Fix Google consent loop: route the callback through the code exchange - #11
Merged
Conversation
The SDK's callback handler treats any already-connected server as "auth
accepted" and returns success WITHOUT exchanging the authorization code
— and Google's anonymous connect leaves the gcal connection "ready", so
every consent round-trip silently discarded the code and saved no
tokens ("one step left" forever). When a consent URL is handed out, the
connection is now flipped to the authenticating state, live and
persisted via the server row's auth_url (so a fresh isolate at callback
time restores the same way), which routes the callback into the
code-exchange branch. Breadcrumb logging on the callback route and the
consent probe for observability.
Claude-Session: https://claude.ai/code/session_01MKLJUWk6biNAKXupHTTWn5
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The agents SDK short-circuits OAuth callbacks for connections in ready state ('auth accepted') without exchanging the code — and Google's MCP server connects anonymously, so consent looped forever with no tokens. Handing out a consent URL now flips the connection to authenticating (live + persisted auth_url) so the callback takes the real exchange path. Adds callback/probe breadcrumbs.
https://claude.ai/code/session_01MKLJUWk6biNAKXupHTTWn5