PortalAuth method. Fetches a fresh authorize URL, presents Google in an ASWebAuthenticationSession sheet from the anchor set with setAuthPresentationAnchor(_:), receives the callback inside the sheet, and exchanges the token through the same code path as handleRedirect. Replay protection, persist-before-return and the two-factor branch behave identically.
Returns
AuthResult: One of:.authenticated(AuthenticatedResult): The sign-in is complete.sessionis aPortalSessionalready saved to the Keychain; pass it toPortal(credentials:).clientIdandisAccountAbstracteddescribe the client Portal resolved..totpRequired(TotpRequiredResult): The environment requires a two-factor code. Nothing is persisted; complete the sign-in withverifyTotp.
PortalAuthSignInError.unavailable: No presentation anchor was set (or its window was deallocated), theredirectUrlis not a custom URL scheme, or the system refused to start the session.PortalAuthSignInError.signInInProgress: AnothersignInWith*call is still running.PortalAuthSignInError.closed: The user dismissed the sheet, or the calling task was cancelled.PortalAuthSignInError.callbackIncomplete: The browser returned a callback that carried no sign-in result for this instance.PortalAuthError.authMethodUnavailable(.google): Google is not enabled for this auth environment.PortalAuthError.authenticationFailed(error:): The provider sign-in failed (oauth_failed).PortalAuthError.sessionStorageFailure(message:): The session could not be saved to the Keychain. The sign-in is not returned unsaved; start a new sign-in.PortalRequestsError.unauthorized: Portal refused the authorize URL request (theredirectUrlis not allow-listed, the Auth Environment ID is wrong, or an enabled provider is missing its credentials), or rejected the grant.- Other
PortalAuthErrorcaseshandleRedirectcan throw, and transport errors unchanged.
- Call
setAuthPresentationAnchor(_:)with your window before signing in. The anchor is held weakly. - Requires a custom-scheme
redirectUrlsuch asmyapp://auth/callback. Anhttps://Universal Link is not supported bysignInWith*in this release and throws.unavailable; useloginWithGoogle+handleRedirectfor that. - The callback is matched inside the browser session and never routed through the OS URL handler, so another app that registers the same scheme cannot intercept it. This is the recommended OAuth path.
- One sign-in at a time. Both provider URLs share a single-use
state, so a concurrent attempt throws rather than invalidating the first. - Set
prefersEphemeralWebBrowserSession = trueto open the sheet without shared cookies. The defaultfalselets a returning user reuse their Safari sign-in, which also means a user who signed out gets the same Google account back. - Cancelling the calling
Taskdismisses the sheet and throws.closed; the grant is never exchanged. - Available starting from SDK version 8.0.0.