Repository navigation
fix: desktop OAuth login via system browser with session handoff - #36
Merged
Merged
Conversation
OAuth login (Google/GitHub) was silently failing in the Tauri desktop app because the webview blocked navigation to external OAuth provider URLs. - In Tauri: use implicit flow + system browser for OAuth, with a session-exchange API to pass tokens back to the webview via polling - In Web: use PKCE flow with explicit skipBrowserRedirect + window.location - Add oauthLoading/oauthError state with UI feedback (spinner, error display) - Add /auth/desktop-callback page for system browser token handoff - Add /api/auth/session-exchange endpoint for one-time token relay - Update Supabase redirect URL docs with desktop-callback paths Made-with: Cursor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
skipBrowserRedirect+window.location.assignoauthLoading/oauthErrorstate with loading spinner and error display on login pageChanges
src/stores/auth-store.ts— Platform-aware OAuth: Tauri uses system browser + implicit flow + polling; Web uses PKCE flowsrc/app/(app)/login/page.tsx— OAuth buttons show loading spinner and disabled state; display OAuth errorssrc/app/auth/desktop-callback/page.tsx— New page for system browser to hand off tokens after OAuthsrc/app/api/auth/session-exchange/route.ts— New one-time token relay API (POST stores, GET consumes)docs/supabase-setup.md— Updated redirect URL docs with desktop-callback pathspackage.json— Added@tauri-apps/plugin-shellfor opening system browserTest plan
Made with Cursor