_GET['us_registered'] ?? '' ) ) ); $registered = sanitize_key( Val::string( wp_unslash( $_GET['us_registered'] ?? '' ) ) );
if ( is_user_logged_in() ) { if ( is_user_logged_in() ) {
if ( self::RESULT_INVITE === $registered ) { // Both logged-in outcomes are dead ends without somewhere to go next,
// An invited student is done the moment they land here logged in, // so both offer the same "continue" link to the configured page.
// so this is where their "continue" link belongs. The sign-in-page wp_enqueue_style( 'us-scheduler' );
// fallback is deliberately not used: pointing someone who is $link = $this->continueLink( $atts );
// already signed in at the login screen helps nobody.
$continue = $this->continueUrl( $this->successPageId( $atts ) );
$link = null === $continue
? ''
: '<p><a href="' . esc_url( $continue ) . '">'
. esc_html__( 'Continue to your account', 'unsupervised-schedular' )
. '</a></p>';
if ( self::RESULT_INVITE === $registered ) {
// An invited student is done the moment they land here logged in.
return '<div class="us-register-form"><p class="us-success">' return '<div class="us-register-form"><p class="us-success">'
. esc_html__( 'Your account has been created and you are now logged in.', 'unsupervised-schedular' ) . esc_html__( 'Your account has been created and you are now logged in.', 'unsupervised-schedular' )
. '</p>' . $link . '</div>'; . '</p>' . $link . '</div>';
} }
return '<p>' . esc_html__( 'You already have an account and are logged in.', 'unsupervised-schedular' ) . '</p>'; return '<div class="us-register-form"><p>'
. esc_html__( 'You already have an account and are logged in.', 'unsupervised-schedular' )
. '</p>' . $link . '</div>';
} }
// phpcs:ignore WordPress.Security.NonceVerification.Recommended -- token identifies the invite; the form submit is nonce-checked in maybeHandleSubmit. // phpcs:ignore WordPress.Security.NonceVerification.Recommended -- token identifies the invite; the form submit is nonce-checked in maybeHandleSubmit.
@@ -353,6 +350,26 @@ class RegistrationPage {
return $this->continueUrl( $loginPageId ) ?? wp_login_url(); return $this->continueUrl( $loginPageId ) ?? wp_login_url();
} }
/**
* The "continue to your account" paragraph shown to a logged-in visitor, or
* an empty string when no destination page is configured.
*
* The sign-in-page fallback {@see loginUrl()} applies is deliberately not
* used here: pointing someone who is already signed in at the login screen is
* the same dead end with extra steps, so no link is better than that one.
*
* @param array<int|string, mixed> $atts
*/
private function continueLink( array $atts ): string {
$continue = $this->continueUrl( $this->successPageId( $atts ) );
return null === $continue
? ''
: '<p><a href="' . esc_url( $continue ) . '">'
. esc_html__( 'Continue to your account', 'unsupervised-schedular' )
. '</a></p>';
}
/** /**
* The chosen post-registration page's URL, or null when none is configured * The chosen post-registration page's URL, or null when none is configured
* (or it has since been deleted). Unlike {@see loginUrl()} this has no * (or it has since been deleted). Unlike {@see loginUrl()} this has no
+31
View File
@@ -504,6 +504,37 @@ class RegistrationPageTest extends TestCase
self::assertStringContainsString('href="http://home.test/welcome/"', $html); self::assertStringContainsString('href="http://home.test/welcome/"', $html);
} }
public function testAlreadyLoggedInVisitorIsLinkedToTheChosenPage(): void
{
// No us_registered flag: someone who simply happens to be signed in and
// lands on the registration page. They still need a way onward.
Functions\when('is_user_logged_in')->justReturn(true);
Functions\when('sanitize_key')->alias(static fn ($v) => strtolower((string) $v));
Functions\expect('get_permalink')->once()->with(4)->andReturn('http://home.test/welcome/');
$html = $this->ctx['page']->render([ 'loginPageId' => 4 ]);
self::assertStringContainsString('already have an account', $html);
self::assertStringContainsString('href="http://home.test/welcome/"', $html);
// Not the just-registered message — that branch needs its own flag.
self::assertStringNotContainsString('us-success', $html);
}
public function testAlreadyLoggedInVisitorGetsNoLinkWithoutAChosenPage(): void
{
Functions\when('is_user_logged_in')->justReturn(true);
Functions\when('sanitize_key')->alias(static fn ($v) => strtolower((string) $v));
Functions\when('get_permalink')->justReturn(false);
// A deleted page resolves to false, which must not become a broken link.
$html = $this->ctx['page']->render([ 'loginPageId' => 4 ]);
self::assertStringContainsString('already have an account', $html);
self::assertStringNotContainsString('<a href', $html);
self::assertStringNotContainsString('<a href', $this->ctx['page']->render([]));
}
public function testContinueUrlIsNullWithoutAResolvablePage(): void public function testContinueUrlIsNullWithoutAResolvablePage(): void
{ {
Functions\when('get_permalink')->justReturn(false); Functions\when('get_permalink')->justReturn(false);