Expand description
The way back of a sign-in: the page opens in the person’s own browser, and the answer the browser is sent back with is carried to the application inside its container.
An application that signs in with Google — Antigravity IDE is the first — listens on a port of
its own localhost and asks for a page whose redirect_uri names that port. When the person
has signed in, Google sends their browser to http://localhost:<port>/<path>?code=…, and the
application takes the code from that request.
Showing the page inside the container would keep that localhost the application’s, and QCode
did that first. Google refuses it: a browser window started by an application is turned away
with “Couldn’t sign you in — This browser or app may not be secure.” Nothing that pretends to be
another browser is tried here; the page goes to the person’s own browser, where they are often
signed in already, and the way back is carried instead.
The carrying has three parts:
return_toreads the address the application asked to open and finds the port and path the sign-in comes back to, looking through aredirect_urithat is encoded, or nested inside another address, as sign-in pages like to do. An address whose way back is not the machine’s ownlocalhostover plainhttphas nothing to carry, and nothing is listened for.Listener::bindlistens on that port on this machine’s loopback,127.0.0.1and, for a way back namedlocalhost,[::1]too: a browser resolveslocalhostto both and may try either first, and a program of someone else’s on the other one would be handed the code. When the port is taken, nothing is opened; another port cannot be chosen, because Google sends the browser to exactly the address it was given.- Each connection the browser makes is carried by
carrier:<engine> exec -i <container> node -e …, a program of twenty lines that connects to the same port inside the container and copies bytes both ways. The container needs no network for it — loopback is there in a container with none — and nothing is ever carried to anything but that one port.
The listening ends when the application has answered a request for the path of the way back
(the sign-in has arrived), when the tab stops it (the window closed, or the person chose the
window of last resort instead), or after WAIT, which is long enough to find a phone for the
second step and short enough that a port is not held for an afternoon.
Every harness whose sign-in comes back to localhost can use the same road — Antigravity’s
command-line agy, Gemini CLI, and opencode or Codex where their sign-in works the same way.
What differs is only where the address comes from: a desktop application runs xdg-open, which
reaches super::signin::OPEN_PROGRAM; a harness in a terminal prints the address instead,
and the address would have to be read from what it prints. carrier relies on nothing but
node, which every image QCode builds carries.
Structs§
- Listener
- A way back listened for on this machine’s loopback, not yet served.
- Return
- Where a sign-in comes back to: a port of the application’s
localhost, and the path it asks for there. - Stop
- Stops a listening when it is dropped: a tab holds one while its sign-in’s way back is listened for, so a tab that closes, or moves on, gives the port up by itself.
Enums§
- Ending
- How a listening ended.
- Loopback
- Which of the machine’s own addresses a way back names.
- NotListening
- Why a way back could not be listened for.
Constants§
- CARRIER
- The program that carries one connection inside the container: it connects to the port on the container’s loopback, trying each address it is given in turn, and copies its standard input there and what comes back to its standard output. It ends with code 3 when nothing listens.
- WAIT
- How long a sign-in’s way back is listened for before QCode gives the port up again.