• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

supabase / supabase-swift / 35210399762
90%

Build:
DEFAULT BRANCH: main
Ran 17 Sep 2026 10:29AM UTC
Jobs 1
Files 134
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

17 Sep 2026 10:25AM UTC coverage: 88.939% (+0.07%) from 88.867%
35210399762

push

github

web-flow
fix(auth): listen on the callback scheme the provider redirects to (#1363)

The two halves of the ASWebAuthenticationSession flow resolved the
redirect with opposite precedence. The authorize request used
`redirectTo ?? configuration.redirectToURL`, so the provider sent the
user to the per-call URL; the session was told to listen on
`(configuration.redirectToURL ?? redirectTo)?.scheme`, the configured
one. A client that set both with different schemes therefore listened
on a scheme the provider never redirected to: the callback was never
matched, the continuation never resumed, and the flow hung with no
error until the user cancelled — surfacing as canceledLogin, which
points nowhere near the cause.

Inverting the one expression would have fixed the symptom. The cause is
that the rule was written out twice, in two functions, which is what
let them drift apart in the first place. So the precedence now lives in
oauthRedirectURL(redirectTo:configured:), both halves route through it,
and oauthCallbackScheme takes the already-resolved URL instead of
re-deriving it. Disagreement stops being a thing that has to be
remembered and becomes structurally impossible.

Two invariants, two tests. prefersThePerCallURLOverTheConfiguredOne
pins which URL wins, and fails if the precedence is re-inverted
(verified by mutation). theCallbackSchemeAlwaysMatchesTheResolvedRedirect
pins that the scheme always belongs to the resolved redirect across
every combination — it cannot fail while both sides share one
resolution, which is the point, and it documents the invariant for
whoever is tempted to re-derive it.

Not marked breaking: under the old behavior this combination hung the
flow, so no working integration can depend on it.

Fixes SDK-1873

Co-authored-by: Claude <noreply@anthropic.com>

9 of 16 new or added lines in 1 file covered. (56.25%)

38 existing lines in 1 file now uncovered.

10606 of 11925 relevant lines covered (88.94%)

108.64 hits per line

Uncovered Changes

Lines Coverage ∆ File
7
90.53
0.74% Sources/Auth/AuthClient.swift

Coverage Regressions

Lines Coverage ∆ File
38
90.53
0.74% Sources/Auth/AuthClient.swift
Jobs
ID Job ID Ran Files Coverage
1 35210399762.1 17 Sep 2026 10:29AM UTC 134
88.94
GitHub Action Run
Source Files on build 35210399762
  • Tree
  • List 134
  • Changed 1
  • Source Changed 1
  • Coverage Changed 1
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • Github Actions Build #35210399762
  • ba8ebab3 on github
  • Prev Build on main (#35205236753)
  • Next Build on main (#35221295927)
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc