google / google/GoogleSignIn-iOS

GIDSignInCompletion block not called when ASWebAuthenticationSession is interrupted by device locking

Abierto
#578 1 comentario 0 reacciones 0 asignados Ver en GitHub
bug
Lenguaje dominante
Objective-C
Estrellas
750
Forks
282
Merge medio
2 d 15 h
PR fusionados (30 d)
9

Descripción

**Describe the bug**
When using Google Sign-In SDK on iOS, if the user locks their device or the app transitions to background during the authentication flow (while `ASWebAuthenticationSession` is active), the `GIDSignInCompletion` block is never called. This leaves the app in an indefinite loading/blocked state with no way to detect that the session was interrupted or cancelled by the OS.

**To Reproduce**
1. Initiate Google Sign-In flow in an iOS app
2. Wait for the `ASWebAuthenticationSession` system prompt to appear
3. Lock the device before completing authentication
4. Unlock the device and return to the app
5. Observe that the `GIDSignInCompletion` block is never called (no success, no error, no cancellation callback) and the `ASWebAuthenticationSession` alert is dismissed.

**Expected behavior**
The `GIDSignInCompletion` block should be invoked with either:
1. A cancellation result/error indicating the session was interrupted, OR
2. A property that allows detection of this interrupted state

This would allow the host app to reset its UI state (e.g., hide loading indicators, re-enable the sign-in button).

**Screenshots**
N/A.

**Environment**
- Device: iPhone (various models)
- OS: iOS (tested on iOS26, iOS18)
- SDK: Google Sign-In SDK for iOS

**Additional context**
This issue stems from how iOS handles `ASWebAuthenticationSession` interruptions. When the device is locked or the app goes to background, iOS may dismiss the authentication prompt without reliably delivering a cancellation callback to the SDK.
A similar issue has been reported by multiple users in the AppAuth-iOS repository: https://github.com/openid/AppAuth-iOS/issues/468. A fix for the SDK is observing the app's background/foreground state transitions and invoking the completion block if a previously active session was found. We recommend Google Sign-In SDK implement a similar mechanism to detect interrupted sessions and return an appropriate callback to the host application.

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.