Repository navigation
feat(oauth): support web client type for remote Google OAuth - #8845
Merged
diegosouzapw merged 2 commits intoJul 28, 2026
Merged
diegosouzapw merged 2 commits into
diegosouzapw merged 2 commits into
Conversation
Google Desktop app OAuth clients require loopback redirect URIs per policy, which breaks remote deployments where the browser cannot reach 127.0.0.1 on the server. Add ANTIGRAVITY_OAUTH_CLIENT_TYPE env var: when set to 'web' and OMNIROUTE_PUBLIC_BASE_URL is configured, the loopback redirect URI is upgraded to the public base URL. Default behavior (desktop) is unchanged. Enables remote deployments without SSH tunneling by registering a Web application OAuth client in Google Cloud Console. Signed-off-by: Minxi Hou <houminxi@gmail.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
diegosouzapw
merged commit Jul 28, 2026
7193b0a
into
diegosouzapw:release/v3.8.49
15 of 16 checks passed
diegosouzapw
added a commit
that referenced
this pull request
Jul 28, 2026
…e lost credits Aggregates every pending changelog.d fragment into the [3.8.49] section and regenerates the contributors table from the reconciled bullets. Three fixes this surfaced: - The [3.8.49] section had no `### 📝 Maintenance` heading, so the aggregator's findIndex matched the first one in the file — inside [3.8.47] — and would have filed 92 maintenance bullets under the wrong release. Added the heading to the living section; [3.8.47] stays at its original 234 bullets. - 46 bullets carried no PR/issue reference. Fragments may keep the number only in the filename (`<N>-slug.md`), which the aggregator does not copy into the bullet, so the link and the credit were dropped on aggregation. Restored, scoped strictly to the [3.8.49] range. - 9 external contributors lost their attribution that way and are credited again: @MisileLab (#8566), @MumuTW (#8619), @epsilonode (#8724), @hppsc1215 (#8835), @sumanxg (#8837, #8856), @TitoTFP (#8838), @HouMinXi (#8842, #8845). Contributors table: 84 → 155 entries, no one removed. 42 i18n mirrors synced. check:changelog-integrity green — no base bullet lost.
Merged
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…uzapw#8845) * feat(oauth): support web client type for remote Google OAuth Google Desktop app OAuth clients require loopback redirect URIs per policy, which breaks remote deployments where the browser cannot reach 127.0.0.1 on the server. Add ANTIGRAVITY_OAUTH_CLIENT_TYPE env var: when set to 'web' and OMNIROUTE_PUBLIC_BASE_URL is configured, the loopback redirect URI is upgraded to the public base URL. Default behavior (desktop) is unchanged. Enables remote deployments without SSH tunneling by registering a Web application OAuth client in Google Cloud Console. Signed-off-by: Minxi Hou <houminxi@gmail.com> * docs(changelog): add fragment for diegosouzapw#8845 Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Signed-off-by: Minxi Hou <houminxi@gmail.com> Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra
pushed a commit
to niyatna/NiyatnaRoute
that referenced
this pull request
Sep 27, 2026
…e lost credits Aggregates every pending changelog.d fragment into the [3.8.49] section and regenerates the contributors table from the reconciled bullets. Three fixes this surfaced: - The [3.8.49] section had no `### 📝 Maintenance` heading, so the aggregator's findIndex matched the first one in the file — inside [3.8.47] — and would have filed 92 maintenance bullets under the wrong release. Added the heading to the living section; [3.8.47] stays at its original 234 bullets. - 46 bullets carried no PR/issue reference. Fragments may keep the number only in the filename (`<N>-slug.md`), which the aggregator does not copy into the bullet, so the link and the credit were dropped on aggregation. Restored, scoped strictly to the [3.8.49] range. - 9 external contributors lost their attribution that way and are credited again: @MisileLab (diegosouzapw#8566), @MumuTW (diegosouzapw#8619), @epsilonode (diegosouzapw#8724), @hppsc1215 (diegosouzapw#8835), @sumanxg (diegosouzapw#8837, diegosouzapw#8856), @TitoTFP (diegosouzapw#8838), @HouMinXi (diegosouzapw#8842, diegosouzapw#8845). Contributors table: 84 → 155 entries, no one removed. 42 i18n mirrors synced. check:changelog-integrity green — no base bullet lost.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Add
ANTIGRAVITY_OAUTH_CLIENT_TYPEenvironment variable to support Web application OAuth client type for remote deployments. When set towebwith custom credentials andOMNIROUTE_PUBLIC_BASE_URL, the loopback redirect URI (127.0.0.1) is upgraded to the public base URL.Why
Google Desktop app OAuth clients require loopback redirect URIs per policy. This breaks remote deployments (Docker, VPS, LAN servers) where the browser cannot reach
127.0.0.1on the server. Users must manually edit the callback URL after Google authentication.The existing
resolveBrowserOAuthRedirectUrimechanism only upgrades when custom credentials are detected, but still uses loopback. This change adds an explicit opt-in for Web application client type.How
ANTIGRAVITY_OAUTH_CLIENT_TYPEenv var check inresolveBrowserOAuthRedirectUriweb(case-insensitive, trimmed), upgrade loopback redirect toOMNIROUTE_PUBLIC_BASE_URLdesktopor unset) is unchangedANTIGRAVITY_OAUTH_CLIENT_ID+ANTIGRAVITY_OAUTH_CLIENT_SECRET)upgradeLoopbackToPublichelper to avoid DRY violationTests
6 new test cases in
oauth-redirect-uri-mismatch.test.ts:All 24 tests pass (18 existing + 6 new).
Usage
Requires registering a Web application OAuth client in Google Cloud Console with the public URL as an authorized redirect URI.
Related