{"record":{"id":"a5865ee4206a965c","repo":"google-gemini/gemini-cli","slug":"invalid-state-parameter","errorCode":null,"errorMessage":"Invalid state parameter","messagePattern":"Invalid state parameter","errorType":"http","errorClass":null,"httpStatus":400,"severity":"error","filePath":"packages/core/src/utils/oauth-flow.ts","lineNumber":260,"sourceCode":"              server.close();\n              reject(new Error(`OAuth error: ${error}`));\n              return;\n            }\n\n            if (!code || !state) {\n              debugLogger.warn(\n                'OAuth callback rejected: Missing code or state parameter.',\n              );\n              res.writeHead(400);\n              res.end('Missing code or state parameter');\n              return;\n            }\n\n            if (state !== expectedState) {\n              debugLogger.error(\n                `OAuth callback state mismatch: received state \"${state}\", expected \"${expectedState}\". Possible CSRF attack.`,\n              );\n              res.writeHead(400);\n              res.end('Invalid state parameter');\n              server.close();\n              reject(new Error('State mismatch - possible CSRF attack'));\n              return;\n            }\n\n            // RFC 9207 Authorization Server Issuer Identification check\n            if (expectedIssuer) {\n              // Fail-closed: if an issuer was expected, the response MUST include it\n              if (!iss) {\n                debugLogger.error(\n                  'OAuth callback rejected: Missing required \"iss\" parameter when an expected issuer is configured. Possible IdP mix-up attack (RFC 9207).',\n                );\n                res.writeHead(400, { 'Content-Type': 'text/html' });\n                res.end(`\n                <html>\n                  <body>\n                    <h1>Authentication Failed</h1>","sourceCodeStart":242,"sourceCodeEnd":278,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/utils/oauth-flow.ts#L242-L278","documentation":"The OAuth callback carried a state parameter that does not match the expected state generated at flow start, indicating a possible CSRF/replay attack. The server responds 400, logs the mismatch, closes, and rejects with a state-mismatch error. This is a security guard on the authorization response.","triggerScenarios":"Thrown at packages/core/src/utils/oauth-flow.ts:260 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Restart the OAuth flow to generate a fresh state","Ensure only one login flow runs at a time (stale callback from an earlier attempt)","Verify no proxy or extension alters query parameters"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}