You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Progresses #898. This issue owns protected production verification for Google OAuth.
Agent login
google-labs-jules[bot]
Agent run ID
15243187445261469621
Objective
Verify and safely complete the Google OAuth naming migration for Vercel production by keeping GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET canonical, preserving legacy fallback compatibility until production migration is proven, and recording exact-head and production evidence without exposing secrets.
Acceptance criteria
GOOGLE_CLIENT_ID and GOOGLE_CLIENT_SECRET are canonical.
Legacy GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET remain temporary fallbacks.
Tests prove canonical precedence and backward compatibility.
Environment examples and migration/removal documentation are updated.
Artifact: current exact head includes canonical-name precedence, legacy fallback compatibility, documentation updates, and zero unresolved review threads; protected production verification remains pending
Truth-gate reconciliation — 2026-07-21
Added the machine-readable Agent login and Agent run ID fields without fabricating a snapshot.
Normalized the existing verified checklist as Acceptance criteria.
Added copilot-rabbit authorization and triggered an exact-head reevaluation.
Replaced the generic invalid_payload failure with explicit evidence on run 29821176515.
Pre-dispatch intent snapshot exists: no.
Declared file scope and focused-test contract existed before implementation: no; do not backfill as historical intent.
Trusted terminal result from google-labs-jules[bot] / 15243187445261469621: pending.
Artifact: exact-head code migration is present and review threads are resolved; remaining blockers are procedural truth-gate provenance and protected production verification
Next executable action
Keep work on the canonical PR/branch only. Do not create a competing implementation. If the accepted current-head review opens a valid finding, patch the same branch. Protected deployment verification and an authorized legacy-provenance disposition remain the later human boundaries.
Parent program
Progresses #898. This issue owns protected production verification for Google OAuth.
Agent login
google-labs-jules[bot]Agent run ID
15243187445261469621Objective
Verify and safely complete the Google OAuth naming migration for Vercel production by keeping
GOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRETcanonical, preserving legacy fallback compatibility until production migration is proven, and recording exact-head and production evidence without exposing secrets.Acceptance criteria
GOOGLE_CLIENT_IDandGOOGLE_CLIENT_SECRETare canonical.GOOGLE_OAUTH_CLIENT_IDandGOOGLE_OAUTH_CLIENT_SECRETremain temporary fallbacks.Declared file scope
.env.exampleapps/web/.env.exampleapps/web/src/app/login/GoogleSignInButton.tsxapps/web/src/app/login/page.tsxapps/web/src/lib/__tests__/auth-config-source.test.tsapps/web/src/lib/auth.tsdocs/deployment/VERCEL_PRODUCTION_RUNBOOK.mdFocused test paths
apps/web/src/lib/__tests__/auth-config-source.test.tsAllowed extra files
Current state — CODE GREEN, AUTHORIZED PRODUCTION VERIFICATION PENDING
jules-15243187445261469621-ffdb089ef8800ad3673ab5b11453da249d377f5539c5b152Exact-head and runtime evidence
npm --prefix apps/web test -- --run src/lib/__tests__/auth-config-source.test.tsvalidate: passed on exact headPR Governance: recently alternates across reruns; investigate only against the current exact headCanonical issue and evidence: recently alternates across reruns; investigate only against the current exact headagent-completion/truth-gate: remains the procedural blocker on the current exact headVercel Agent Review: in progress on the current exact headdpl_7DFP2PGLmtiRvPBVi6wqM9tdpTUN, READY frommainat2d660c7e5382db1df5c5eba39537aa9d034376bbRemaining gates — authorized owner
maincommit.mainSHA.No known code blocker remains. A clean runtime window before deploying #903 does not prove the new configuration or real sign-in.
Historical incident fingerprints
SIGNIN_OAUTH_ERRORwith missingclient_idOAUTH_CALLBACK_ERRORwith missing state cookie/api/auth/[...nextauth]Safety boundary
Never place credential values in GitHub, logs, comments, or artifacts. Do not mutate production credentials or deploy without authorized ownership.
Execution receipt
google-labs-jules[bot]/15243187445261469621groupthinking/eventrelay-blocker-watch-20260721-1005zjules-15243187445261469621-ffdb089e2026-07-20T23:55:29Z2026-07-28T10:40:49Zf8800ad3673ab5b11453da249d377f5539c5b152Truth-gate reconciliation — 2026-07-21
copilot-rabbitauthorization and triggered an exact-head reevaluation.invalid_payloadfailure with explicit evidence on run29821176515.google-labs-jules[bot]/15243187445261469621: pending.Controller receipt
groupthinking/eventrelay-blocker-watch-20260721-1005z2026-07-21T10:05:35Z2026-07-28T10:40:49Zf8800ad3673ab5b11453da249d377f5539c5b152Next executable action
Keep work on the canonical PR/branch only. Do not create a competing implementation. If the accepted current-head review opens a valid finding, patch the same branch. Protected deployment verification and an authorized legacy-provenance disposition remain the later human boundaries.