Skip to content

Implement Google OAuth Flow - #41

Open
singhaditya21 wants to merge 1 commit into
mainfrom
google-oauth-flow-2211627360713653871
Open

Implement Google OAuth Flow#41
singhaditya21 wants to merge 1 commit into
mainfrom
google-oauth-flow-2211627360713653871

Conversation

@singhaditya21

Copy link
Copy Markdown
Owner

Implemented a complete Google OAuth Authorization Code flow.
The web-demo now uses the Google Identity Services library (gsi/client) to initiate the sign-in flow and retrieve an authorization code.
The backend API exposes a new endpoint POST /api/auth/google which accepts the code, exchanges it for an access token and ID token from Google, verifies the user, and issues a JWT for the application.
Configuration was updated to include Google Client credentials.
Frontend changes were verified visually (screenshot google_login_ui.png) and backend logic was verified with unit tests.


PR created automatically by Jules for task 2211627360713653871 started by @singhaditya21

…nd API.

- Added `POST /api/auth/google` endpoint in backend to exchange auth code for tokens.
- Updated backend user schema to support `web` and `google` platforms.
- Updated `web-demo` to use Google Identity Services for sign-in.
- Added `GOOGLE_CLIENT_ID` and `GOOGLE_CLIENT_SECRET` to backend configuration.

Co-authored-by: singhaditya21 <53948039+singhaditya21@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@singhaditya21

Copy link
Copy Markdown
Owner Author

Reviewed, leaving open — the feature is wanted, but three things need sorting before it can land:

  1. Stray artifacts. The diff includes google_login_ui.png and verification/verify_google_ui.py. Committed screenshots and one-off verification scripts were cleared out of this repo in the recent cleanup; please drop both.
  2. Needs a rebase. config.py, routers/users.py and schemas/user.py have all moved since February.
  3. Cannot be verified here. The flow needs real GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET credentials, so I can only review it statically.

main now has a test suite with a working Postgres fixture (backend/api/tests/conftest.py, auth_client), so the token-exchange path can be tested against a stubbed Google endpoint — worth adding here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant