Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

AuthActivity with Firefox's "Tab queue" turned on cancels login flow

Open
#242 5 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
4/5
Estimated time
3-5 days
Newbie friendliness
42/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Stale
Tech stack
android, java

Research direction

Start in src/main/java/com/dropbox/core/android/AuthActivity.java around onResume() at the referenced line, and trace how the second resume calls authFinished(null) and clears state. Reproduce with Android 7.1.1 and Firefox Tab Queue enabled, then verify that returning from the queued browser login still associates the completed login with the client app instead of treating it as cancelled.

Written by the indexing model from the issue text.

Description

bug

SDK version: 3.0.8
Android Version: 7.1.1 (didn't test on other versions)

On Android, Firefox's Tab Queue feature causes the web browser login flow to not work due to SDK's AuthActivity treating the login flow as cancelled before user runs the login flow.

Repro Steps:

  1. Set Firefox as default Browser for Android.
  2. In Firefox go to Settings -> General -> Turn on "Tab queue" (which requires grating access Firefox to draw over apps, Settings link should show in Firefox when turning this on for the first time).
  3. Invoke SDK's AuthActivity from client app with no Dropbox app installed (to invoke browser flow) which causes AuthActivity to request Android to launch the login flow URL in a web browser which launches the Firefox browser to open the login flow URL.
  4. Due to Firefox's "Tab queue" feature, Firefox opens the login flow URL internally but does NOT show it to the user. Instead it returns right away causing AuthActivity in client app to show again while also showing a Toast like UI from Firefox to open the queued URL.
  5. User then opens the login flow with the Firefox Tab queue Toast UI which then does show the login flow URL in Firefox now.
  6. When user completes login flow in Firefox the web login flow navigates back to client application.
  7. Client app's AuthActivity when navigated back does nothing because the Dropbox SDK has no token associated with the completed login flow.

The reason for having no token in the Dropbox SDK in step 7 is because in Step 4 when Firefox navigates back to the client app, the Dropbox SDK handles this as a cancelled login attempt and wipes its internal state (same would happen if user task switches back to client app while on Login flow in browser). This logic can be seen in https://github.com/dropbox/dropbox-sdk-java/blob/c710ef80f1c2700031baad7c615dc9934162c090/src/main/java/com/dropbox/core/android/AuthActivity.java#L412 (onResume() will be called for the second time when Firefox navigates back to client app while mAuthStateNonce is non null -> authFinished(null))

For now I'm advising users who report this to simply turn off Firefox's "Tab Queue" feature or install Dropbox however it would be ideal if this just worked for users.

Dominant language
Java
Stars
627
Forks
463
Avg merge
5m
Merged PRs (30d)
10

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from dropbox/dropbox-sdk-java

All issues in dropbox/dropbox-sdk-java

Similar issues

More Java issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.