Skip to content

feat(ui_oauth_google)!: migrate to google_sign_in 7 - #689

Open
bjrochem72 wants to merge 2 commits into
firebase:mainfrom
bjrochem72:google-sign-in-7
Open

feat(ui_oauth_google)!: migrate to google_sign_in 7#689
bjrochem72 wants to merge 2 commits into
firebase:mainfrom
bjrochem72:google-sign-in-7

Conversation

@bjrochem72

Copy link
Copy Markdown

Description

Migrates firebase_ui_oauth_google from google_sign_in 6.x to 7.x.

google_sign_in 6.x pins apps to google_sign_in_ios 5.x, which still uses the deprecated UIApplication delegate lifecycle. Moving to 7.x resolves google_sign_in_ios 6.3.x, which adopted the UIScene lifecycle in 6.3.0 and added a Swift Package Manager target in 6.3.3. This clears the FLTGoogleSignInPlugin deprecation warning that iOS apps currently log on startup.

What changed:

  • GoogleProvider now uses the shared GoogleSignIn.instance and initializes it once before the first sign-in.
  • Authentication and authorization are separate steps in google_sign_in 7. When scopes are requested, the provider first tries authorizationForScopes and falls back to authorizeScopes, so the resulting Firebase credential still carries an access token as it did in 6.x. When no scopes are requested the credential contains only an ID token, which is all Firebase Auth needs.
  • A cancelled sign-in (GoogleSignInExceptionCode.canceled) is surfaced as AuthCancelledException, so the auth flow resets exactly as before.
  • New optional serverClientId parameter on GoogleProvider, GoogleSignInButton and GoogleSignInIconButton. On Android an ID token requires a server client ID. Apps that use google-services.json containing a web OAuth client entry need no change; other apps can now pass it explicitly.
  • The existing integration test is migrated to mock the new API.

The constraint is ^7.1.0 because 7.1.0 added the GoogleSignInExceptionCode export needed for structured cancel handling.

Verified locally on the workspace: dart analyze reports no problems, firebase_ui_oauth (7/7) and firebase_ui_auth (69/69) test suites pass, and the tests package compiles against the migrated API.

Related Issues

Fixes #673. Related to the wider UIScene migration alongside #672 / #676.

Checklist

Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes ([x]).
This will ensure a smooth and quick review process. Updating the pubspec.yaml and changelogs is not required.

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • My PR includes unit or integration tests for all changed/updated/fixed behaviors (See Contributor Guide).
  • All existing and new tests are passing.
  • I updated/added relevant documentation (doc comments with ///).
  • The analyzer (melos run analyze) does not report any problems on my PR.
  • All unit tests pass (melos run test:unit:all doesn't fail).
  • I read and followed the Flutter Style Guide.
  • I signed the CLA.
  • I am willing to follow-up on review comments in a timely manner.

Breaking Change

Does your PR require plugin users to manually update their apps to accommodate your change?

  • Yes, this is a breaking change.
  • No, this is not a breaking change.

Consumers must follow the google_sign_in 7 platform integration steps: GIDClientID in Info.plist on iOS, and on Android a web OAuth client entry in google-services.json or an explicit serverClientId. This package would therefore need a major version bump.

Migrates GoogleProvider to the google_sign_in 7 API, which adopts the
UIScene lifecycle on iOS (google_sign_in_ios 6.3.0) and Swift Package
Manager (6.3.3). Fixes the deprecated application lifecycle warning
tracked in firebase#673.

- GoogleSignIn is now the shared instance and is initialized once
  before the first sign-in.
- Authentication and authorization are separate steps. The provider
  reuses an existing authorization for the requested scopes and prompts
  for consent when one is not available, so the credential still
  carries an access token when scopes are requested.
- A cancelled sign-in surfaces as AuthCancelledException, matching the
  previous flow reset behaviour.
- Adds an optional serverClientId parameter to GoogleProvider,
  GoogleSignInButton and GoogleSignInIconButton for Android apps that
  do not use google-services.json.
- Updates the integration test mocks to the new API.

BREAKING CHANGE: consumers must follow the google_sign_in 7 platform
integration steps: GIDClientID in Info.plist on iOS, and on Android a
web OAuth client entry in google-services.json or an explicit
serverClientId. When no scopes are requested the credential now
contains only an ID token.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request upgrades the google_sign_in dependency to version ^7.1.0 and introduces support for serverClientId in GoogleSignInButton, GoogleSignInIconButton, and GoogleProvider. It refactors GoogleProvider to align with the new plugin API, separating authentication and authorization steps and adding initialization logic. Feedback suggests exposing a @visibleForTesting method to reset the static _initialization state to ensure test isolation, as well as simplifying the _ensureInitialized method by chaining the .catchError call directly.

// google_sign_in 7 requires initialize to be called exactly once, while
// multiple GoogleProvider instances may be created (for example one per
// GoogleSignInButton). The first instance to sign in configures the plugin.
static Future<void>? _initialization;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Because _initialization is a static variable, its state will persist across different tests in the same test suite. Since each test in google_sign_in_test.dart injects a new MockGoogleSignIn instance in setUp, subsequent tests will reuse the cached _initialization future from the first test and will not call initialize on their respective mock providers. To ensure proper test isolation and prevent potential flakiness, consider exposing a @visibleForTesting static method to reset _initialization and calling it in the test's setUp block.

Suggested change
static Future<void>? _initialization;
@visibleForTesting
static void debugReset() {
_initialization = null;
}
static Future<void>? _initialization;

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 160260b — added a @visibleForTesting debugReset() that clears _initialization, and call it at the top of the test setUp so each test re-initializes on its freshly injected mock.

Comment on lines +81 to +93
Future<void> _ensureInitialized() {
final initialization = _initialization ??= provider.initialize(
clientId: _ignoreClientId() ? null : clientId,
serverClientId: serverClientId,
);

return initialization.catchError((Object err) {
// Allow a later sign-in attempt to retry initialization instead of
// rethrowing the same stale error forever.
_initialization = null;
throw err;
});
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

The _ensureInitialized method can be simplified by chaining the .catchError call directly onto the _initialization ??= assignment. This eliminates the need for the intermediate local variable initialization and makes the code more concise and idiomatic.

  Future<void> _ensureInitialized() {
    return _initialization ??= provider.initialize(
      clientId: _ignoreClientId() ? null : clientId,
      serverClientId: serverClientId,
    ).catchError((Object err) {
      // Allow a later sign-in attempt to retry initialization instead of
      // rethrowing the same stale error forever.
      _initialization = null;
      throw err;
    });
  }

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done in 160260b — chained .catchError directly onto initialize() and dropped the intermediate local.

Chain the retry-reset catchError directly onto initialize() instead of
threading an intermediate local, and add a @VisibleForTesting
debugReset() that clears the static one-time-init future so each test
starts from a clean state with its freshly injected mock.

Addresses review feedback on firebase#689.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

firebase_ui_oauth_google: adopt google_sign_in 7.x (UIScene support; 6.x uses deprecated lifecycle events)

1 participant