createRedirectChain remembers the page a user wanted before they were sent to sign in, lets you queue extra steps (verify email, onboarding), and tells you where to send them next. State lives in one short-lived cookie, so it works on any runtime that has Web Request and Response.
redirects.ts
push returns a Set-Cookie value, so send it on the response that moves the user to the next step. The same helpers are also exported from @glinr/theauth.
API
Options
If the captured page is in
excludePaths, the chain falls back to defaultPath, so users never bounce back to the sign-in page.
Security notes
Entries created from a URL keep only its path, query and hash, never the origin. The cookie itself is base64url JSON and is not signed, so a user can edit it. Before you redirect to theurl that pop or peek returns, check that it starts with a single / (and not // or /\), and validate any redirectTo value you accept from users before passing it to createEntry or push.