fix: language switcher works — GET route, simple links, forced RO fallback
The previous POST-based switcher failed silently: CSRF token check
returned 419 when clicking, and the session never persisted.
Root causes:
- POST requires @csrf token, but the test path fetched pages that had
no matching form so the token in the DOM didn't match the session
- Some tenant subdomains had SESSION_DOMAIN scoped differently, so
the cookie set by POST didn't come back on the follow-up GET
- Prod .env had APP_LOCALE=en which took precedence over the config
edit; when session had no locale yet, defaulted to English
Fixes:
1. Route accepts BOTH GET and POST via Route::match(['get', 'post']).
Setting your own language is not a security concern — GET is fine.
2. Route explicitly calls $request->session()->save() before redirect,
forcing the session store to write before the redirect fires.
Also honors ?redirect=<url> query so the user lands back on their
original page rather than referer-guessing.
3. lang-switcher partial rewrites to plain <a href> tags (no @csrf,
no forms). Each link points at /locale/{code}?redirect={current-url}
so the switch happens in a single hop with predictable target.
4. SetLocale middleware hard-codes 'ro' as the ultimate fallback,
ignoring config/env. The Romanian portal is the default
client-facing surface; if a client has no session locale set and
no user account, they see Romanian (safer than English which has
no portal translations).
Suite: 306 passed (853 assertions). Unchanged.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -44,6 +44,8 @@ class SetLocale
|
|||||||
return $tenantLang;
|
return $tenantLang;
|
||||||
}
|
}
|
||||||
|
|
||||||
return config('app.locale', 'ro');
|
// Hard-code fallback la 'ro' — indiferent de APP_LOCALE din env,
|
||||||
|
// portal-ul client-facing e livrat cu RO ca implicit safe (RU disponibil via switcher).
|
||||||
|
return 'ro';
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,45 +1,37 @@
|
|||||||
@php
|
@php
|
||||||
$locales = [
|
$locales = [
|
||||||
'ro' => ['label' => 'RO', 'full' => 'Română', 'flag' => '🇷🇴'],
|
'ro' => ['label' => 'RO', 'full' => 'Română'],
|
||||||
'ru' => ['label' => 'RU', 'full' => 'Русский', 'flag' => '🇷🇺'],
|
'ru' => ['label' => 'RU', 'full' => 'Русский'],
|
||||||
'en' => ['label' => 'EN', 'full' => 'English', 'flag' => '🇬🇧'],
|
'en' => ['label' => 'EN', 'full' => 'English'],
|
||||||
];
|
];
|
||||||
$current = app()->getLocale();
|
$current = app()->getLocale();
|
||||||
// Default: dark-glass style suits colored header (shop, tracking). Override via $style param.
|
|
||||||
$style = $style ?? 'chip';
|
$style = $style ?? 'chip';
|
||||||
|
$back = urlencode(request()->fullUrl());
|
||||||
@endphp
|
@endphp
|
||||||
|
|
||||||
@if ($style === 'chip')
|
@if ($style === 'chip')
|
||||||
<div style="display:inline-flex;align-items:center;gap:2px;background:rgba(255,255,255,.15);border-radius:8px;padding:2px;font-size:12px;">
|
<div style="display:inline-flex;align-items:center;gap:2px;background:rgba(255,255,255,.15);border-radius:8px;padding:2px;font-size:12px;">
|
||||||
@foreach ($locales as $code => $meta)
|
@foreach ($locales as $code => $meta)
|
||||||
<form method="POST" action="{{ url('/locale/' . $code) }}" style="margin:0;">
|
<a href="{{ url('/locale/' . $code . '?redirect=' . $back) }}" title="{{ $meta['full'] }}"
|
||||||
@csrf
|
|
||||||
<input type="hidden" name="_redirect_back" value="1">
|
|
||||||
<button type="submit" title="{{ $meta['full'] }}"
|
|
||||||
style="background:{{ $code === $current ? 'rgba(255,255,255,.95)' : 'transparent' }};
|
style="background:{{ $code === $current ? 'rgba(255,255,255,.95)' : 'transparent' }};
|
||||||
color:{{ $code === $current ? '#1f2937' : '#fff' }};
|
color:{{ $code === $current ? '#1f2937' : '#fff' }};
|
||||||
border:0;padding:5px 10px;border-radius:6px;cursor:pointer;font-size:12px;font-weight:600;
|
padding:5px 10px;border-radius:6px;font-size:12px;font-weight:600;
|
||||||
font-family:inherit;">
|
text-decoration:none;display:inline-block;">
|
||||||
{{ $meta['label'] }}
|
{{ $meta['label'] }}
|
||||||
</button>
|
</a>
|
||||||
</form>
|
|
||||||
@endforeach
|
@endforeach
|
||||||
</div>
|
</div>
|
||||||
@else
|
@else
|
||||||
{{-- light style for pale backgrounds (invitations, auth pages) --}}
|
|
||||||
<div style="display:inline-flex;gap:4px;font-size:12px;">
|
<div style="display:inline-flex;gap:4px;font-size:12px;">
|
||||||
@foreach ($locales as $code => $meta)
|
@foreach ($locales as $code => $meta)
|
||||||
<form method="POST" action="{{ url('/locale/' . $code) }}" style="margin:0;">
|
<a href="{{ url('/locale/' . $code . '?redirect=' . $back) }}" title="{{ $meta['full'] }}"
|
||||||
@csrf
|
|
||||||
<button type="submit" title="{{ $meta['full'] }}"
|
|
||||||
style="background:{{ $code === $current ? '#3b82f6' : 'transparent' }};
|
style="background:{{ $code === $current ? '#3b82f6' : 'transparent' }};
|
||||||
color:{{ $code === $current ? '#fff' : '#4b5563' }};
|
color:{{ $code === $current ? '#fff' : '#4b5563' }};
|
||||||
border:1px solid {{ $code === $current ? '#3b82f6' : '#d1d5db' }};
|
border:1px solid {{ $code === $current ? '#3b82f6' : '#d1d5db' }};
|
||||||
padding:4px 10px;border-radius:6px;cursor:pointer;font-size:12px;font-weight:600;
|
padding:4px 10px;border-radius:6px;font-size:12px;font-weight:600;
|
||||||
font-family:inherit;">
|
text-decoration:none;display:inline-block;">
|
||||||
{{ $meta['label'] }}
|
{{ $meta['label'] }}
|
||||||
</button>
|
</a>
|
||||||
</form>
|
|
||||||
@endforeach
|
@endforeach
|
||||||
</div>
|
</div>
|
||||||
@endif
|
@endif
|
||||||
|
|||||||
+10
-3
@@ -129,16 +129,23 @@ Route::post('/t/{token}/approve/{kind}/{lineToken}', [\App\Http\Controllers\Trac
|
|||||||
->where('lineToken', '[A-Za-z0-9]{16,32}')
|
->where('lineToken', '[A-Za-z0-9]{16,32}')
|
||||||
->name('tracking.approve');
|
->name('tracking.approve');
|
||||||
|
|
||||||
// Locale switch — POST /locale/{lang} sets session and persists to user.
|
// Locale switch — GET/POST /locale/{lang} sets session and persists to user.
|
||||||
Route::post('/locale/{lang}', function (Request $request, string $lang) {
|
// GET intentionally supported so simple <a> links (no CSRF token) work; anyone
|
||||||
|
// setting their own language is not a security concern.
|
||||||
|
Route::match(['get', 'post'], '/locale/{lang}', function (Request $request, string $lang) {
|
||||||
if (! in_array($lang, ['ro', 'ru', 'en'], true)) {
|
if (! in_array($lang, ['ro', 'ru', 'en'], true)) {
|
||||||
abort(404);
|
abort(404);
|
||||||
}
|
}
|
||||||
$request->session()->put('locale', $lang);
|
$request->session()->put('locale', $lang);
|
||||||
|
$request->session()->save(); // force write to session store before redirecting
|
||||||
if ($u = $request->user()) {
|
if ($u = $request->user()) {
|
||||||
$u->forceFill(['locale' => $lang])->saveQuietly();
|
$u->forceFill(['locale' => $lang])->saveQuietly();
|
||||||
}
|
}
|
||||||
return back();
|
// Prefer explicit redirect from query, otherwise fall back to referer / homepage
|
||||||
|
$to = $request->query('redirect')
|
||||||
|
?: $request->header('referer')
|
||||||
|
?: '/';
|
||||||
|
return redirect($to);
|
||||||
})->name('locale.switch');
|
})->name('locale.switch');
|
||||||
|
|
||||||
// PWA — manifest pentru panou central (service.mir.md).
|
// PWA — manifest pentru panou central (service.mir.md).
|
||||||
|
|||||||
Reference in New Issue
Block a user