feat(auth): add branded OAuth callback pages#52
Merged
Conversation
26 tasks
digitallysavvy
force-pushed
the
feat/login-ui-polish
branch
from
July 22, 2026 14:56
45171d2 to
cf30aff
Compare
Commit the self-contained global and CN success pages. Embed both pages with go:embed and record their design revision and
hashes.
Hold the browser response until token exchange, session persistence, and runtime reset finish. Render regional embedded
templates with safe session details, reject duplicate callbacks, and cover callback failure paths.
Document AGORA_LOGIN_TIMEOUT_MS as 120000 to match the implementation.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds a branded OAuth browser callback page for Agora CLI login success and error states. The page now renders region-aware branding:
cnshows Shengwang copy/logo, while global, empty, or unknown regions default to Agora branding and do not include Shengwang content.Type of change
error.coderename/removal)Public-contract impact
error.code— added todocs/error-codes.md.error.code— flagged as breaking, included in CHANGELOG.docs/automation.md.No CLI flags, JSON envelope shapes, exit codes, or
error.codevalues are changed.Test plan
Added unit tests for OAuth callback page rendering, including global branding, China branding, fallback-to-global behavior, and error-page behavior.
go test ./...passes locally.make lintpasses locally (gofmt,golangci-lint, error-code coverage audit).internal/cli/integration_test.go.internal/cli/app_test.go(where applicable).Ran:
Documentation
CHANGELOG.mdupdated under## Unreleased(Added / Changed / Deprecated / Removed / Fixed / Security).docs/automation.mdupdated for any user-facing JSON shape, env var, or flag change.docs/error-codes.mdupdated for any newerror.code(or N/A).README.mdupdated if the command tree, install path, or quickstart changed.AGENTS.mdupdated if engineering or release process changed.No documentation contract changes are required because this only updates the browser callback page UI.
Security checklist
$HOMEwithout0o600perms when it can contain credentials (e.g. session, config).unsafeimport.Additional notes
The global page references the official Agora logo URL in browser-rendered HTML. The CLI itself does not make an additional network request for that asset.