fix(auth): prefer canonical Google OAuth env names - #1720
Draft
groupthinking with Copilot wants to merge 2 commits into
Draft
fix(auth): prefer canonical Google OAuth env names#1720groupthinking with Copilot wants to merge 2 commits into
groupthinking with Copilot wants to merge 2 commits into
Conversation
Contributor
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
12 tasks
Co-authored-by: groupthinking <154503486+groupthinking@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Verify Google OAuth in Vercel production
fix(auth): prefer canonical Google OAuth env names
Sep 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Canonical issue
Outcome
Canonical Google OAuth variables now take precedence without breaking Vercel environments still using legacy names. Production credential, redirect URI, and real callback verification remain protected operator actions.
Scope
GOOGLE_CLIENT_ID/GOOGLE_CLIENT_SECRET.GOOGLE_OAUTH_*as temporary fallbacks.Risk
Verification
Focused test run on
35dd63bdf33707cd7de5e57ce9d939447dc308c2.npm --prefix apps/web test -- --run src/lib/__tests__/auth-config-source.test.tsProduction evidence
Not applicable to this code-only change. Protected production verification requires canonical Vercel variables, redirect URI
https://uvai.io/api/auth/callback/google, a deployedmainSHA, and a real Google callback.Agent handoff