Skip to content

fix: use a google web oauth client for mcp and device sign-in - #928

Merged
leynier merged 2 commits into
mainfrom
fix/mcp-web-google-oauth-client
Oct 10, 2026
Merged

leynier merged 2 commits into
mainfrom
fix/mcp-web-google-oauth-client

Conversation

@leynier

@leynier leynier commented Oct 10, 2026 •

Copy link
Copy Markdown
Owner

Summary

MCP and device sign-in redirect to https://api.alera.build/oauth/callback. Production had no web OAuth clients, so the cloud reused the desktop clients: Google's desktop client only accepts loopback redirects (redirect_uri_mismatch), and the GitHub OAuth App only listed http://127.0.0.1/callback.

  • Sets web_google_oauth_client_id to the new Google web client Alera Web, whose only redirect is the API callback. Its secret already has version 1 in alera-web-google-oauth-client-secret, so the new Cloud Run revision can read it.
  • GitHub keeps the desktop OAuth App: the API callback was added as a second redirect URI, so no web GitHub client is needed.
  • Updates docs/remote-mcp.md and the secret list in infra/production/readme.md.

Validation

  • The secret version exists and is enabled before this change deploys.
  • After deploy: start the ChatGPT connector sign-in with Google and GitHub.

Risk

Cloud Deploy creates a revision with the new env and secret; a failed verification rolls back automatically.

The web sign-in redirects to https://api.alera.build/oauth/callback, which the
Google desktop client cannot accept, so Google answered redirect_uri_mismatch.
Production now sets the new Alera Web client id; its secret is in
alera-web-google-oauth-client-secret. GitHub keeps the desktop OAuth App, which
now lists the web callback as a second redirect URI.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Important

Production deploy will mount a Google secret the preflight does not check.

Reviewed changes

Reviewed the production OAuth client change for MCP and device sign-in.

  • Web Google client: Sets web_google_oauth_client_id, which injects ALERA_WEB_GOOGLE_CLIENT_ID and mounts alera-web-google-oauth-client-secret on the Cloud Run revision.
  • GitHub reuse: Leaves the web GitHub client unset so the browser leg keeps the desktop OAuth App credentials and the API callback.
  • Docs: docs/remote-mcp.md and infra/production/readme.md describe that split.

Pullfrog  | Fix all ➔ | Fix 👍s ➔ | View workflow run | Using grok-4.7 | 𝕏

Comment thread infra/production/production.auto.tfvars
A web client id mounts its secret on the Cloud Run revision, so the preflight
now checks that secret has an enabled version before the image build, and the
setup and operations docs list it. The setup guide also records the API
callback as the GitHub OAuth App's second redirect URI.

@pullfrog pullfrog Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

✅ No new issues found.

Reviewed changes

Reviewed the production preflight and operator docs added since the prior review.

  • Web secret gate: Required an enabled alera-web-{provider}-oauth-client-secret in Production Preflight when production.auto.tfvars sets that provider's web client id, so a missing Google secret fails before the image build and an unset GitHub web client does not.
  • Operator docs: Recorded the Google web client, the API callback on the desktop GitHub OAuth App, and which web secrets need a version before apply.

Pullfrog  | View workflow run | Using grok-4.7 | 𝕏

@leynier
leynier merged commit 2aa0a6a into main Oct 10, 2026
24 checks passed
@leynier
leynier deleted the fix/mcp-web-google-oauth-client branch October 10, 2026 06:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant