fix(nav): keep sign-in and sign-up in the header without javascript #241
Inga granskare
Etiketter
Inga etiketter
area/backups
area/ci
area/control-panel
area/identity
area/infra
area/observability
area/payments
area/security
area/storage
area/web
blocked
needs-info
needs-triage
ready-for-implementation
type
bug
type
chore
type
docs
type
epic
type
feature
type
task
wontfix
Ingen milstolpe
Inget projekt
Inga tilldelade
1 deltagare
Notiser
Förfallodatum
Inget förfallodatum satt.
Beroenden
Inga beroenden satta
Referens
bitborg/bitborg-web!241
Läser in…
Hänvisa till i nytt ärende
Ingen beskrivning angiven.
Ta bort grenen "work/154"
Borttagning av en gren är permanent. Även om den borttagna grenen kan fortsätta existera en kort tid innan den faktiskt tas bort, kan det INTE ångras i de flesta fall. Vill du fortsätta?
With JavaScript disabled the header had no "Sign in" and no "Sign up".
secondary-navigation.astrorendered<UserMenu server:defer>with anaria-hiddenplaceholder holding two empty spans, so the served HTML carried no links at all. The same hole opened with JavaScript on whenever the/_server-islands/UserMenurequest failed.The island is kept. Pages set
publiccache headers and the deferred island is what keeps a signed-in user's menu out of a shared cache.Fix: the fallback renders
UserMenuitself with a newanonymousprop that forces the signed-out branch beforeAstro.locals.useris read. No new component, no duplicated markup, and the old hand-tuned placeholder CSS is deleted. Net 45 lines removed, 9 added.Verified against the served HTML, which is the only evidence that counts here:
/carrieshref="/auth/login/""Logga in" andhref="/signup/""Skapa konto" inside<nav class="user-menu" slot="fallback">./en/carries/en/auth/login/"Sign in" and/en/signup/"Sign up"./docs/faq/carries the Swedish pair.cache-controlunchanged:public, max-age=300, s-maxage=3600on/,public, max-age=86400, s-maxage=86400on/docs/faq/. The body under those headers now only ever contains anonymous links.<nav>and the resolved<nav>carry the samedata-astro-cidscope, so the reserved box is generated by the identical component and CSS rather than approximated.user-menu-fallbackno longer appears in the response.pnpm lint,pnpm checkandpnpm test(361 tests) pass.One acceptance bullet is not met, and it may not be reachable
The issue asks for "no anonymous links flash first" for a signed-in user with JavaScript enabled. A
server:deferfallback is in the initial HTML and stays visible until the island resolves, so any fallback with visible content will flash. The previousaria-hiddenplaceholder avoided that flash by carrying nothing, which is exactly the bug this fixes. The two bullets pull against each other.This is untested against a real signed-in session because
/auth/*is still a scaffold. Worth deciding before that lands: accept the flash, or find a mitigation. Everything else in the acceptance list is met.Closes #154
3e994a3b0a5533e1d672