Skip to content

feat(oauth): support web client type for remote Google OAuth - #8845

Merged
diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.49from
HouMinXi:fix/oauth-web-client-type
Jul 28, 2026
Merged

diegosouzapw merged 2 commits into
diegosouzapw:release/v3.8.49from
HouMinXi:fix/oauth-web-client-type

Conversation

@HouMinXi

Copy link
Copy Markdown
Contributor

What

Add ANTIGRAVITY_OAUTH_CLIENT_TYPE environment variable to support Web application OAuth client type for remote deployments. When set to web with custom credentials and OMNIROUTE_PUBLIC_BASE_URL, the loopback redirect URI (127.0.0.1) is upgraded to the public base URL.

Why

Google Desktop app OAuth clients require loopback redirect URIs per policy. This breaks remote deployments (Docker, VPS, LAN servers) where the browser cannot reach 127.0.0.1 on the server. Users must manually edit the callback URL after Google authentication.

The existing resolveBrowserOAuthRedirectUri mechanism only upgrades when custom credentials are detected, but still uses loopback. This change adds an explicit opt-in for Web application client type.

How

  • Add ANTIGRAVITY_OAUTH_CLIENT_TYPE env var check in resolveBrowserOAuthRedirectUri
  • When set to web (case-insensitive, trimmed), upgrade loopback redirect to OMNIROUTE_PUBLIC_BASE_URL
  • Default behavior (desktop or unset) is unchanged
  • Requires custom OAuth credentials (ANTIGRAVITY_OAUTH_CLIENT_ID + ANTIGRAVITY_OAUTH_CLIENT_SECRET)
  • Extract upgradeLoopbackToPublic helper to avoid DRY violation

Tests

6 new test cases in oauth-redirect-uri-mismatch.test.ts:

  1. Web client type with custom credentials switches to public URL
  2. agy inherits web client type from antigravity
  3. Web client type without custom credentials keeps loopback
  4. Desktop client type keeps loopback
  5. No client type defaults to desktop
  6. Web client type preserves custom callback path

All 24 tests pass (18 existing + 6 new).

Usage

# In .env or environment:
ANTIGRAVITY_OAUTH_CLIENT_ID=your-web-client-id.apps.googleusercontent.com
ANTIGRAVITY_OAUTH_CLIENT_SECRET=your-web-client-secret
ANTIGRAVITY_OAUTH_CLIENT_TYPE=web
OMNIROUTE_PUBLIC_BASE_URL=https://192.168.100.10:20128

Requires registering a Web application OAuth client in Google Cloud Console with the public URL as an authorized redirect URI.

Related

Google Desktop app OAuth clients require loopback redirect URIs per
policy, which breaks remote deployments where the browser cannot reach
127.0.0.1 on the server. Add ANTIGRAVITY_OAUTH_CLIENT_TYPE env var:
when set to 'web' and OMNIROUTE_PUBLIC_BASE_URL is configured, the
loopback redirect URI is upgraded to the public base URL. Default
behavior (desktop) is unchanged.

Enables remote deployments without SSH tunneling by registering a Web
application OAuth client in Google Cloud Console.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@HouMinXi
HouMinXi requested a review from diegosouzapw as a code owner July 28, 2026 10:43
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
@diegosouzapw
diegosouzapw merged commit 7193b0a into diegosouzapw:release/v3.8.49 Jul 28, 2026
15 of 16 checks passed
diegosouzapw added a commit that referenced this pull request Jul 28, 2026
…e lost credits

Aggregates every pending changelog.d fragment into the [3.8.49] section and
regenerates the contributors table from the reconciled bullets.

Three fixes this surfaced:

- The [3.8.49] section had no `### 📝 Maintenance` heading, so the aggregator's
  findIndex matched the first one in the file — inside [3.8.47] — and would have
  filed 92 maintenance bullets under the wrong release. Added the heading to the
  living section; [3.8.47] stays at its original 234 bullets.

- 46 bullets carried no PR/issue reference. Fragments may keep the number only in
  the filename (`<N>-slug.md`), which the aggregator does not copy into the bullet,
  so the link and the credit were dropped on aggregation. Restored, scoped strictly
  to the [3.8.49] range.

- 9 external contributors lost their attribution that way and are credited again:
  @MisileLab (#8566), @MumuTW (#8619), @epsilonode (#8724), @hppsc1215 (#8835),
  @sumanxg (#8837, #8856), @TitoTFP (#8838), @HouMinXi (#8842, #8845).

Contributors table: 84 → 155 entries, no one removed. 42 i18n mirrors synced.
check:changelog-integrity green — no base bullet lost.
@diegosouzapw diegosouzapw mentioned this pull request Jul 28, 2026
@HouMinXi
HouMinXi deleted the fix/oauth-web-client-type branch September 16, 2026 14:05
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…uzapw#8845)

* feat(oauth): support web client type for remote Google OAuth

Google Desktop app OAuth clients require loopback redirect URIs per
policy, which breaks remote deployments where the browser cannot reach
127.0.0.1 on the server. Add ANTIGRAVITY_OAUTH_CLIENT_TYPE env var:
when set to 'web' and OMNIROUTE_PUBLIC_BASE_URL is configured, the
loopback redirect URI is upgraded to the public base URL. Default
behavior (desktop) is unchanged.

Enables remote deployments without SSH tunneling by registering a Web
application OAuth client in Google Cloud Console.

Signed-off-by: Minxi Hou <houminxi@gmail.com>

* docs(changelog): add fragment for diegosouzapw#8845

Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>

---------

Signed-off-by: Minxi Hou <houminxi@gmail.com>
Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com>
muhamadgalihsaputra pushed a commit to niyatna/NiyatnaRoute that referenced this pull request Sep 27, 2026
…e lost credits

Aggregates every pending changelog.d fragment into the [3.8.49] section and
regenerates the contributors table from the reconciled bullets.

Three fixes this surfaced:

- The [3.8.49] section had no `### 📝 Maintenance` heading, so the aggregator's
  findIndex matched the first one in the file — inside [3.8.47] — and would have
  filed 92 maintenance bullets under the wrong release. Added the heading to the
  living section; [3.8.47] stays at its original 234 bullets.

- 46 bullets carried no PR/issue reference. Fragments may keep the number only in
  the filename (`<N>-slug.md`), which the aggregator does not copy into the bullet,
  so the link and the credit were dropped on aggregation. Restored, scoped strictly
  to the [3.8.49] range.

- 9 external contributors lost their attribution that way and are credited again:
  @MisileLab (diegosouzapw#8566), @MumuTW (diegosouzapw#8619), @epsilonode (diegosouzapw#8724), @hppsc1215 (diegosouzapw#8835),
  @sumanxg (diegosouzapw#8837, diegosouzapw#8856), @TitoTFP (diegosouzapw#8838), @HouMinXi (diegosouzapw#8842, diegosouzapw#8845).

Contributors table: 84 → 155 entries, no one removed. 42 i18n mirrors synced.
check:changelog-integrity green — no base bullet lost.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants