Fix OAuth state validation error by specifying authentication scheme in callback

Co-authored-by: clayschaad <11883505+clayschaad@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot] 2025-08-27 16:21:18 +00:00
parent 0fac698803
commit aa56f84f34

View file

@ -1,4 +1,5 @@
using Microsoft.AspNetCore.Authentication; using Microsoft.AspNetCore.Authentication;
using Microsoft.AspNetCore.Authentication.Cookies;
using Microsoft.AspNetCore.Authentication.Google; using Microsoft.AspNetCore.Authentication.Google;
using Microsoft.AspNetCore.Authorization; using Microsoft.AspNetCore.Authorization;
using Microsoft.AspNetCore.Mvc; using Microsoft.AspNetCore.Mvc;
@ -29,14 +30,15 @@ namespace ShiftScheduler.Server.Controllers
[HttpGet("callback")] [HttpGet("callback")]
public async Task<IActionResult> Callback() public async Task<IActionResult> Callback()
{ {
var result = await HttpContext.AuthenticateAsync(); // Explicitly specify the Google authentication scheme for the callback
if (!result.Succeeded) var result = await HttpContext.AuthenticateAsync(GoogleDefaults.AuthenticationScheme);
if (!result.Succeeded || result.Principal == null)
{ {
return Redirect("/?error=auth_failed"); return Redirect("/?error=auth_failed");
} }
var emailClaim = result.Principal?.FindFirst(ClaimTypes.Email) ?? var emailClaim = result.Principal.FindFirst(ClaimTypes.Email) ??
result.Principal?.FindFirst("email"); result.Principal.FindFirst("email");
if (emailClaim?.Value == null || !_authorizedEmails.Contains(emailClaim.Value)) if (emailClaim?.Value == null || !_authorizedEmails.Contains(emailClaim.Value))
{ {
@ -44,6 +46,9 @@ namespace ShiftScheduler.Server.Controllers
return Redirect("/?error=unauthorized"); return Redirect("/?error=unauthorized");
} }
// Sign in with the cookie scheme after successful Google authentication
await HttpContext.SignInAsync(result.Principal);
return Redirect("/"); return Redirect("/");
} }