Hide app landing after session restore

Remove the /app landing overlay once `whoami` confirms the user is authenticated, even if the server rendered the page as anonymous because the session cookie was missing. This prevents the overlay from covering the email, phone, and card verification gates during localStorage-based session restores.
This commit is contained in:
jelveh
2026-08-31 20:07:47 -07:00
parent a27852de0a
commit 22c3316109
+12
View File
@@ -1963,6 +1963,18 @@ window.initgui = async function (options) {
}
// update local user data
if (whoami) {
// The server renders the /app/<name> landing overlay only for
// requests it saw as anonymous, but its only signal is the session
// cookie — which can be gone (e.g. browser restart) while the
// localStorage session is still valid. whoami just proved this is
// a logged-in user, so drop the overlay. This must happen before
// the verification gates below: the overlay's max z-index would
// cover them.
const app_landing = document.getElementById('appLanding');
if (app_landing) {
app_landing.classList.add('fade-out');
setTimeout(() => app_landing.remove(), 600);
}
// Verification gates run in order: email → phone (SMS) → card,
// matching the server-side order in assertVerifiedAccount.
if (whoami.requires_email_confirmation) {