Skip to content

Bug : When SSO login is started twice within the same running process, the CLI crashes with a panic #549

Description

@aniket866

Describe the bug

When SSO login is started twice within the same running process, the CLI crashes with a panic:

This happens because oauth2login registers /auth/callback on Go’s global HTTP router every time it runs. The second registration causes Go to panic.

Image

Steps to reproduce:

  1. Start SSO login once.
  2. Start SSO login again in the same process.
  3. Observe the panic.

here is the Panic: `panic: pattern "/auth/callback" conflicts with pattern "/auth/callback"

The issue can be reproduced with:

package cmd

import (
    "context"
    "testing"
    "time"

    "golang.org/x/oauth2"
)

func TestReproduceSSODuplicateCallbackPanic(t *testing.T) {
    config := &oauth2.Config{
        Endpoint: oauth2.Endpoint{
            AuthURL:  "http://127.0.0.1",
            TokenURL: "http://127.0.0.1",
        },
    }

    go func() {
        _, _, _ = oauth2login(context.Background(), 0, config, false)
    }()

    time.Sleep(2 * time.Second)

    // The second invocation registers /auth/callback again and panics.
    _, _, _ = oauth2login(context.Background(), 0, config, false)
}

Expected behavior:

  • The second login should return a normal error or create its own temporary callback server.

Actual behavior:

  • The process crashes with a panic and stack trace.

Impact:

  • Applications, tests, or services that reuse the CLI cannot safely perform multiple SSO logins.

Suggested fix:

  • Use a private http.ServeMux for each login instead of the global http.DefaultServeMux..

Expected behavior

No response

Actual behavior

No response

How to Reproduce?

No response

Microcks version or git rev

No response

Install method (docker-compose, helm chart, operator, docker-desktop extension,...)

No response

Additional information

@Harsh4902
Please review and assign if valid

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions