Sign in on a phone with no console work, in the browser's own session

Mobile OAuth reused the desktop client all along; what stopped it was the
browser. Sending the user out to Safari or Chrome backgrounds the app, iOS
suspends it, and the redirect carrying the code arrives at a socket nobody
is accepting on. The consent page now opens in front of the app instead, in
SFSafariViewController or a Chrome Custom Tab, so the loopback listener
stays live and the existing `installed` client is enough. Verified against
Google's real consent screen on a simulator and an emulator.

A per-platform client is still supported and is now an upgrade rather than a
prerequisite. On iOS it buys ASWebAuthenticationSession, which shares
Safari's session so nobody is asked to sign in to Google twice. Android
needs nothing: Custom Tabs share Chrome's cookies, measured rather than
assumed. iOS session sharing could not be confirmed on the simulator and
wants a real device.

Never an app-owned WebView: Google blocks it, and rightly, since a webview
the app controls can read the password typed into it.

Cancelling is no longer reported as a failure. AuthEvent carries a
`cancelled` flag, set by comparing against the constant every back-out path
returns, and Google's `access_denied` on desktop counts too.

Five frontend bugs found by driving the real UI, not by reading it: the
details card slid under the tab bar leaving its buttons unhittable; the
ghost click after a touch pressed a button in the card that tap had just
opened, opening the editor by itself; the swipe that pages the day was dead
over every read-only block; 84px of macOS traffic-light lane was reserved on
platforms with no traffic lights; and the desktop header ignored the top
safe area on an iPad. A first launch now says what to do next rather than
showing an empty grid, and accounts are named as Google accounts throughout.
This commit is contained in:
pj committed 2026-08-12 18:32:45 +05:30
1 parent 661100dfdc
commit d4c3a304b5
31 files changed
+1319 -114

No files matched your search

+12 -3
View File
@@ -44,9 +44,10 @@ chacha20poly1305 = "0.10"
tauri-plugin-process = "2"
tauri-plugin-updater = "2"
# One UIKit property that wry does not set for us; stop_uikit_shrinking_the_viewport in lib.rs says
# which one and why. These versions are the ones wry already resolves for its own iOS backend, so
# matching them keeps a single copy of objc2 in the build rather than a second incompatible one.
# Two things wry leaves to us: one UIKit property (stop_uikit_shrinking_the_viewport in lib.rs) and
# the SFSafariViewController that shows the consent page (google/browser.rs). These versions are the
# ones wry already resolves for its own iOS backend, so matching them keeps a single copy of objc2 in
# the build rather than a second incompatible one.
[target.'cfg(target_os = "ios")'.dependencies]
objc2 = "0.6"
objc2-ui-kit = { version = "0.3", default-features = false, features = [
@@ -55,6 +56,14 @@ objc2-ui-kit = { version = "0.3", default-features = false, features = [
"UIView",
"UIScrollView",
] }
objc2-foundation = { version = "0.3", default-features = false, features = [
"std",
"NSString",
"NSURL",
] }
# Only for the null completion handler the two present/dismiss calls take. Passing a raw null
# pointer there would encode as an object rather than a block, which objc2 checks and rejects.
block2 = "0.6"
[dev-dependencies]
tempfile = "3"