Skip to content

fix(Oauth): validate client IDs against resolvePublicCred to correctly togg… - #3206

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.11from
juandisay:hotfix/Oauth-google
Jun 5, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.11from
juandisay:hotfix/Oauth-google

Conversation

@juandisay

@juandisay juandisay commented Jun 5, 2026 •

Copy link
Copy Markdown
Contributor

Propblems

When adding a new Antigravity (or Gemini CLI / AGY) provider connection via the dashboard, the OAuth flow failed with a redirect_uri_mismatch error from Google. This happened because hasCustomGoogleOAuthCredentials() treated the default built-in public client IDs (auto-populated by sync-env) as "custom" credentials, which triggered resolveBrowserOAuthRedirectUri() to rewrite the loopback callback URL to a public NEXT_PUBLIC_BASE_URL — producing a mismatch against what Google's OAuth consent screen expected.

The fix compares the env-supplied client ID against the dynamically resolved default from resolvePublicCred() (instead of treating any non-empty value as custom). When the env value matches the embedded public default, the redirect URI stays on loopback as intended.

Related Issues

  • Closes #TBD
  • Related to redirect_uri_mismatch errors on fresh installs with default .env configuration

Validation

  • npm run lint
  • npm run test:unit
  • npm run test:coverage
  • Coverage is still >= 60% for statements, lines, functions, and branches
  • SonarQube PR analysis is green or any remaining issues are explicitly documented below

Tests Added Or Updated

  • [NEW] tests/unit/oauth-redirect-uri-mismatch.test.ts — 25 fully offline tests covering:
    • Default public credentials correctly identified → loopback preserved
    • Truly custom credentials → public base URL override works
    • agy provider alias inherits antigravity credential detection
    • Incomplete/missing/blank credentials → no override
    • Non-Google providers unaffected
    • Already-remote redirect URIs not double-overridden
    • IPv6 [::1] and localhost loopback variants
    • Path and query string preservation during override
    • Trailing slash normalization on base URL
    • OMNIROUTE_PUBLIC_BASE_URL fallback

Coverage Notes

  • src/lib/oauth/providers.ts is the only production file changed. The new test file exercises every branch of hasCustomGoogleOAuthCredentials() and resolveBrowserOAuthRedirectUri() with both default and custom credential combinations. Coverage should increase for this file.

Reviewer Notes

  • The fix uses resolvePublicCred("antigravity_id") and resolvePublicCred("gemini_id") to dynamically resolve the default client IDs from the XOR-masked embedded defaults in open-sse/utils/publicCreds.ts. This avoids hardcoding the raw *.apps.googleusercontent.com strings (which would trip pattern scanners) while keeping the comparison accurate even if the embedded defaults are rotated in the future.
  • No migration or feature flag required — this is a pure bugfix for the existing credential detection logic.
  • The OAuthModal.tsx frontend already uses 127.0.0.1 on main, so no frontend change was needed on this branch.

@juandisay
juandisay requested a review from diegosouzapw as a code owner June 5, 2026 05:10
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Warning

You have reached your daily quota limit. Please wait up to 24 hours and I will start processing your requests again!

@juandisay juandisay changed the title feat: validate client IDs against resolvePublicCred to correctly togg… fix(Oauth): validate client IDs against resolvePublicCred to correctly togg… Jun 5, 2026
@diegosouzapw
diegosouzapw changed the base branch from main to release/v3.8.11 June 5, 2026 05:39
@diegosouzapw
diegosouzapw merged commit 0ea925a into diegosouzapw:release/v3.8.11 Jun 5, 2026
1 check passed
@diegosouzapw

Copy link
Copy Markdown
Owner

Merged into release/v3.8.11 — thank you @juandisay! 🙏

Solid fix: hasCustomGoogleOAuthCredentials() was treating the built-in public client IDs (auto-populated by sync-env) as "custom", which rewrote the loopback redirect URI and triggered Google's redirect_uri_mismatch. Comparing against resolvePublicCred("antigravity_id" / "gemini_id") correctly distinguishes real custom creds from the defaults — and it's the mandated resolvePublicCred pattern (no hard-coded literals).

Verified before merge: 25/25 tests in oauth-redirect-uri-mismatch green, lint clean, Semgrep passed. Ships in the next release.

diegosouzapw added a commit that referenced this pull request Jun 5, 2026
…s + add contributor hall

Consolidate the split [Unreleased]/[3.8.11] sections into one, add entries for
every merged contributor PR that was missing credit (#3170/#3171/#3172 @pizzav-xyz,
#3185/#3195 @zhiru, #3188 @xz-dev, #3189/#3203/#3204/#3241 @wilsonicdev, #3191 @bypanghu,
#3206 @juandisay, #3217 @oyi77, #3226 @miracuves, #3187/#3200 maintainer), drop stale
v3.8.8 leftovers (#2958/#2959 already shipped) and 3 empty v3.8.10 stub headers.
@diegosouzapw diegosouzapw mentioned this pull request Jun 5, 2026
wilsonicdev pushed a commit to wilsonicdev/OmniRoute that referenced this pull request Jun 6, 2026
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206)

Integrated into release/v3.8.11
HouMinXi pushed a commit to HouMinXi/OmniRoute that referenced this pull request Aug 2, 2026
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206)

Integrated into release/v3.8.11
Poid-ZA pushed a commit to Poid-ZA/OmniRoute that referenced this pull request Aug 5, 2026
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…le OAuth redirect URI overrides (diegosouzapw#3206)

Integrated into release/v3.8.11
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants