Skip to content

fix(auth): prevent infinite verification and OAuth retry loops - #29655

Merged
DavidAPierce merged 7 commits into
google-gemini:mainfrom
villahernandez-coder:FixBug-cla-561556265
Oct 7, 2026
Merged

DavidAPierce merged 7 commits into
google-gemini:mainfrom
villahernandez-coder:FixBug-cla-561556265

Conversation

@villahernandez-coder

Copy link
Copy Markdown
Contributor

Summary

Fixes an issue where users could get stuck in an infinite cycle of browser verification and OAuth prompts even after completing browser authentication and pressing Enter in the CLI.

Details

  • Bounded Verification Retries (packages/core/src/utils/retry.ts, packages/core/src/code_assist/setup.ts):
    - Previously, retryWithBackoff reset attempt = 0 unconditionally whenever onValidationRequired returned 'verify', and _doSetupUser looped in while (true) without a cap. Bounded verification retries to MAX_VALIDATION_ATTEMPTS = 3 so persistent 403 VALIDATION_REQUIRED responses terminate cleanly instead of trapping the user in an infinite verification loop.
    - Added fallback extraction for validation_url and validation_learn_more_url in classifyValidationRequiredError
    (packages/core/src/utils/googleQuotaErrors.ts).

  • Terminal Redraw & Timer Stabilization (packages/cli/src/ui/components/ValidationDialog.tsx, packages/cli/src/ui/AppContainer.tsx):
    - Stored onChoice in a ref (onChoiceRef) with a completion guard (hasCompletedRef) inside ValidationDialog and memoized handleShowAuthSelection in AppContainer. Previously, parent re-renders recreated onShowAuthSelection and handleValidationChoice, resetting the 500ms 'complete' transition timer in ValidationDialog.

  • OAuth Callback & Token Acquisition Synchronization (packages/core/src/agents/auth-provider/oauth2-provider.ts, packages/core/src/utils/oauth-flow.ts):
    - Deduplicated concurrent token acquisition / interactive OAuth flows in OAuth2AuthProvider.headers() via pendingAuthPromise.
    - Reset authRetryCount = 0 when returning a valid cached token on subsequent headers() calls.
    - Cleared the 5-minute callback timeout on server close/error in startCallbackServer() and exposed a cancel callback to close the server cleanly when user consent is declined.

  • Auth State Transitions (packages/cli/src/ui/auth/useAuth.ts, packages/cli/src/ui/auth/AuthDialog.tsx):
    - Handled ChangeAuthRequestedError and ValidationCancelledError in useAuthCommand by transitioning cleanly to AuthState.Updating without setting a blocking authError.
    - Cleared stale authError and awaited onSelect when a valid auth method is chosen in AuthDialog.

Related Issues

Fixes #19936

How to Validate

  1. Run the core unit test suites for OAuth flow, OAuth2 provider, retry logic, and Code Assist user setup:

    npm test -w @google/gemini-cli-core -- src/agents/auth-provider/oauth2-provider.test.ts src/utils/oauth-flow.test.ts src/utils/retry.test.ts src/code_assist/setup.test.ts
    
  2. Run the CLI UI unit test suites for ValidationDialog, AuthDialog, useAuth, and useQuotaAndFallback:
    npm test -w @google/gemini-cli -- src/ui/components/ValidationDialog.test.tsx src/ui/auth/AuthDialog.test.tsx src/ui/auth/useAuth.test.tsx src/ui/hooks/useQuotaAndFallback.test.ts

  3. Run workspace typecheck and lint:
    npm run typecheck && npm run lint

Pre-Merge Checklist

  • Updated relevant documentation and README (if needed)
  • Added/updated tests (if needed)
  • Noted breaking changes (if any)
  • Validated on required platforms/methods:
    • MacOS
      • npm run
      • npx
      • Docker
      • Podman
      • Seatbelt
    • Windows
      • npm run
      • npx
      • Docker
    • Linux
      • npm run
      • npx
      • Docker

@villahernandez-coder
villahernandez-coder requested a review from a team as a code owner October 6, 2026 20:16
@github-actions github-actions Bot added the size/l A large sized PR label Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

📊 PR Size: size/L

  • Lines changed: 463
  • Additions: +436
  • Deletions: -27
  • Files changed: 16

@gemini-code-assist

Copy link
Copy Markdown
Contributor

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

This pull request addresses several critical issues related to authentication and verification loops in the CLI. By introducing retry bounds, synchronizing concurrent OAuth flows, and stabilizing UI state transitions, the changes ensure that users are not trapped in infinite verification cycles and that authentication processes are more resilient to transient errors and race conditions.

Highlights

  • Bounded Verification Retries: Implemented a limit of 3 validation attempts in both the core setup logic and retry utility to prevent infinite loops when encountering persistent 403 Validation Required errors.
  • OAuth Flow Synchronization: Deduplicated concurrent OAuth token acquisition requests using a pending promise and ensured proper cleanup of callback servers when authentication is cancelled.
  • UI Stabilization: Refactored ValidationDialog to use refs for completion state and callbacks, preventing parent re-renders from resetting the 500ms success transition timer.
  • Auth State Handling: Improved error handling in the CLI auth flow to transition cleanly to an 'Updating' state instead of blocking on specific cancellation or change-auth errors.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution. ↩

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several improvements to the authentication and validation flows, including deduplicating concurrent OAuth2 requests, bounding verification retries to prevent infinite loops, and ensuring parent re-renders do not reset the validation dialog timer. The review feedback suggests resetting the authentication retry counter when a new token is successfully acquired in oauth2-provider.ts, and wrapping the asynchronous onSelect call in a try/catch block in AuthDialog.tsx to handle potential errors gracefully.

Note: Security Review did not run due to the size of the PR.

Comment thread packages/core/src/agents/auth-provider/oauth2-provider.ts
Comment thread packages/cli/src/ui/auth/AuthDialog.tsx Outdated
@gemini-cli gemini-cli Bot added priority/p2 Important but can be addressed in a future release. area/core Issues related to User Interface, OS Support, Core Functionality labels Oct 6, 2026
@villahernandez-coder

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several improvements to the authentication and validation flows, including deduplicating concurrent OAuth2 authentication requests, bounding verification retries to prevent infinite loops, and preventing parent re-renders from resetting timers in the validation dialog. The feedback highlights a potential race condition in shouldRetryWithHeaders where concurrent 401/403 failures could independently increment the retry counter and exhaust the limit prematurely, suggesting a check to see if the token has already been updated or cleared by another request.

Note: Security Review did not run due to the size of the PR.

Comment thread packages/core/src/agents/auth-provider/oauth2-provider.ts Outdated
@villahernandez-coder

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several robustness improvements to the authentication and validation flows. Key changes include deduplicating concurrent interactive OAuth requests and gracefully handling concurrent token failures in OAuth2AuthProvider, adding a cancellation mechanism to the OAuth callback server, and bounding verification retries to a maximum of three attempts in both setupUser and retryWithBackoff to prevent infinite loops. Additionally, ValidationDialog now uses refs to prevent parent re-renders from resetting its transition timer, and error handling in AuthDialog has been improved to catch and forward errors thrown during selection. I have no further feedback to provide.

Note: Security Review did not run due to the size of the PR.

@villahernandez-coder

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces several robustness improvements to the authentication and validation flows in the Gemini CLI. Key changes include coalescing concurrent token refresh and interactive auth requests in OAuth2AuthProvider to prevent duplicate flows, bounding verification retries to a maximum of three attempts in both setupUser and retryWithBackoff to prevent infinite loops, and using refs in ValidationDialog to prevent parent re-renders from resetting the success timer. Additionally, error handling has been enhanced in AuthDialog and useAuthCommand, a cancel mechanism has been added to startCallbackServer, and fallback metadata keys are now supported when classifying validation errors. Comprehensive unit tests have been added to verify these behaviors. I have no feedback to provide as there are no review comments to assess.

@DavidAPierce
DavidAPierce enabled auto-merge October 7, 2026 18:33
@villahernandez-coder

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request improves the robustness of the authentication and validation flows by deduplicating concurrent interactive OAuth2 requests, bounding verification retries to prevent infinite loops, and using refs in the validation dialog to prevent parent re-renders from resetting timers. It also adds a cancel mechanism to the OAuth callback server. Feedback identifies a potential crash in the callback server's abort handler if server.close() is called on an already closed server, suggesting a check on server.listening before closing.

Comment thread packages/core/src/utils/oauth-flow.ts
auto-merge was automatically disabled October 7, 2026 21:28

Head branch was pushed to by a user without write access

@villahernandez-coder

Copy link
Copy Markdown
Contributor Author

/gemini review

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request improves the robustness of the authentication and validation flows. Key updates include deduplicating concurrent interactive OAuth2 requests, bounding verification retries to a maximum of three attempts to prevent infinite loops, and adding cancellation support to the OAuth callback server. Additionally, it optimizes React rendering in ValidationDialog and AppContainer by using refs and callbacks to prevent unnecessary timer resets, and refines error handling for validation and auth transitions. I have no feedback to provide.

Note: Security Review did not run due to the size of the PR.

@DavidAPierce
DavidAPierce enabled auto-merge October 7, 2026 21:45
@DavidAPierce
DavidAPierce added this pull request to the merge queue Oct 7, 2026
Merged via the queue into google-gemini:main with commit 44d764e Oct 7, 2026
35 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

area/core Issues related to User Interface, OS Support, Core Functionality priority/p2 Important but can be addressed in a future release. size/l A large sized PR

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Stuck in loop of verification

2 participants