{"record":{"id":"b405ec1c1766f9a5","repo":"google-gemini/gemini-cli","slug":"missing-code-or-state-parameter","errorCode":null,"errorMessage":"Missing code or state parameter","messagePattern":"Missing code or state parameter","errorType":"http","errorClass":null,"httpStatus":400,"severity":"error","filePath":"packages/core/src/utils/oauth-flow.ts","lineNumber":251,"sourceCode":"              <html>\n                <body>\n                  <h1>Authentication Failed</h1>\n                  <p>Error: ${error.replace(/</g, '&lt;').replace(/>/g, '&gt;')}</p>\n                  <p>${(url.searchParams.get('error_description') || '').replace(/</g, '&lt;').replace(/>/g, '&gt;')}</p>\n                  <p>You can close this window.</p>\n                </body>\n              </html>\n            `);\n              server.close();\n              reject(new Error(`OAuth error: ${error}`));\n              return;\n            }\n\n            if (!code || !state) {\n              debugLogger.warn(\n                'OAuth callback rejected: Missing code or state parameter.',\n              );\n              res.writeHead(400);\n              res.end('Missing code or state parameter');\n              return;\n            }\n\n            if (state !== expectedState) {\n              debugLogger.error(\n                `OAuth callback state mismatch: received state \"${state}\", expected \"${expectedState}\". Possible CSRF attack.`,\n              );\n              res.writeHead(400);\n              res.end('Invalid state parameter');\n              server.close();\n              reject(new Error('State mismatch - possible CSRF attack'));\n              return;\n            }\n\n            // RFC 9207 Authorization Server Issuer Identification check\n            if (expectedIssuer) {\n              // Fail-closed: if an issuer was expected, the response MUST include it","sourceCodeStart":233,"sourceCodeEnd":269,"githubUrl":"https://github.com/google-gemini/gemini-cli/blob/6a466a7e2fe2b1255752c1e74f69b31f0216084d/packages/core/src/utils/oauth-flow.ts#L233-L269","documentation":"The OAuth callback server received a redirect request missing the required code or state query parameter, so the authorization response is malformed and the flow is rejected with a 400. A debug log records the rejection before the plain-text response.","triggerScenarios":"Thrown at packages/core/src/utils/oauth-flow.ts:251 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Retry the login flow to get a fresh, well-formed authorization response","Verify the provider redirect URI configuration","Check for browser extensions or proxies stripping query parameters"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"6a466a7e2fe2b1255752c1e74f69b31f0216084d","analyzedAt":"2026-09-16T18:14:43.978Z","contentChangedAt":"2026-09-16T18:14:43.978Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}