Oauth Callback
GET/api/v2/authentication/oauth/:provider/callback
Handle the provider's redirect back, then always hand the browser to the frontend.
Never returns an error response to the browser -- handle_oauth_callback never raises, so
every outcome becomes a status=... query param on the redirect. That includes the user
denying consent: Google then redirects here with error=access_denied and no code at
all, so code is an optional query param rather than a required one (a required, missing
code would otherwise fail FastAPI's own request validation before this handler runs,
surfacing a raw JSON 422 instead of the frontend redirect every other failure gets).
state is optional for the same reason -- Google itself always echoes it back, but a
malformed or bot-issued hit on this URL might not carry one at all.
Request
Responses
- 200
- 422
Successful Response
Validation Error