fix: skip silent OIDC on callback page to prevent race condition
AuthProvider.build() was initiating silent OIDC while the callback page was processing the auth code, causing PKCE state to be cleared. Now checks if on /callback route and skips silent OIDC initiation. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.5
parent
a95296e1fc
commit
f90b4a0963
@@ -42,6 +42,13 @@ class AuthNotifier extends _$AuthNotifier {
|
||||
Future<AuthState> build() async {
|
||||
// On web with auth required, use silent OIDC to get JWT
|
||||
if (kIsWeb && AppConfig.requiresAuth) {
|
||||
// Skip silent OIDC if we're on the callback page (it will handle auth)
|
||||
final currentUrl = web_utils.getCurrentUrl();
|
||||
if (currentUrl.contains('/callback')) {
|
||||
developer.log('Web: On callback page, skipping silent OIDC', name: 'auth');
|
||||
return const AuthState();
|
||||
}
|
||||
|
||||
// First check if we have stored tokens
|
||||
final storedAuth = await _loadStoredAuth();
|
||||
if (storedAuth.isAuthenticated && !storedAuth.isTokenExpired) {
|
||||
|
||||
Reference in New Issue
Block a user