fix: skip silent OIDC on callback page to prevent race condition
AuthProvider.build() was initiating silent OIDC while the callback page was processing the auth code, causing PKCE state to be cleared. Now checks if on /callback route and skips silent OIDC initiation. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
a95296e1fc
commit
f90b4a0963
@@ -7,6 +7,11 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
|
||||
|
||||
## [Unreleased]
|
||||
|
||||
## [1.1.5] - 2026-01-04
|
||||
|
||||
### Fixed
|
||||
- Race condition in OIDC callback: AuthProvider.build() was initiating silent OIDC while the callback page was processing, causing PKCE state to be cleared. Now skips silent OIDC when on `/callback` route.
|
||||
|
||||
## [1.1.4] - 2026-01-04
|
||||
|
||||
### Fixed
|
||||
|
||||
@@ -42,6 +42,13 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
Future<AuthState> build() async {
|
||||
// On web with auth required, use silent OIDC to get JWT
|
||||
if (kIsWeb && AppConfig.requiresAuth) {
|
||||
// Skip silent OIDC if we're on the callback page (it will handle auth)
|
||||
final currentUrl = web_utils.getCurrentUrl();
|
||||
if (currentUrl.contains('/callback')) {
|
||||
developer.log('Web: On callback page, skipping silent OIDC', name: 'auth');
|
||||
return const AuthState();
|
||||
}
|
||||
|
||||
// First check if we have stored tokens
|
||||
final storedAuth = await _loadStoredAuth();
|
||||
if (storedAuth.isAuthenticated && !storedAuth.isTokenExpired) {
|
||||
|
||||
+1
-1
@@ -16,7 +16,7 @@ publish_to: 'none' # Remove this line if you wish to publish to pub.dev
|
||||
# https://developer.apple.com/library/archive/documentation/General/Reference/InfoPlistKeyReference/Articles/CoreFoundationKeys.html
|
||||
# In Windows, build-name is used as the major, minor, and patch parts
|
||||
# of the product and file versions while build-number is used as the build suffix.
|
||||
version: 1.1.4+1
|
||||
version: 1.1.5+1
|
||||
|
||||
environment:
|
||||
sdk: ^3.10.4
|
||||
|
||||
Reference in New Issue
Block a user