{"record":{"id":"2ec57327b935996c","repo":"google-gemini/gemini-cli","slug":"error-missing-issuer-parameter-in-response","errorCode":null,"errorMessage":"Error: Missing issuer parameter in response.","messagePattern":"Error: Missing issuer parameter in response\\.","errorType":"http","errorClass":null,"httpStatus":400,"severity":"error","filePath":"packages/core/src/utils/oauth-flow.ts","lineNumber":274,"sourceCode":"            if (state !== expectedState) {\n              debugLogger.error(\n                `OAuth callback state mismatch: received state \"${state}\", expected \"${expectedState}\". Possible CSRF attack.`,\n              );\n              res.writeHead(400);\n              res.end('Invalid state parameter');\n              server.close();\n              reject(new Error('State mismatch - possible CSRF attack'));\n              return;\n            }\n\n            // RFC 9207 Authorization Server Issuer Identification check\n            if (expectedIssuer) {\n              // Fail-closed: if an issuer was expected, the response MUST include it\n              if (!iss) {\n                debugLogger.error(\n                  'OAuth callback rejected: Missing required \"iss\" parameter when an expected issuer is configured. Possible IdP mix-up attack (RFC 9207).',\n                );\n                res.writeHead(400, { 'Content-Type': 'text/html' });\n                res.end(`\n                <html>\n                  <body>\n                    <h1>Authentication Failed</h1>\n                    <p>Error: Missing issuer parameter in response.</p>\n                    <p>You can close this window.</p>\n                  </body>\n                </html>\n              `);\n                server.close();\n                reject(\n                  new Error(\n                    'Missing \"iss\" parameter in authorization response per RFC 9207',\n                  ),\n                );\n                return;\n              }\n","sourceCodeStart":256,"sourceCodeEnd":292,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/utils/oauth-flow.ts#L256-L292","documentation":"RFC 9207 issuer identification is enabled (expectedIssuer set) but the authorization response omitted the iss parameter. The check fails closed: absence of the issuer is treated as a mix-up-attack risk, the server closes, and the flow is rejected with a missing-iss error.","triggerScenarios":"Thrown at packages/core/src/utils/oauth-flow.ts:274 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Verify the OAuth provider supports RFC 9207 iss in authorization responses","Confirm the expected issuer configuration matches the provider's actual issuer URL","Disable the issuer check only if the provider is known not to support RFC 9207"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}