FormidableLabs / FormidableLabs/react-native-app-auth

Google error 401 - The server cannot process the request because it is malformed. It should not be retried.

Offen
#1,111 0 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Java
Sterne
2.3k
Forks
473
PR-Merge-Kennzahlen
Keine gemergten PRs in 30 T.

Beschreibung

## Google 401 Malformed Request on Android when adding new account (Cognito + Google Sync)

Image

### Description
I'm experiencing a **401 Malformed Request** error specifically on Android when using AWS Cognito as an Identity Provider with Google.

The issue occurs only when the device has Google account synchronization active and the user attempts to **add a new Google account** during the sign-in process.

### Steps to Reproduce
1. Trigger the login flow using `authorize` with Google/Cognito.
2. When the Google account selector appears, instead of picking an existing account, select **"Add another account"**.
3. Complete the Android system's native verification (fingerprint/PIN).
4. Enter the new account credentials.
5. The Android system displays a native "Terms and Conditions" / "Google Play Services" acceptance screen.
6. After accepting, instead of redirecting back to the app/Cognito, the browser displays a Google 401 error.

### Observations
* The issue **does not happen** if an existing account from the list is selected.
* The issue **does not happen on iOS**.
* Other providers (Microsoft, Apple) work perfectly.
* The redirected URL in the browser shows `authuser=unknown`, suggesting the session context is lost when the Android System Assistant takes over the UI focus.

### Error URL (Redacted)
`https://accounts.google.com/signin/oauth/consent?authuser=unknown&part=...&flowName=GeneralOAuthFlow&client_id=REDACTED.apps.googleusercontent.com&requestPath=%2Fsignin%2Foauth%2Fconsent#`

### Code Snippet
```javascript
const socialConfig = {
serviceConfiguration: {
authorizationEndpoint: `https://${COGNITO_URL}/oauth2/authorize`,
tokenEndpoint: `https://${COGNITO_URL}/oauth2/token`,
},
clientId: CLIENT_ID,
redirectUrl: REDIRECT_URL,
scopes: ['email', 'openid', 'profile'],
additionalParameters: {
identity_provider: 'Google',
prompt: 'select_account',
},
usePKCE: true,
};

const result = await authorize(socialConfig);
```

## Environment
* **Identity Provider**: `Cognito`
* **Platform experiencing the issue on**: `Android`
* **React Native Version**: `0.83.1`
* **react-native-app-auth Version**: `8.1.0`
* **Platform**: Android (tested on API 36)
* **Device**: Physical device with Google Sync active.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginne mit dem Autorisierungsflow und der bereitgestellten socialConfig, insbesondere mit dem Cognito-Autorisierungsendpunkt, Google identity_provider und den prompt-Einstellungen. Reproduziere das auf einem physischen Android API 36-Gerät mit aktivem Google Sync, indem du „Add another account“ auswählst und die nativen Nutzungsbedingungen von Google Play Services akzeptierst. Erledigt ist es, wenn der Flow zur App bzw. zu Cognito zurückkehrt, anstatt die Google-401-Seite für fehlerhafte Anfragen anzuzeigen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
android, react-native
Bereich
authentication, mobile
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.