Skip to content

Report error if session token is not present in complete_oauth_flow#7259

Open
bendk wants to merge 1 commit intomozilla:mainfrom
bendk:push-vulxwvnlwyny
Open

Report error if session token is not present in complete_oauth_flow#7259
bendk wants to merge 1 commit intomozilla:mainfrom
bendk:push-vulxwvnlwyny

Conversation

@bendk
Copy link
Contributor

@bendk bendk commented Mar 5, 2026

We've been getting a bunch of No stored session token error reports and have been discussing this on slack. My theory is that somehow the oauth flow is completing without a session token. Maybe because the set_user_data is coming after the complete_oauth_flow call.

This tries to validate that theory by reporting errors when complete_oauth_flow is called without a session token. Note that this won't lead always lead to the error state if set_user_data is called shortly after. However it could, for example if some exception prevents the set_user_data call, or Firefox exits early.

Pull Request checklist

  • Breaking changes: This PR follows our breaking change policy
    • This PR follows the breaking change policy:
      • This PR has no breaking API changes, or
      • There are corresponding PRs for our consumer applications that resolve the breaking changes and have been approved
  • Quality: This PR builds and tests run cleanly
    • Note:
      • For changes that need extra cross-platform testing, consider adding [ci full] to the PR title.
      • If this pull request includes a breaking change, consider cutting a new release after merging.
  • Tests: This PR includes thorough tests or an explanation of why it does not
  • Changelog: This PR includes a changelog entry in CHANGELOG.md or an explanation of why it does not need one
    • Any breaking changes to Swift or Kotlin binding APIs are noted explicitly
  • Dependencies: This PR follows our dependency management guidelines
    • Any new dependencies are accompanied by a summary of the due diligence applied in selecting them.

We've been getting a bunch of `No stored session token` error reports
and have been discussing this on slack.  My theory is that somehow the
oauth flow is completing without a session token.  Maybe because the
`set_user_data` is coming after the `complete_oauth_flow` call.

This tries to validate that theory by reporting errors when
`complete_oauth_flow` is called without a session token.  Note that this
won't lead always lead to the error state if `set_user_data` is called
shortly after.  However it could, for example if some exception prevents
the `set_user_data` call, or Firefox exits early.
@bendk bendk requested a review from mhammond March 5, 2026 15:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants