Fix session-expiry redirect breaking standalone PWA out of its shell

Two compounding issues were kicking installed/standalone maintenance
PWA sessions out into the portal's framed browser view on re-login:

- manifest scope was the app's own base path instead of "/", so any
  same-origin navigation outside it (like the old redirect to
  /login) dropped the standalone window into a regular browser tab
- AuthGate unconditionally hard-navigated window.top to the central
  /login on session expiry, even when not embedded in the portal
  iframe, which is exactly the navigation the doc warns against

AuthGate now only bounces to central login when actually embedded
(and passes ?from= so it returns to this app afterwards); standalone
or directly-opened tabs get an in-app login form and never navigate
away. Also wired up the previously-dead inactivity auto-logout timer
(disabled for installed PWAs, configurable per device otherwise).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
jtricerolph 2026-07-24 17:06:55 +00:00
parent 9f402bd2d9
commit 3740727950
2 changed files with 126 additions and 12 deletions

View file

@ -15,7 +15,7 @@ export default defineConfig({
name: 'Maintenance',
short_name: 'Maint.',
start_url: '/maintenance/',
scope: '/maintenance/',
scope: '/',
display: 'standalone',
theme_color: '#b45309',
background_color: '#b45309',