Index: includes/common.inc
===================================================================
RCS file: /cvs/drupal/drupal/includes/common.inc,v
retrieving revision 1.1263
diff -u -p -r1.1263 common.inc
--- includes/common.inc	22 Nov 2010 04:33:02 -0000	1.1263
+++ includes/common.inc	22 Nov 2010 10:20:20 -0000
@@ -510,7 +510,7 @@ function drupal_get_destination() {
     $destination = array('destination' => $_GET['destination']);
   }
   else {
-    $path = $_GET['q'];
+    $path = request_path() == '' ? '' : $_GET['q'];
     $query = drupal_http_build_query(drupal_get_query_parameters());
     if ($query != '') {
       $path .= '?' . $query;
Index: modules/simpletest/tests/form.test
===================================================================
RCS file: /cvs/drupal/drupal/modules/simpletest/tests/form.test,v
retrieving revision 1.76
diff -u -p -r1.76 form.test
--- modules/simpletest/tests/form.test	21 Nov 2010 10:14:25 -0000	1.76
+++ modules/simpletest/tests/form.test	22 Nov 2010 10:20:21 -0000
@@ -1510,3 +1510,90 @@ class FormCheckboxTestCase extends Drupa
     }
   }
 }
+
+/**
+ * Tests form submission destination URL.
+ */
+class FormDestinationTestCase extends DrupalWebTestCase {
+
+  public static function getInfo() {
+    return array(
+      'name' => 'Form destination',
+      'description' => 'Tests that the user is sent to the proper URL on form submit.',
+      'group' => 'Form API',
+    );
+  }
+
+  function setUp() {
+    parent::setUp('block', 'user');
+    
+    // Setup users and permissions.
+    $permissions = array('access content', 'access user profiles');
+    user_role_grant_permissions(DRUPAL_ANONYMOUS_RID, $permissions);
+    $this->web_user = $this->drupalCreateUser($permissions);
+    $permissions[]= 'administer blocks';
+    $this->admin_user = $this->drupalCreateUser($permissions);
+
+    // Add the login block to all pages.
+    $this->drupalLogin($this->admin_user);
+    $this->drupalPost('admin/structure/block', array('blocks[user_login][region]' => 'sidebar_first'), t('Save blocks'));
+    $this->assertText(t('The block settings have been updated.'), t('Block successfully moved to %region_name region.', array( '%region_name' => 'sidebar_first')));
+  }
+
+  /**
+   * Test with drupal_get_destination() and "destination" URL query parameter.
+   */
+  function testDestination () {
+    $destinations = array(variable_get('site_frontpage', 'node'), '<front>', 'user/1');
+    foreach ($destinations as $destination) {
+      $this->drupalLogout();
+      $_GET['destination'] = $destination;
+      $edit = array(
+        'name' => $this->web_user->name,
+        'pass' => $this->web_user->pass_raw,
+      );
+      drupal_static_reset('drupal_get_destination');
+      $this->drupalPost('user/login', $edit, t('Log in'), array('query' => drupal_get_destination()));
+      $this->assertLink(t('Log out'), 0, t('User %name successfully logged in.', array('%name' => $this->web_user->name)));
+      $this->assertUrl($destination, array(), t('Login form POSTed to user/login?destination=%destination has an ending URL of %destination', array('%destination' => $destination)));
+    }
+  }
+
+  /**
+   * Test with drupal_get_destination and no "destination" URL query parameter.
+   */
+  function testNullDestination () {
+    $paths = array(variable_get('site_frontpage', 'node'), '<front>', 'user/1');
+    foreach ($paths as $path) {
+      $this->drupalLogout();
+      $edit = array(
+        'name' => $this->web_user->name,
+        'pass' => $this->web_user->pass_raw,
+      );
+      $_GET = array('q' => $path);
+      drupal_static_reset('drupal_get_destination');
+      $url_query = drupal_get_destination();
+      $this->drupalPost($path, $edit, t('Log in'), array('query' => $url_query));
+      $this->assertLink(t('Log out'), 0, t('User %name successfully logged in.', array('%name' => $this->web_user->name)));
+      $this->assertUrl($path, array(), t('Login block form POSTed to %path?destination=%destination has an ending URL of %path', array('%path' => $path, '%destination' => $url_query['destination'])));
+    }
+  }
+
+  /**
+   * Test without drupal_get_destination().
+   */
+  function testWithoutDestination () {
+    $paths = array(variable_get('site_frontpage', 'node'), '<front>', 'user/1');
+    foreach ($paths as $path) {
+      $this->drupalLogout();
+      $edit = array(
+        'name' => $this->web_user->name,
+        'pass' => $this->web_user->pass_raw,
+      );
+      $this->drupalPost($path, $edit, t('Log in'));
+      $this->assertLink(t('Log out'), 0, t('User %name successfully logged in.', array('%name' => $this->web_user->name)));
+      $this->assertUrl($path, array(), t('Login block form POSTed to %path has an ending URL of %path', array('%path' => $path)));
+    }
+  }
+
+}
Index: modules/user/user.module
===================================================================
RCS file: /cvs/drupal/drupal/modules/user/user.module,v
retrieving revision 1.1220
diff -u -p -r1.1220 user.module
--- modules/user/user.module	21 Nov 2010 18:52:05 -0000	1.1220
+++ modules/user/user.module	22 Nov 2010 10:20:22 -0000
@@ -1233,7 +1233,7 @@ function user_user_categories() {
 }
 
 function user_login_block($form) {
-  $form['#action'] = url($_GET['q'], array('query' => drupal_get_destination()));
+  $form['#action'] = url(request_path(), array('query' => drupal_get_destination()));
   $form['#id'] = 'user-login-form';
   $form['#validate'] = user_login_default_validators();
   $form['#submit'][] = 'user_login_submit';
