Skip to content

fix: handle GitHub OAuth denial with friendly retry screen - #344

Open
Victoria-Devo wants to merge 2 commits into
AyinkxLab:mainfrom
Victoria-Devo:fix/issue-58-improve-oauth-denial-and-error-page
Open

Victoria-Devo wants to merge 2 commits into
AyinkxLab:mainfrom
Victoria-Devo:fix/issue-58-improve-oauth-denial-and-error-page

Conversation

@Victoria-Devo

Copy link
Copy Markdown

Overview

This PR replaces the raw OAuth error flash shown when a user denies GitHub access with a friendly cancellation screen, adds a clear "Connect GitHub" retry path on the dashboard, and ensures the callback never leaks the full GitHub error payload.

Related Issue

Changes

🔐 OAuth Callback Handling

  • [MODIFY] app/github/routes.py

    • Treat access_denied from the GitHub callback as a user cancellation rather than an error.
    • Redirect cancelled flows to the new errors/oauth_denied.html screen instead of surfacing the raw error string.
    • Sanitize any other callback failure so only a safe, generic message is passed to the template — the full GitHub error payload is never rendered or logged to the user.
  • [MODIFY] app/services/github.py

    • Distinguish access_denied from genuine OAuth failures when processing the token exchange.
    • Return a structured cancellation result so the route layer can branch on it without inspecting raw provider payloads.

🖥️ Templates

  • [ADD] app/templates/errors/oauth_denied.html

    • Friendly cancellation screen explaining what access would have been granted and why it's requested.
    • "Connect GitHub" retry button that returns the user to the OAuth start flow.
  • [MODIFY] app/templates/github/index.html

    • Dashboard now shows a clear "Connect GitHub" call-to-action when the account is not connected, giving users a retry path after a denial.

⚙️ Frontend

  • [MODIFY] app/static/js/github.js
    • Wire the retry button to re-initiate the GitHub OAuth flow.
    • Ensure no raw provider error text is surfaced in the UI on cancellation.

Verification Results

Manual check:
✅ Denying consent on GitHub lands on the friendly oauth_denied screen (no raw error flash)
✅ "Connect GitHub" retry button on the denial screen and dashboard restarts the OAuth flow
✅ Callback response contains only the generic cancellation message — no full GitHub error payload
Acceptance Criteria Status
access_denied is handled as a user cancellation, not an error ✅ Route and service branch on access_denied and route to the cancellation screen
The GitHub dashboard offers a clear "Connect GitHub" retry path ✅ Retry CTA added to github/index.html and wired in github.js
The callback never leaks the full GitHub error payload ✅ Only a sanitized generic message is passed to templates

Closes #58

@drips-wave

drips-wave Bot commented Sep 30, 2026

Copy link
Copy Markdown

@Victoria-Devo Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Improve OAuth denial and error page

1 participant