Skip to content

feat(ui_oauth_google)!: migrate to google_sign_in 7 - #700

Open
bjrochem72 wants to merge 4 commits into
firebase:mainfrom
bjrochem72:google-sign-in-7
Open

bjrochem72 wants to merge 4 commits into
firebase:mainfrom
bjrochem72:google-sign-in-7

Conversation

@bjrochem72

Copy link
Copy Markdown
Contributor

Re-opening the change from #689. That PR was merged and then reverted from main while breaking changes are held for the upcoming release. Same changes here, ready to merge after today's normal release.

Description

Migrates firebase_ui_oauth_google from google_sign_in 6.x to 7.x.

google_sign_in 6.x pins apps to google_sign_in_ios 5.x, which still uses the deprecated UIApplication delegate lifecycle. Moving to 7.x resolves google_sign_in_ios 6.3.x, which adopted the UIScene lifecycle in 6.3.0 and added a Swift Package Manager target in 6.3.3. This clears the FLTGoogleSignInPlugin deprecation warning that iOS apps currently log on startup.

What changed:

  • GoogleProvider now uses the shared GoogleSignIn.instance and initializes it once before the first sign-in.
  • Authentication and authorization are separate steps in google_sign_in 7. When scopes are requested, the provider first tries authorizationForScopes and falls back to authorizeScopes, so the resulting Firebase credential still carries an access token as it did in 6.x. When no scopes are requested the credential contains only an ID token, which is all Firebase Auth needs.
  • A cancelled sign-in (GoogleSignInExceptionCode.canceled) is surfaced as AuthCancelledException, so the auth flow resets exactly as before.
  • New optional serverClientId parameter on GoogleProvider, GoogleSignInButton and GoogleSignInIconButton. On Android an ID token requires a server client ID. Apps that use google-services.json containing a web OAuth client entry need no change; other apps can now pass it explicitly.
  • The existing integration test is migrated to mock the new API.

The constraint is ^7.1.0 because 7.1.0 added the GoogleSignInExceptionCode export needed for structured cancel handling.

Verified locally on the workspace: dart analyze reports no problems, firebase_ui_oauth (7/7) and firebase_ui_auth (69/69) test suites pass, and the tests package compiles against the migrated API.

Related Issues

Fixes #673. Related to the wider UIScene migration alongside #672 / #676.

Checklist

Before you create this PR confirm that it meets all requirements listed below by checking the relevant checkboxes ([x]).
This will ensure a smooth and quick review process. Updating the pubspec.yaml and changelogs is not required.

  • I read the Contributor Guide and followed the process outlined there for submitting PRs.
  • My PR includes unit or integration tests for all changed/updated/fixed behaviors (See Contributor Guide).
  • All existing and new tests are passing.
  • I updated/added relevant documentation (doc comments with ///).
  • The analyzer (melos run analyze) does not report any problems on my PR.
  • All unit tests pass (melos run test:unit:all doesn't fail).
  • I read and followed the Flutter Style Guide.
  • I signed the CLA.
  • I am willing to follow-up on review comments in a timely manner.

bjrochem72 and others added 3 commits September 14, 2026 16:40
Migrates GoogleProvider to the google_sign_in 7 API, which adopts the
UIScene lifecycle on iOS (google_sign_in_ios 6.3.0) and Swift Package
Manager (6.3.3). Fixes the deprecated application lifecycle warning
tracked in firebase#673.

- GoogleSignIn is now the shared instance and is initialized once
  before the first sign-in.
- Authentication and authorization are separate steps. The provider
  reuses an existing authorization for the requested scopes and prompts
  for consent when one is not available, so the credential still
  carries an access token when scopes are requested.
- A cancelled sign-in surfaces as AuthCancelledException, matching the
  previous flow reset behaviour.
- Adds an optional serverClientId parameter to GoogleProvider,
  GoogleSignInButton and GoogleSignInIconButton for Android apps that
  do not use google-services.json.
- Updates the integration test mocks to the new API.

BREAKING CHANGE: consumers must follow the google_sign_in 7 platform
integration steps: GIDClientID in Info.plist on iOS, and on Android a
web OAuth client entry in google-services.json or an explicit
serverClientId. When no scopes are requested the credential now
contains only an ID token.
Chain the retry-reset catchError directly onto initialize() instead of
threading an intermediate local, and add a @VisibleForTesting
debugReset() that clears the static one-time-init future so each test
starts from a clean state with its freshly injected mock.

Addresses review feedback on firebase#689.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request upgrades the google_sign_in dependency to version 7.1.0 and updates the GoogleProvider implementation to align with the new API, which requires explicit initialization and the use of authenticate instead of signIn. Additionally, support for serverClientId is added, and the test suite is updated to mock the new initialization and authentication methods. A review comment suggests improving error handling in _ensureInitialized by using a try-catch block with rethrow to preserve stack traces during debugging.

Comment on lines +90 to +102
Future<void> _ensureInitialized() {
return _initialization ??= provider
.initialize(
clientId: _ignoreClientId() ? null : clientId,
serverClientId: serverClientId,
)
.catchError((Object err) {
// Allow a later sign-in attempt to retry initialization instead of
// rethrowing the same stale error forever.
_initialization = null;
throw err;
});
}

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

medium

Using .catchError and then throwing the error with throw err resets the stack trace to the current line, which makes debugging production errors much harder because the original stack trace of the initialization failure is lost.

Instead, use a standard try-catch block with rethrow to preserve the original stack trace. This is also more idiomatic in Dart than chaining .catchError on a future.

  Future<void> _ensureInitialized() async {
    if (_initialization != null) {
      await _initialization;
      return;
    }

    try {
      _initialization = provider.initialize(
        clientId: _ignoreClientId() ? null : clientId,
        serverClientId: serverClientId,
      );
      await _initialization;
    } catch (err) {
      _initialization = null;
      rethrow;
    }
  }

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Good catch, thanks. Fixed in 27ea07d — kept the memoised retry-reset structure and swapped the bare throw err for Error.throwWithStackTrace(err, stackTrace), which preserves the original initialization stack trace.

Use Error.throwWithStackTrace in the initialize() catchError so a failed initialization keeps its original stack trace instead of resetting it with a bare throw.
@bjrochem72

Copy link
Copy Markdown
Contributor Author

Hi Russell, thanks for the heads-up, no problem at all. I have reopened the change here with the same commits, rebased onto current main, so it is ready to merge after today's release whenever suits. I also rebased the small sibling PR #676 (a non-breaking one-line widening of the app_links constraint) in case it is useful for today's normal release. Thanks again.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

firebase_ui_oauth_google: adopt google_sign_in 7.x (UIScene support; 6.x uses deprecated lifecycle events)

1 participant