Skip to content
This repository was archived by the owner on May 12, 2026. It is now read-only.
This repository was archived by the owner on May 12, 2026. It is now read-only.

DefaultPKCEProvider challenge rejected  #1373

Description

@sqrrrl

Environment details

  1. Meet (but not API-specific)
  2. OS type and version: Linux
  3. Java version: OpenJDK 17
  4. version(s):

Steps to reproduce

  1. Create a UserAuthorizer with PKCE enabled
  2. Open authorization URL in browser

Code example

      UserAuthorizer authorizer = UserAuthorizer.newBuilder()
          .setClientId(clientId)
          .setCallbackUri(callbackUri)
          .setScopes(SCOPES)
          .setPKCEProvider(new DefaultPKCEProvider())
          .build()
      URL authorizationUrl = authorizer.getAuthorizationUrl("me" "", null);
      System.out.printf("Open the following URL to authorize access: %s\n",
          authorizationUrl.toExternalForm());

Stack trace

None. Error is when attempting authorization, fails with error:

Access blocked: Authorization Error

Code Challenge must be base64 encoded. Learn more about this error

External references such as API reference guides

https://www.rfc-editor.org/rfc/rfc7636

Any additional information below

Following these steps guarantees the quickest resolution possible.

Thanks!

Activity

  1. sqrrrl commented on Mar 7, 2024

    @sqrrrl
    Author

    Looks like the issue is padding. PKCE spec calls for having the padding stripped (https://www.rfc-editor.org/rfc/rfc7636#appendix-A) whereas the URL generated with the DefaultPkCEProvider has padding included (the trailing %3D in the challenge):

    https://accounts.google.com/o/oauth2/auth?response_type=code&client_id=1091545035118-1fgup6gnafl7fhneispbln4rt6olmb19.apps.googleusercontent.com&redirect_uri=http://localhost:38377/Callback&scope=https://www.googleapis.com/auth/meetings.space.created&state&access_type=offline&approval_prompt=force&login_hint=default&include_granted_scopes=true&code_challenge=Wv7S82_ZOSlisom9x4K_qljSAb0LTPSjUogEz8Aq08E%3D&code_challenge_method=S256
    
  2. sqrrrl commented on Mar 7, 2024

    @sqrrrl
    Author

    And verified that removing the padding fixes the issues:

    .setPKCEProvider(new DefaultPKCEProvider() {
      @Override
       public String getCodeChallenge() {
         return super.getCodeChallenge().split("=")[0];
       }
    })
    
  3. TimurSadykov commented on Mar 7, 2024

    @TimurSadykov

    @clundin25 Could you please take a look, maybe applies to other langs?

  4. added
    priority: p2Moderately-important priority. Fix may not be included in next release.
    on Mar 7, 2024
  5. clundin25 commented on Mar 11, 2024

    @clundin25
    Contributor

    Thanks for pointing this out @sqrrrl ! I have opened #1375 to address this issue.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

priority: p2Moderately-important priority. Fix may not be included in next release.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions