diff --git a/apps/api/app/services/provider_oauth.py b/apps/api/app/services/provider_oauth.py index a7b32d9..9ceae97 100644 --- a/apps/api/app/services/provider_oauth.py +++ b/apps/api/app/services/provider_oauth.py @@ -69,7 +69,13 @@ _AGY_OAUTH = { "redirect_uri": "http://localhost:1455/auth/callback", "client_id": "1071006060591-tmhssin2h21lcre235vtolojh4g403ep.apps.googleusercontent.com", "client_secret": "GOCSPX-K58FWR486LdLJ1mLB8sXC4zqDAf", - "scope": "auth/cloud-platform auth/userinfo.email auth/userinfo.profile auth/cclog auth/experimentsandconfigs", + "scope": ( + "https://www.googleapis.com/auth/cloud-platform " + "https://www.googleapis.com/auth/userinfo.email " + "https://www.googleapis.com/auth/userinfo.profile " + "https://www.googleapis.com/auth/cclog " + "https://www.googleapis.com/auth/experimentsandconfigs" + ), "user_agent": "antigravity/cli/1.0.0 (aidev_client; os_type=windows; arch=amd64; auth_method=consumer)", "code_assist_base": "https://cloudcode-pa.googleapis.com", } diff --git a/apps/api/app/test_provider_oauth.py b/apps/api/app/test_provider_oauth.py index 8401c32..c6ee527 100644 --- a/apps/api/app/test_provider_oauth.py +++ b/apps/api/app/test_provider_oauth.py @@ -63,6 +63,21 @@ class StartOAuthTest(unittest.TestCase): self.assertIn("code_challenge_method=S256", result["authorize_url"]) self.assertNotIn("callback_url", result["authorize_url"]) + def test_agy_authorize_url_uses_absolute_scope_urls(self): + # 구글은 축약형(auth/...) 스코프를 인식하지 못해 invalid_scope로 거부한다. + result = svc.start_oauth("agy", "admin@example.com") + authorize_url = result["authorize_url"] + self.assertIn("https://accounts.google.com/o/oauth2/v2/auth?", authorize_url) + for scope in ( + "cloud-platform", + "userinfo.email", + "userinfo.profile", + "cclog", + "experimentsandconfigs", + ): + self.assertIn(f"https://www.googleapis.com/auth/{scope}", authorize_url) + self.assertNotIn("scope=auth/", authorize_url) + def test_pending_expires(self): import time