Skip to main content

Module callback

Module callback 

Source
Expand description

The way back of a sign-in: the page opens in the person’s own browser, and the answer the browser is sent back with is carried to the application inside its container.

An application that signs in with Google — Antigravity IDE is the first — listens on a port of its own localhost and asks for a page whose redirect_uri names that port. When the person has signed in, Google sends their browser to http://localhost:<port>/<path>?code=…, and the application takes the code from that request.

Showing the page inside the container would keep that localhost the application’s, and QCode did that first. Google refuses it: a browser window started by an application is turned away with “Couldn’t sign you in — This browser or app may not be secure.” Nothing that pretends to be another browser is tried here; the page goes to the person’s own browser, where they are often signed in already, and the way back is carried instead.

The carrying has three parts:

  • return_to reads the address the application asked to open and finds the port and path the sign-in comes back to, looking through a redirect_uri that is encoded, or nested inside another address, as sign-in pages like to do. An address whose way back is not the machine’s own localhost over plain http has nothing to carry, and nothing is listened for.
  • Listener::bind listens on that port on this machine’s loopback, 127.0.0.1 and, for a way back named localhost, [::1] too: a browser resolves localhost to both and may try either first, and a program of someone else’s on the other one would be handed the code. When the port is taken, nothing is opened; another port cannot be chosen, because Google sends the browser to exactly the address it was given.
  • Each connection the browser makes is carried by carrier: <engine> exec -i <container> node -e …, a program of twenty lines that connects to the same port inside the container and copies bytes both ways. The container needs no network for it — loopback is there in a container with none — and nothing is ever carried to anything but that one port.

The listening ends when the application has answered a request for the path of the way back (the sign-in has arrived), when the tab stops it (the window closed, or the person chose the window of last resort instead), or after WAIT, which is long enough to find a phone for the second step and short enough that a port is not held for an afternoon.

Every harness whose sign-in comes back to localhost can use the same road — Antigravity’s command-line agy, Gemini CLI, and opencode or Codex where their sign-in works the same way. What differs is only where the address comes from: a desktop application runs xdg-open, which reaches super::signin::OPEN_PROGRAM; a harness in a terminal prints the address instead, and the address would have to be read from what it prints. carrier relies on nothing but node, which every image QCode builds carries.

Structs§

Listener
A way back listened for on this machine’s loopback, not yet served.
Return
Where a sign-in comes back to: a port of the application’s localhost, and the path it asks for there.
Stop
Stops a listening when it is dropped: a tab holds one while its sign-in’s way back is listened for, so a tab that closes, or moves on, gives the port up by itself.

Enums§

Ending
How a listening ended.
Loopback
Which of the machine’s own addresses a way back names.
NotListening
Why a way back could not be listened for.

Constants§

CARRIER
The program that carries one connection inside the container: it connects to the port on the container’s loopback, trying each address it is given in turn, and copies its standard input there and what comes back to its standard output. It ends with code 3 when nothing listens.
WAIT
How long a sign-in’s way back is listened for before QCode gives the port up again.

Functions§

carrier
The command that carries one connection to the way back back inside container.
return_to
Where the sign-in of address comes back to, when it comes back to localhost.