From d3cce35fc4dde829548df3178bc20534ec4980d0 Mon Sep 17 00:00:00 2001 From: Quentin Gliech Date: Fri, 25 Sep 2026 17:16:32 +0200 Subject: [PATCH] Explain the `/register/password` redirect and reword a registration test comment --- crates/handlers/src/lib.rs | 2 +- crates/handlers/src/views/register/mod.rs | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/crates/handlers/src/lib.rs b/crates/handlers/src/lib.rs index 63c729529..bed3c99f0 100644 --- a/crates/handlers/src/lib.rs +++ b/crates/handlers/src/lib.rs @@ -400,7 +400,7 @@ where mas_router::Register::route(), get(self::views::register::get).post(self::views::register::post), ) - // XXX: hard-coded redirect from /register/password to /register + // Keeps links to the former password registration page working .route( "/register/password", redirect_to(mas_router::Register::route()), diff --git a/crates/handlers/src/views/register/mod.rs b/crates/handlers/src/views/register/mod.rs index 2a16fed6a..70d2b2b68 100644 --- a/crates/handlers/src/views/register/mod.rs +++ b/crates/handlers/src/views/register/mod.rs @@ -621,7 +621,7 @@ mod tests { .expect("the upstream sessions cookie should be set"); assert!(sessions[0].get("username").is_none()); - // The password path sees it whole, and the policy rejects it + // Password registration keeps the overlong username, and the policy rejects it let request = cookies.with_cookies(Request::post("/register").form(serde_json::json!({ "csrf": csrf_token, "username": username,