google / google/GoogleSignIn-iOS

GIDSignInCompletion block not called when ASWebAuthenticationSession is interrupted by device locking

未关闭
#578 1 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
Objective-C
星标
751
派生
282
平均合并
2 天 15 小时
30 天内合并 PR
9

描述

**Describe the bug**
When using Google Sign-In SDK on iOS, if the user locks their device or the app transitions to background during the authentication flow (while `ASWebAuthenticationSession` is active), the `GIDSignInCompletion` block is never called. This leaves the app in an indefinite loading/blocked state with no way to detect that the session was interrupted or cancelled by the OS.

**To Reproduce**
1. Initiate Google Sign-In flow in an iOS app
2. Wait for the `ASWebAuthenticationSession` system prompt to appear
3. Lock the device before completing authentication
4. Unlock the device and return to the app
5. Observe that the `GIDSignInCompletion` block is never called (no success, no error, no cancellation callback) and the `ASWebAuthenticationSession` alert is dismissed.

**Expected behavior**
The `GIDSignInCompletion` block should be invoked with either:
1. A cancellation result/error indicating the session was interrupted, OR
2. A property that allows detection of this interrupted state

This would allow the host app to reset its UI state (e.g., hide loading indicators, re-enable the sign-in button).

**Screenshots**
N/A.

**Environment**
- Device: iPhone (various models)
- OS: iOS (tested on iOS26, iOS18)
- SDK: Google Sign-In SDK for iOS

**Additional context**
This issue stems from how iOS handles `ASWebAuthenticationSession` interruptions. When the device is locked or the app goes to background, iOS may dismiss the authentication prompt without reliably delivering a cancellation callback to the SDK.
A similar issue has been reported by multiple users in the AppAuth-iOS repository: https://github.com/openid/AppAuth-iOS/issues/468. A fix for the SDK is observing the app's background/foreground state transitions and invoking the completion block if a previously active session was found. We recommend Google Sign-In SDK implement a similar mechanism to detect interrupted sessions and return an appropriate callback to the host application.

贡献指南

打开贡献指南

调研方向

首先跟踪 SDK 的 ASWebAuthenticationSession 生命周期,以及应用在后台和前台之间切换时的处理方式。将此处描述的中断行为与 AppAuth-iOS issue 468 进行比较。当中断的会话通过取消或其他可检测的错误调用 GIDSignInCompletion,使宿主应用能够重置其 UI 时,即视为完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
ios, objective-c
领域
authentication, mobile
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。