Skip to content

feat: add optional Google Drive OAuth setup - #15

Merged
CruxExperts merged 3 commits into
mainfrom
feature/gdrive-oauth
Aug 4, 2026
Merged

CruxExperts merged 3 commits into
mainfrom
feature/gdrive-oauth

Conversation

@CruxExperts

Copy link
Copy Markdown
Owner

Summary

  • Add optional bbman auth-gdrive setup for a dedicated rclone Google Drive remote.
  • Validate installed Google Desktop OAuth client secrets and redact credential-bearing output.
  • Use authenticated local rclone RC over a temporary Unix socket with one-time child-process credentials; never put client secrets or tokens in argv.
  • Add dry-run, JSON, non-browser/SSH-friendly flow, generated CLI metadata, docs, and mocked test coverage.

This branch is refreshed onto current main and contains no GitPython/management extra. It includes cryptography 50.0.0, health-floor enforcement, restic retention safety, and bounded xdist tests from main.

Live Google authorization remains unverified because the Google API client was deleted; the implementation is validated through mocked OAuth/config flows, dry-run behavior, redaction tests, authenticated local rclone RC transport, and CLI/docs integration.

Verification

  • OAuth-focused tests passed.
  • Full suite: 616 passed with 8 workers.
  • Ruff, py_compile, generated CLI metadata, version sync, publishing readiness, and diff checks passed.
  • Real local rclone core/version RC smoke passed.
  • Independent merged-feature review: no material findings.
  • No client secret, access token, refresh token, or real credential committed.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 957f12453f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread tests/test_gdrive_auth.py
Comment on lines +42 to +45
with patch(
"bbackup.management.gdrive_auth._load_installed_app_flow",
side_effect=gdrive_auth.OptionalDependencyMissing(gdrive_auth.INSTALL_HINT),
):

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Mock rclone before asserting missing OAuth extras

When this test runs on a machine without rclone, the command never reaches the patched _load_installed_app_flow: auth_gdrive() calls _preflight_rclone_config() first and returns the rclone-missing system error instead of the optional-dependency hint asserted below. Since rclone is an optional external tool for this repo, please mock the rclone preflight/config dump here so the unit test exercises the missing-extra path deterministically.

Useful? React with 👍 / 👎.

Comment thread bbackup/bbman.py
BBACKUP_NO_INTERACTIVE_ENV,
)
from bbackup.skills import get_skill
from bbackup.management import gdrive_auth as gdrive_auth_module

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Avoid eager management imports in bbman startup

Importing gdrive_auth through bbackup.management eagerly executes bbackup/management/__init__.py, which imports modules that require packages such as yaml and docker. In a partially installed checkout where bbman check-deps is supposed to report or install missing Python dependencies, any bbman invocation now aborts during import before the dependency checker can run; import this helper lazily inside auth-gdrive or from the submodule without triggering the package initializer.

Useful? React with 👍 / 👎.

"opt": {"obscure": True, "nonInteractive": True, "noOutput": True},
}

_call_rclone_rc(method, payload, secrets)

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Handle rclone's non-interactive config response

When rclone still has a Drive config question to ask, the RC API documents nonInteractive as “don't interact with a user, return questions” (rclone RC docs), but this call discards that response and reports the remote as configured. In those cases, for example post-token Drive/team-drive prompts, bbman auth-gdrive can exit 0 even though rclone did not finish writing a usable remote; check the returned body for a continuation/question state and either answer it or fail explicitly.

Useful? React with 👍 / 👎.

@CruxExperts
CruxExperts merged commit 6beaea2 into main Aug 4, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant