Fix OAuth login redirect loops

#8
ICML 2026 Agent Reproductions org

Summary

  • Move OAuth login into the top-level browser context so iframe cookie restrictions do not break authentication.
  • Expire stale Gradio session cookies before starting a new OAuth attempt.
  • Preserve logout behavior and eligibility checks.
  • Declare the Gradio OAuth and Uvicorn runtime dependencies explicitly.

Root cause

Gradio 5.49.1 starts OAuth inside the embedded Space iframe. Browsers can block that third-party session cookie, and interrupted attempts can leave an invalid HttpOnly session cookie behind. Gradio then retries with the same invalid state until the browser reports too many redirects.

This addresses the failure reported in discussion #7 and matches the upstream Gradio regression documented at https://github.com/gradio-app/gradio/issues/13634.

Testing

  • pytest -q: 2 passed
  • Verified /oauth-login returns 303, expires the session cookie, and redirects to /login/huggingface
  • Started the mounted app with Gradio 5.49.1 and checked /, /config, and /oauth-login
  • Generated a certificate for the affected eligible record locally
ICML 2026 Agent Reproductions org

Great, thanks for fixing!

nielsr changed pull request status to merged

Sign up or log in to comment