fix(Oauth): validate client IDs against resolvePublicCred to correctly togg… - #3206
Merged
diegosouzapw merged 2 commits intoJun 5, 2026
Merged
Conversation
…le OAuth redirect URI overrides
Contributor
|
Warning You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again! |
Owner
|
Merged into Solid fix: Verified before merge: 25/25 tests in |
diegosouzapw
added a commit
that referenced
this pull request
Jun 5, 2026
…s + add contributor hall Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for every merged contributor PR that was missing credit (#3170/#3171/#3172 @pizzav-xyz, #3185/#3195 @zhiru, #3188 @xz-dev, #3189/#3203/#3204/#3241 @wilsonicdev, #3191 @bypanghu, #3206 @juandisay, #3217 @oyi77, #3226 @miracuves, #3187/#3200 maintainer), drop stale v3.8.8 leftovers (#2958/#2959 already shipped) and 3 empty v3.8.10 stub headers.
Merged
wilsonicdev
pushed a commit
to wilsonicdev/OmniRoute
that referenced
this pull request
Jun 6, 2026
…s + add contributor hall Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for every merged contributor PR that was missing credit (diegosouzapw#3170/diegosouzapw#3171/diegosouzapw#3172 @pizzav-xyz, diegosouzapw#3185/diegosouzapw#3195 @zhiru, diegosouzapw#3188 @xz-dev, diegosouzapw#3189/diegosouzapw#3203/diegosouzapw#3204/diegosouzapw#3241 @wilsonicdev, diegosouzapw#3191 @bypanghu, diegosouzapw#3206 @juandisay, diegosouzapw#3217 @oyi77, diegosouzapw#3226 @miracuves, diegosouzapw#3187/diegosouzapw#3200 maintainer), drop stale v3.8.8 leftovers (diegosouzapw#2958/diegosouzapw#2959 already shipped) and 3 empty v3.8.10 stub headers.
HouMinXi
pushed a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Aug 2, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206) Integrated into release/v3.8.11
HouMinXi
pushed a commit
to HouMinXi/OmniRoute
that referenced
this pull request
Aug 2, 2026
…s + add contributor hall Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for every merged contributor PR that was missing credit (diegosouzapw#3170/diegosouzapw#3171/diegosouzapw#3172 @pizzav-xyz, diegosouzapw#3185/diegosouzapw#3195 @zhiru, diegosouzapw#3188 @xz-dev, diegosouzapw#3189/diegosouzapw#3203/diegosouzapw#3204/diegosouzapw#3241 @wilsonicdev, diegosouzapw#3191 @bypanghu, diegosouzapw#3206 @juandisay, diegosouzapw#3217 @oyi77, diegosouzapw#3226 @miracuves, diegosouzapw#3187/diegosouzapw#3200 maintainer), drop stale v3.8.8 leftovers (diegosouzapw#2958/diegosouzapw#2959 already shipped) and 3 empty v3.8.10 stub headers.
Poid-ZA
pushed a commit
to Poid-ZA/OmniRoute
that referenced
this pull request
Aug 5, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206) Integrated into release/v3.8.11
Poid-ZA
pushed a commit
to Poid-ZA/OmniRoute
that referenced
this pull request
Aug 5, 2026
…s + add contributor hall Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for every merged contributor PR that was missing credit (diegosouzapw#3170/diegosouzapw#3171/diegosouzapw#3172 @pizzav-xyz, diegosouzapw#3185/diegosouzapw#3195 @zhiru, diegosouzapw#3188 @xz-dev, diegosouzapw#3189/diegosouzapw#3203/diegosouzapw#3204/diegosouzapw#3241 @wilsonicdev, diegosouzapw#3191 @bypanghu, diegosouzapw#3206 @juandisay, diegosouzapw#3217 @oyi77, diegosouzapw#3226 @miracuves, diegosouzapw#3187/diegosouzapw#3200 maintainer), drop stale v3.8.8 leftovers (diegosouzapw#2958/diegosouzapw#2959 already shipped) and 3 empty v3.8.10 stub headers.
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206) Integrated into release/v3.8.11
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…s + add contributor hall Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for every merged contributor PR that was missing credit (diegosouzapw#3170/diegosouzapw#3171/diegosouzapw#3172 @pizzav-xyz, diegosouzapw#3185/diegosouzapw#3195 @zhiru, diegosouzapw#3188 @xz-dev, diegosouzapw#3189/diegosouzapw#3203/diegosouzapw#3204/diegosouzapw#3241 @wilsonicdev, diegosouzapw#3191 @bypanghu, diegosouzapw#3206 @juandisay, diegosouzapw#3217 @oyi77, diegosouzapw#3226 @miracuves, diegosouzapw#3187/diegosouzapw#3200 maintainer), drop stale v3.8.8 leftovers (diegosouzapw#2958/diegosouzapw#2959 already shipped) and 3 empty v3.8.10 stub headers.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Propblems
When adding a new Antigravity (or Gemini CLI / AGY) provider connection via the dashboard, the OAuth flow failed with a
redirect_uri_mismatcherror from Google. This happened becausehasCustomGoogleOAuthCredentials()treated the default built-in public client IDs (auto-populated bysync-env) as "custom" credentials, which triggeredresolveBrowserOAuthRedirectUri()to rewrite the loopback callback URL to a publicNEXT_PUBLIC_BASE_URL— producing a mismatch against what Google's OAuth consent screen expected.The fix compares the env-supplied client ID against the dynamically resolved default from
resolvePublicCred()(instead of treating any non-empty value as custom). When the env value matches the embedded public default, the redirect URI stays on loopback as intended.Related Issues
redirect_uri_mismatcherrors on fresh installs with default.envconfigurationValidation
npm run lintnpm run test:unitnpm run test:coverage>= 60%for statements, lines, functions, and branchesTests Added Or Updated
tests/unit/oauth-redirect-uri-mismatch.test.ts— 25 fully offline tests covering:agyprovider alias inherits antigravity credential detection[::1]andlocalhostloopback variantsOMNIROUTE_PUBLIC_BASE_URLfallbackCoverage Notes
src/lib/oauth/providers.tsis the only production file changed. The new test file exercises every branch ofhasCustomGoogleOAuthCredentials()andresolveBrowserOAuthRedirectUri()with both default and custom credential combinations. Coverage should increase for this file.Reviewer Notes
resolvePublicCred("antigravity_id")andresolvePublicCred("gemini_id")to dynamically resolve the default client IDs from the XOR-masked embedded defaults inopen-sse/utils/publicCreds.ts. This avoids hardcoding the raw*.apps.googleusercontent.comstrings (which would trip pattern scanners) while keeping the comparison accurate even if the embedded defaults are rotated in the future.OAuthModal.tsxfrontend already uses127.0.0.1onmain, so no frontend change was needed on this branch.