Skip to content

fix: desktop OAuth login via system browser with session handoff - #36

Merged
Talljack merged 1 commit into
mainfrom
fix/desktop-oauth-login
Apr 11, 2026
Merged

Talljack merged 1 commit into
mainfrom
fix/desktop-oauth-login

Conversation

@Talljack

Copy link
Copy Markdown
Owner

Summary

  • Fix OAuth login (Google/GitHub) silently failing in the Tauri desktop app
  • In Tauri: open OAuth in system browser (shows saved accounts), use implicit flow + session-exchange API to relay tokens back to the webview
  • In Web: use PKCE flow with explicit skipBrowserRedirect + window.location.assign
  • Add oauthLoading/oauthError state with loading spinner and error display on login page

Changes

  • src/stores/auth-store.ts — Platform-aware OAuth: Tauri uses system browser + implicit flow + polling; Web uses PKCE flow
  • src/app/(app)/login/page.tsx — OAuth buttons show loading spinner and disabled state; display OAuth errors
  • src/app/auth/desktop-callback/page.tsx — New page for system browser to hand off tokens after OAuth
  • src/app/api/auth/session-exchange/route.ts — New one-time token relay API (POST stores, GET consumes)
  • docs/supabase-setup.md — Updated redirect URL docs with desktop-callback paths
  • package.json — Added @tauri-apps/plugin-shell for opening system browser

Test plan

  • Web: Google OAuth button navigates to Google login page
  • Web: GitHub OAuth button navigates to GitHub login page
  • Desktop-callback page correctly parses tokens and shows success
  • Session-exchange API stores and returns tokens (one-time use)
  • TypeScript type check passes
  • Biome lint passes
  • Manual: Tauri desktop Google OAuth full flow
  • Manual: Tauri desktop GitHub OAuth full flow

Made with Cursor

OAuth login (Google/GitHub) was silently failing in the Tauri desktop app
because the webview blocked navigation to external OAuth provider URLs.

- In Tauri: use implicit flow + system browser for OAuth, with a
  session-exchange API to pass tokens back to the webview via polling
- In Web: use PKCE flow with explicit skipBrowserRedirect + window.location
- Add oauthLoading/oauthError state with UI feedback (spinner, error display)
- Add /auth/desktop-callback page for system browser token handoff
- Add /api/auth/session-exchange endpoint for one-time token relay
- Update Supabase redirect URL docs with desktop-callback paths

Made-with: Cursor
@vercel

vercel Bot commented Apr 11, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
echo-type Ready Ready Preview, Comment Apr 11, 2026 4:26pm

@Talljack
Talljack merged commit 52916cb into main Apr 11, 2026
6 checks passed
@Talljack
Talljack deleted the fix/desktop-oauth-login branch April 11, 2026 16:27

This branch was successfully deployed

1 active deployment
Preview — 1ae42397 Deployed Apr 11, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant