feat(ui_oauth_google)!: migrate to google_sign_in 7 - #689
Conversation
Migrates GoogleProvider to the google_sign_in 7 API, which adopts the UIScene lifecycle on iOS (google_sign_in_ios 6.3.0) and Swift Package Manager (6.3.3). Fixes the deprecated application lifecycle warning tracked in firebase#673. - GoogleSignIn is now the shared instance and is initialized once before the first sign-in. - Authentication and authorization are separate steps. The provider reuses an existing authorization for the requested scopes and prompts for consent when one is not available, so the credential still carries an access token when scopes are requested. - A cancelled sign-in surfaces as AuthCancelledException, matching the previous flow reset behaviour. - Adds an optional serverClientId parameter to GoogleProvider, GoogleSignInButton and GoogleSignInIconButton for Android apps that do not use google-services.json. - Updates the integration test mocks to the new API. BREAKING CHANGE: consumers must follow the google_sign_in 7 platform integration steps: GIDClientID in Info.plist on iOS, and on Android a web OAuth client entry in google-services.json or an explicit serverClientId. When no scopes are requested the credential now contains only an ID token.
There was a problem hiding this comment.
Code Review
This pull request upgrades the google_sign_in dependency to version ^7.1.0 and introduces support for serverClientId in GoogleSignInButton, GoogleSignInIconButton, and GoogleProvider. It refactors GoogleProvider to align with the new plugin API, separating authentication and authorization steps and adding initialization logic. Feedback suggests exposing a @visibleForTesting method to reset the static _initialization state to ensure test isolation, as well as simplifying the _ensureInitialized method by chaining the .catchError call directly.
| // google_sign_in 7 requires initialize to be called exactly once, while | ||
| // multiple GoogleProvider instances may be created (for example one per | ||
| // GoogleSignInButton). The first instance to sign in configures the plugin. | ||
| static Future<void>? _initialization; |
There was a problem hiding this comment.
Because _initialization is a static variable, its state will persist across different tests in the same test suite. Since each test in google_sign_in_test.dart injects a new MockGoogleSignIn instance in setUp, subsequent tests will reuse the cached _initialization future from the first test and will not call initialize on their respective mock providers. To ensure proper test isolation and prevent potential flakiness, consider exposing a @visibleForTesting static method to reset _initialization and calling it in the test's setUp block.
| static Future<void>? _initialization; | |
| @visibleForTesting | |
| static void debugReset() { | |
| _initialization = null; | |
| } | |
| static Future<void>? _initialization; |
There was a problem hiding this comment.
Done in 160260b — added a @visibleForTesting debugReset() that clears _initialization, and call it at the top of the test setUp so each test re-initializes on its freshly injected mock.
| Future<void> _ensureInitialized() { | ||
| final initialization = _initialization ??= provider.initialize( | ||
| clientId: _ignoreClientId() ? null : clientId, | ||
| serverClientId: serverClientId, | ||
| ); | ||
|
|
||
| return initialization.catchError((Object err) { | ||
| // Allow a later sign-in attempt to retry initialization instead of | ||
| // rethrowing the same stale error forever. | ||
| _initialization = null; | ||
| throw err; | ||
| }); | ||
| } |
There was a problem hiding this comment.
The _ensureInitialized method can be simplified by chaining the .catchError call directly onto the _initialization ??= assignment. This eliminates the need for the intermediate local variable initialization and makes the code more concise and idiomatic.
Future<void> _ensureInitialized() {
return _initialization ??= provider.initialize(
clientId: _ignoreClientId() ? null : clientId,
serverClientId: serverClientId,
).catchError((Object err) {
// Allow a later sign-in attempt to retry initialization instead of
// rethrowing the same stale error forever.
_initialization = null;
throw err;
});
}There was a problem hiding this comment.
Done in 160260b — chained .catchError directly onto initialize() and dropped the intermediate local.
Chain the retry-reset catchError directly onto initialize() instead of threading an intermediate local, and add a @VisibleForTesting debugReset() that clears the static one-time-init future so each test starts from a clean state with its freshly injected mock. Addresses review feedback on firebase#689.
Description
Migrates
firebase_ui_oauth_googlefrom google_sign_in 6.x to 7.x.google_sign_in 6.x pins apps to google_sign_in_ios 5.x, which still uses the deprecated UIApplication delegate lifecycle. Moving to 7.x resolves google_sign_in_ios 6.3.x, which adopted the UIScene lifecycle in 6.3.0 and added a Swift Package Manager target in 6.3.3. This clears the FLTGoogleSignInPlugin deprecation warning that iOS apps currently log on startup.
What changed:
GoogleProvidernow uses the sharedGoogleSignIn.instanceand initializes it once before the first sign-in.authorizationForScopesand falls back toauthorizeScopes, so the resulting Firebase credential still carries an access token as it did in 6.x. When no scopes are requested the credential contains only an ID token, which is all Firebase Auth needs.GoogleSignInExceptionCode.canceled) is surfaced asAuthCancelledException, so the auth flow resets exactly as before.serverClientIdparameter onGoogleProvider,GoogleSignInButtonandGoogleSignInIconButton. On Android an ID token requires a server client ID. Apps that usegoogle-services.jsoncontaining a web OAuth client entry need no change; other apps can now pass it explicitly.The constraint is
^7.1.0because 7.1.0 added theGoogleSignInExceptionCodeexport needed for structured cancel handling.Verified locally on the workspace:
dart analyzereports no problems,firebase_ui_oauth(7/7) andfirebase_ui_auth(69/69) test suites pass, and thetestspackage compiles against the migrated API.Related Issues
Fixes #673. Related to the wider UIScene migration alongside #672 / #676.
Checklist
Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes (
[x]).This will ensure a smooth and quick review process. Updating the
pubspec.yamland changelogs is not required.///).melos run analyze) does not report any problems on my PR.melos run test:unit:alldoesn't fail).Breaking Change
Does your PR require plugin users to manually update their apps to accommodate your change?
Consumers must follow the google_sign_in 7 platform integration steps:
GIDClientIDin Info.plist on iOS, and on Android a web OAuth client entry ingoogle-services.jsonor an explicitserverClientId. This package would therefore need a major version bump.