Skip to content

Work / Scrvio / Wiki / Surfaces

oauth-callback

Surfacecanonicalverified 2026-10-04

SURFACE.WEB.OAUTH-CALLBACK

Summary

The page Google redirects back to after consent.

Raw wireframe

  • .context/designs/web/auth/callback.html
  • .context/designs/web/auth/callback-error.html

Why it is drawn this way

It normally lives in a popup. With a code in a popup it posts OAUTH_CODE to the opener and waits. The opener finishes the login. The user sees the spinner for a moment.

Outside a popup it gives up and goes to login. A code in a full tab falls through to router.push("/auth/login"). The drawing links the "Processing authentication..." text to login to show that edge. The app has no link there.

The error state is the non-popup ?error=. In a popup the error is posted to the opener and the window closes. Only a full tab shows "Authentication Error".

The error text is the raw query param. It prints whatever ?error= holds, for example access_denied.

It renders inside the auth shell. The route is under /auth, so the spinner sits in the card beside the benefits list.

Related

Sources

  • apps/website/src/app/auth/callback/[provider]/page.tsx
  • packages/ui/src/hooks/use-auth.ts