Delete the deprecated POST /oauth/google route (#957) - #664
Merged
Merged
Conversation
The MCP authorize page moved to the authorization-code redirect through /oauth/google/start and /oauth/google/callback, so the One Tap tokeninfo route kept no caller in either app or in any documented client. It also created users through a raw repository call instead of an application command. Remove the route, its GoogleAuthRequest record, FindOrCreateGoogleUserAsync, the now orphaned user repository and HTTP client factory dependencies, the OAuthController.GoogleAuth catalog entry and the GoogleTokenAudienceMismatch error, and regenerate openapi.json. The route stayed deprecated on main, so oasdiff reports the removal as api-path-removed-with-deprecation at INFO and the breaking-change gate passes. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
There was a problem hiding this comment.
✅ No new issues found.
Reviewed changes The deprecated MCP One Tap endpoint deletion, its contract and catalog cleanup, and the replacement route assertions were reviewed against the remaining OAuth flow and the sibling consumer.
- Route removal:
POST /oauth/googleand its tokeninfo user provisioning path are deleted;/oauth/google/startand/oauth/google/callbackremain available to the MCP authorize page. - Contract cleanup: OpenAPI removes the deprecated path while the separate
/api/auth/googlerequest schema remains; the now-unused audience mismatch declarations and catalog entry are removed. - Test coverage: The controller test asserts the removed route template is absent across controllers and both replacement templates remain. The sibling shared endpoints target
/api/auth/google, not the deleted route.
GPT Sol | 𝕏
|
thomasluizon
added a commit
that referenced
this pull request
Sep 30, 2026
* Delete the deprecated POST /oauth/google route (#957) (#664) The MCP authorize page moved to the authorization-code redirect through /oauth/google/start and /oauth/google/callback, so the One Tap tokeninfo route kept no caller in either app or in any documented client. It also created users through a raw repository call instead of an application command. Remove the route, its GoogleAuthRequest record, FindOrCreateGoogleUserAsync, the now orphaned user repository and HTTP client factory dependencies, the OAuthController.GoogleAuth catalog entry and the GoogleTokenAudienceMismatch error, and regenerate openapi.json. The route stayed deprecated on main, so oasdiff reports the removal as api-path-removed-with-deprecation at INFO and the breaking-change gate passes. Co-authored-by: Claude Opus 5 <noreply@anthropic.com> (cherry picked from commit e596ee1) * chore: run the Pullfrog reviewer on the Codex harness with gpt-6.1-sol (#668) * chore: run the Pullfrog reviewer on the Codex harness with gpt-6.1-sol The Codex step now sets PULLFROG_AGENT=codex and passes openai/gpt-6.1-sol as a raw model specifier, because no published Pullfrog alias resolves to it yet. The Claude fallback moves to claude-opus-5-5. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * chore: keep the Pullfrog reviewer on the opencode harness at the model's default effort The Codex CLI harness disables multi_agent, which drops the reviewfrog specialist sub-agent, and a raw model specifier has no effort rung, so the effort input was never applied. The review step keeps openai/gpt-6.1-sol on the default opencode harness, where OpenAI's documented default effort is medium. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit c95d548) * Transfer or release a device's push subscription when it changes accounts (#932) (#667) * Transfer a device's push subscription when another account registers it A device keeps one push endpoint or FCM token across the accounts that sign in on it. Before, a second account got PUSH_ENDPOINT_OWNED_BY_OTHER_USER, the client rotated the endpoint, and the first account kept a dead row that counted toward its five-device cap. Now the row moves to the registering account when the request proves it holds the device: a Web Push request must present the stored p256dh key and auth secret, and an FCM request must present the stored token with the FCM sentinel. A request without that proof still gets the old error, so an account cannot take or remove another account's device. Refs thomasluizon/orbit-tickets#932 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * Let the account on a device release its prior account's push row Unsubscribe only removed a row the caller owned. When a browser or Android device stayed registered to a previous account and the account now signed in turned push off, the client dropped the endpoint locally while the previous account kept listing and counting a dead device. Unsubscribe now takes the device's p256dh and auth, which both clients already send, and removes another account's row only when they prove control of the device, using the same check as the subscribe transfer. Without that proof the row stays with its owner and the call still returns success, so it does not reveal who owns an endpoint. Refs thomasluizon/orbit-tickets#932 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix: require explicit cross-account push subscription release * fix: bind push unsubscribe deletion to the observed owner --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> (cherry picked from commit ce78ccb) --------- Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.




Closes #957.
api#660moved the MCP authorize page's Google sign-in to an authorization-code redirect through/oauth/google/startand/oauth/google/callback. It keptPOST /oauth/google(the old One Taptokeninfopath) only so the OpenAPI contract gate would keep passing. This deletes it.What changed
POST /oauth/google, theOAuthController.GoogleAuthRequestrecord andFindOrCreateGoogleUserAsyncare gone fromsrc/Orbit.Api/Controllers/OAuthController.cs.IGenericRepository<User>andIHttpClientFactory, are gone with it, along with the imports they orphaned.OAuthController.GoogleAuthis removed from the agent catalog inAgentCatalogService.Capabilities.cs.ErrorCodes.GoogleTokenAudienceMismatchandErrorMessages.GoogleTokenAudienceMismatchare removed: the deleted route was their only call site.src/Orbit.Api/openapi.jsonis regenerated. Only the/oauth/googlepath entry disappears. TheGoogleAuthRequestcomponent schema stays, because the generator binds that name toAuthController.GoogleAuthRequest, which/api/Auth/googlestill uses.No caller remains
src/Orbit.Api/OAuth/OAuthLoginPage.cslinks to/oauth/google/start.thomasluizon/orbit-ui-mobileon bothorigin/mainandorigin/redesign/main: no source hit foroauth/googleorGOOGLE_TOKEN_AUDIENCE_MISMATCH. The only hit anywhere is a prose line in.claude/specs/orbit-prod-release.mdthat asks for this ticket.Contract gate
The route already carried
deprecated: trueonmain, so no extra record is needed. I built oasdiff v1.32.1, the versionoasdiff/oasdiff-action/breaking@5e81b5cpins in its Dockerfile, and ran it againstorigin/mainwith this repository's.oasdiff.yaml:api-path-removed-with-deprecationis INFO inchecker/rules.go, and the job setsfail-on: ERR, so the OpenAPI Breaking-Change Gate passes.Test evidence
This is a deletion, not a defect fix, so there is no defect to reproduce. The closest equivalent applies: an existing test asserted the opposite of the acceptance criterion, and I ran it unchanged against the deletion before I touched it.
dotnet test tests/Orbit.Infrastructure.Tests --no-build --filter "FullyQualifiedName~OAuthControllerTests.GoogleAuth_RouteRemainsAvailableAndDeprecated"fails for the intended reason:Test inverted to assert the removal.
GoogleAuth_OneTapRoute_IsGoneSoAPostTo_OauthGoogle_Returns404scans everyHttpMethodAttributetemplate on everyControllerBasein theOrbit.Apiassembly, asserts/oauth/googleis absent, and asserts the two replacement routes are still present, so a rename cannot make it pass by accident. Nothing serves/oauth/googleany more, so a POST to it falls through to a 404.After the change, the whole suite passes.
dotnet test Orbit.slnx --no-build:node tools/check-suppression-allowlist.mjs,node tools/check-timeless.mjs --base origin/main,node tools/check-dashes.mjs,node tools/check-root-allowlist.mjsandnode tools/arch-map.mjsall exit 0.Assumptions
ErrorCodes.GoogleTokenAudienceMismatchis deleted rather than kept. The deleted route was its only producer and no consumer references the literalGOOGLE_TOKEN_AUDIENCE_MISMATCHin either repository. Rejected alternative: keeping a dead error code for a route that no longer exists.#pragma warning disable S107on the controller stays, even though the constructor now takes 7 parameters. I could not read Sonar's threshold from a real source, andSonarCloud Code Analysisis a required check, so I left a suppression that may still be live rather than remove it on memory. Rejected alternative: deleting the pragma and itstools/suppression-allowlist.jsonentry.gating-matrix.jsonis left untouched. Running the generator locally rewrote only its provenance hash and input-file count, which is local-environment drift and not a product of this change. Rejected alternative: committing that churn.using System.Security.Claims;inOAuthControllerTests.csstays. It was already unused onmain, so this change did not orphan it. Rejected alternative: an unrelated cleanup in a deletion PR.🤖 Generated with Claude Code