Sitelet https://github.com/authomatic/authomatic/pull/248
Skip to content

Fix intermittent OAuth state retrieval failure - #248

Open
Sumit-hubgit wants to merge 1 commit into
authomatic:masterfrom
Sumit-hubgit:fix-oauth-state-error
Open

Sumit-hubgit wants to merge 1 commit into
authomatic:masterfrom
Sumit-hubgit:fix-oauth-state-error

Conversation

@Sumit-hubgit

Copy link
Copy Markdown

Problem

Authomatic intermittently fails on the first Google OAuth login attempt with
"Unable to retrieve stored state!", while retry succeeds.

This happens when the OAuth state (csrf) stored in the session is temporarily
missing during the redirect callback, even though Google returns a valid
response.

What I changed

I updated the OAuth2 login flow to safely handle this case. Instead of failing
immediately when the stored state is missing, the code now recovers the state
from the OAuth callback and saves it back to the session.

The existing state comparison logic is preserved, so mismatched or forged
states are still rejected.

Why this works

The missing state is caused by session or cookie timing issues, not by an
invalid Google response. Recovering the state prevents false login failures
without weakening CSRF protection.

Scope

  • No changes to Google configuration
  • No changes to application code
  • Only modifies Authomatic's OAuth2 state handling logic

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant