Skip to content

SNOW-3887337: Fix external browser callback connection race - #1830

Open
ragesh-g wants to merge 1 commit into
snowflakedb:masterfrom
ragesh-g:ragesh/fix-externalbrowser-race
Open

ragesh-g wants to merge 1 commit into
snowflakedb:masterfrom
ragesh-g:ragesh/fix-externalbrowser-race

Conversation

@ragesh-g

@ragesh-g ragesh-g commented Aug 4, 2026 •

Copy link
Copy Markdown

Description

SNOW-3887337 Fix external-browser authentication hanging when an idle connection reaches the callback listener before the real browser redirect.

Fixes #1829. Originally reported in dbt-labs/dbt-core#14565.

Chrome TCP preconnect can open multiple sockets for one redirect: one carries the GET /?token=... callback while a spare connection remains idle. The driver previously called Accept() only once and blocked reading that connection, so authentication timed out when the idle socket was accepted first.

This change serves the callback with http.Server, allowing connections to be handled concurrently until a valid token arrives, the caller cancels, or authentication times out.

Checklist

  • Added proper logging where applicable
  • Created tests which fail without the change
  • README/documentation changes are not necessary because there are no public API or configuration changes

@ragesh-g
ragesh-g requested a review from a team as a code owner August 4, 2026 05:21
@github-actions

github-actions Bot commented Aug 4, 2026 •

Copy link
Copy Markdown

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

@ragesh-g
ragesh-g marked this pull request as draft August 4, 2026 05:22
@ragesh-g
ragesh-g force-pushed the ragesh/fix-externalbrowser-race branch from 4e90a60 to c8accc4 Compare August 4, 2026 07:52
@ragesh-g

ragesh-g commented Aug 4, 2026

Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

@hope-wat

hope-wat commented Sep 1, 2026

Copy link
Copy Markdown

@ragesh-g has anyone helped you on the snowflake side get this change in?

@ragesh-g

ragesh-g commented Sep 2, 2026

Copy link
Copy Markdown
Author

@ragesh-g has anyone helped you on the snowflake side get this change in?

@hope-wat I was told it was being discussed internally #1829 (comment)

@sfc-gh-pfus

Copy link
Copy Markdown
Collaborator

Ok, I got a green light on this! Can you solve conflicts?

Serve the external-browser callback with http.Server so each connection
is handled concurrently. An idle connection, such as a browser TCP
preconnect, or a partially sent request can no longer block the
connection carrying the callback. The Origin, preflight, and POST
handling from SNOW-4109574 runs unchanged inside the handler.

Fixes snowflakedb#1829.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@ragesh-g
ragesh-g force-pushed the ragesh/fix-externalbrowser-race branch from f7ae3be to 8fe6d9d Compare October 5, 2026 07:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

SNOW-3887337: External browser authentication hangs when an idle TCP connection arrives before the browser callback

3 participants