From 3660486153a16760d2b980e546bbbd29408fb8d4 Mon Sep 17 00:00:00 2001 From: Peter Stone Date: Sun, 16 Aug 2026 00:03:51 +0000 Subject: Replace Google Tasks service-account auth with real OAuth Service-account auth structurally cannot see a regular user's personal task lists (no equivalent of Calendar's per-item sharing model) -- confirmed via GetTaskLists returning exactly the service account's own empty "My Tasks" list, never the real user's three lists. Zero rows were ever cached in production as a result. Adds a standard 3-legged OAuth flow: /settings/google-tasks/connect redirects to Google's consent screen (AccessTypeOffline+ApprovalForce so a refresh_token is always issued), /callback exchanges the code and persists the token (new oauth_tokens table), /disconnect clears it. GoogleTasksClient now takes an option.ClientOption instead of a credentials file path; NewGoogleTasksOAuthClient wraps it with a dbTokenSource that reloads/refreshes from the DB on each access-token expiry and re-persists -- carefully preserving the original refresh_token when Google's refresh response omits one (it usually does), which would otherwise silently and permanently break future refreshes. Settings page shows connection status and a Connect/Disconnect button. Calendar keeps using service-account auth (that one actually works). Requires a one-time manual step: create an OAuth 2.0 Client ID in Google Cloud Console and set GOOGLE_OAUTH_CLIENT_ID/SECRET in .env -- documented in .env.example. --- web/templates/settings.html | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) (limited to 'web') diff --git a/web/templates/settings.html b/web/templates/settings.html index acee1ee..8a72287 100644 --- a/web/templates/settings.html +++ b/web/templates/settings.html @@ -161,6 +161,39 @@ + +
+
+

Google Tasks

+
+ {{if .GoogleTasksError}} +
+ Connection failed: {{.GoogleTasksError}} +
+ {{end}} + {{if not .GoogleTasksOAuthReady}} +
+ Not configured — set GOOGLE_OAUTH_CLIENT_ID and GOOGLE_OAUTH_CLIENT_SECRET in .env and restart. +
+ {{else if .GoogleTasksConnected}} +
+ ✓ Connected — real task lists syncing via OAuth. + +
+ {{else}} +
+ Not connected — service-account auth can't see your real task lists, this needs your own Google sign-in. + + Connect Google Tasks + +
+ {{end}} +
+
-- cgit v1.2.3