From 7aefdffe16f7b9244c7739c83a55255ec590e557 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Zolt=C3=A1n=20Papp?= Date: Wed, 7 Oct 2026 13:53:33 +0200 Subject: [PATCH] [client] Adopt the three-value parseEmailFromIDToken in the device flow The main merge brought in the device flow's email extraction from #7193, which still used the two-value signature this branch replaced when account matching was narrowed to the email claim. Git merged the files without a textual conflict, so the branch stopped compiling. Take the fromEmailClaim result and fill EmailClaim from it, the same way the PKCE path does, so device-flow clients get the same account matching. --- client/internal/auth/device_flow.go | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/client/internal/auth/device_flow.go b/client/internal/auth/device_flow.go index 3592e589d..c2b8d34b8 100644 --- a/client/internal/auth/device_flow.go +++ b/client/internal/auth/device_flow.go @@ -308,10 +308,13 @@ func (d *DeviceAuthorizationFlow) WaitToken(ctx context.Context, info AuthFlowIn // callers store to send back as the login_hint. Without it a client // driven through the device flow — Android TV and tvOS — never binds // an account to its profile and every later login goes out blind. - if email, err := parseEmailFromIDToken(tokenInfo.IDToken); err != nil { + if email, fromEmailClaim, err := parseEmailFromIDToken(tokenInfo.IDToken); err != nil { log.Warnf("failed to parse email from ID token: %v", err) } else { tokenInfo.Email = email + if fromEmailClaim { + tokenInfo.EmailClaim = email + } } log.Infof("device flow: user authorization confirmed after %d polls in %s", polls, time.Since(start).Round(time.Second))