fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(calendar): restore Google Calendar OAuth connect flow (#61) - #407

Merged
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect
Jul 29, 2026
Merged

fix(calendar): restore Google Calendar OAuth connect flow (#61)#407
AndresL230 merged 2 commits into
mainfrom
fix/61-calendar-oauth-connect

Conversation

@Darkest-Teddy

Copy link
Copy Markdown
Collaborator

Summary

Fixes #61 — Google Calendar sync doesn't work for the calendar feature.

Root cause: The dedicated calendar OAuth connect flow — GET /api/calendar/auth-url and GET /api/calendar/callback — was dropped during the SQLite→Supabase migration (last present in ff814e0), but config.GOOGLE_SCOPES / config.GOOGLE_REDIRECT_URI and the frontend "Connect Google" button (Calendar.tsxcalendarAuthUrl/api/calendar/auth-url) still target it. With the routes gone, clicking "Connect Google" 404'd, so a user could never (re)grant calendar access and /sync, /export, /import all failed with 401 "Not connected to Google Calendar."

This also addresses the #61 comment asking to fix the calendar feature's auth scoping holistically (sibling of the #123 export IDOR, which is already fixed on main).

What changed

  • Restore both OAuth routes in backend/routes/calendar.py, reusing the sign-in flow's OAuth primitives (PKCE + HMAC-signed state cookie) from routes/auth.py as the single source of truth for CSRF — no duplication of the security-critical bits.
  • Holistic auth scoping / CSRF:user_id is sealed into the HMAC-signed state cookie afterrequire_self, and the callback reads it from that cookie — never from a request parameter. So the minted tokens can only ever bind to the session that initiated the connect, and a forged/mismatched state can never drive a token write.
  • Request access_type=offline + prompt=consent so a refresh_token is always returned — otherwise sync silently breaks once the access token expires.
  • Latent refresh bug fix:_get_refreshed_credentials wrote expires_at="" when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration 0024) and "" is not a valid timestamptz (auth.py fixed the identical hazard). Now writes None.

No frontend change needed — the callback redirects to /calendar?connected=true, which Calendar.tsx already handles.

Testing

New backend/tests/test_calendar_oauth_connect.py:

  • auth-url redirects to Google, sets the signed state cookie, requests offline + consent; 400 when Google unconfigured.
  • callback happy path stores tokens bound to the cookie's user_id, on_conflict=user_id, expires_at=None (not "").
  • CSRF boundary: nonce mismatch, missing cookie, and user-denied (?error=) are all rejected with no token write.
  • Refresh writes expires_at=None when creds.expiry is None.
pytest tests/ -q → 979 passed, 5 skipped, 1 error, 1 failed

The 1 failure (test_flashcard_import_service::TestRateLimit, assert 61 <= 60) and 1 error (test_ocr_pipeline::test_save_to_db, event-loop teardown ordering) are pre-existing flakes unrelated to this change — this PR touches only calendar.py + the new test file, and neither suspect imports them (test_ocr_pipeline even passes in isolation). All calendar + auth tests pass (117 passed). ruff check clean.

🤖 Generated with Claude Code

@coderabbitai

coderabbitaiBot commented Jul 22, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@AndresL230, you've reached your PR review limit, so we couldn't start this review.

Next review available in:29 minutes

Enable usage-based reviews in Billing to review now. Otherwise, wait until the next included review is available.
You're only billed for reviews past your plan's rate limits ($0.25/file).

How can I continue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

To avoid repeated limits, reduce automatic review volume by pausing incremental auto-reviews earlier, using label-based review opt-in, excluding WIP or generated PR titles, or requesting reviews manually when the PR is ready. If your team needs uninterrupted high-volume reviews, an organization admin can enable usage-based reviews.

How do review limits work?

CodeRabbit enforces per-developer PR review limits for each organization. Most developers receive the normal plan review availability.

For paid Pro and Pro+ PR reviews, CodeRabbit uses adaptive limits for sustained high-volume activity. When a developer's recent PR review activity reaches the 95th percentile or higher among CodeRabbit users, additional reviews become available more gradually as earlier reviews age out of the rolling window.

Please refer docs for additional details.

Review details
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: CHILL

Plan: Pro Plus

Run ID: 8ef637e2-2c1e-48ac-b6aa-13830d57735a

📥 Commits

Reviewing files that changed from the base of the PR and between fb415f9 and 62a97c1.

📒 Files selected for processing (3)
  • backend/db/migrations/0034_oauth_tokens_nullable_expiry.sql
  • backend/routes/calendar.py
  • backend/tests/test_calendar_oauth_connect.py

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@cloudflare-workers-and-pages

cloudflare-workers-and-pagesBot commented Jul 22, 2026

Copy link
Copy Markdown

Deploying with Cloudflare Workers Cloudflare Workers

The latest updates on your project. Learn more about integrating Git with Workers.

StatusNameLatest CommitPreview URLUpdated (UTC)
✅ Deployment successful!
View logs
frontend-staging62a97c1Commit Preview URL

Branch Preview URL
Jul 29 2026, 10:28 AM

@AndresL230
AndresL230 marked this pull request as draft July 27, 2026 23:50
Rebase of PR #407 onto current main (ea2ab0b, ~127 commits ahead of the
original branch point). The true diff applied cleanly with git apply -3;
no textual conflicts. Re-verified every reused primitive against main's
evolved auth/encryption structure (0024 identity split).
The dedicated calendar consent flow — GET /api/calendar/auth-url and
/api/calendar/callback — was dropped in the SQLite→Supabase migration, but
config.GOOGLE_SCOPES / GOOGLE_REDIRECT_URI and the frontend "Connect Google"
button (Calendar.tsx → calendarAuthUrl) still point at it. With the routes
gone, clicking "Connect Google" 404'd, so users could never (re)grant
calendar access and /sync, /export, /import all failed with 401
"Not connected to Google Calendar." This is the root cause of #61.
- Restore both routes, reusing the sign-in flow's OAuth primitives (PKCE +
HMAC-signed state cookie) from routes/auth.py as the single source of truth
for CSRF handling — no duplication of the security-critical bits. On current
main these helpers still live in routes/auth.py (session minting moved to
services/session_tokens.py, but the OAuth state/PKCE helpers did not).
- Auth scoping (the #61 comment, sibling of the #123 export IDOR): the
user_id is sealed into the signed state cookie after require_self, and the
callback reads it from that cookie — never from a request parameter — so
the minted tokens can only ever bind to the session that initiated connect.
- Request access_type=offline + prompt=consent so a refresh_token is always
returned; otherwise sync breaks once the access token expires.
- Token storage follows main's encryption boundaries: encrypt(access_token),
encrypt_if_present(refresh_token), upsert on_conflict=user_id — byte-for-
byte the same shape as the sign-in callback's oauth_tokens write.
- Fix a latent refresh bug: _get_refreshed_credentials wrote expires_at=""
when a refresh yielded no expiry, but expires_at is TIMESTAMPTZ (migration
0024) and "" is not a valid timestamptz (auth.py fixed the same hazard).
- The calendar flow uses GOOGLE_REDIRECT_URI (/api/calendar/callback), kept
distinct from the sign-in flow's GOOGLE_AUTH_REDIRECT_URI, via
_calendar_client_config re-pointing the shared client config.
Tests: new test_calendar_oauth_connect.py covers the happy path, the CSRF
boundary (nonce mismatch / missing cookie / user-denied), token binding to
the cookie user, and the expires_at=None refresh fix. Full suite green on
main's tip: 1231 passed, 27 skipped. ruff check clean (zero findings, same
as the origin/main baseline).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230force-pushed the fix/61-calendar-oauth-connect branch from c6eeed2 to 0dd341dCompareJuly 29, 2026 10:10
@AndresL230
AndresL230 marked this pull request as ready for review July 29, 2026 10:10
…rite needs schema backing (review finding)
The expires_at=None 'fix' traded an invalid-timestamptz cast for a
not-null violation (0001 baseline constraint; 0024 only retyped the
column) — a refresh PATCH would 500 AND lose the fresh access_token.
Readers already treat NULL as 'no known expiry'.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@AndresL230
AndresL230 merged commit 4d4c00c into mainJul 29, 2026
6 checks passed
@AndresL230
AndresL230 deleted the fix/61-calendar-oauth-connect branch August 2, 2026 18:30
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@Darkest-Teddy@AndresL230