• Resolved judajo

    (@judajo)


    I just got the email below from Google Developers, I was wondering if you guys have a solution for this?

    Thanks in advance!

    Here’s the email-

    Hello Google Developer,

    We’re writing to let you know that we detected the use of an embedded webview in requests to Google’s OAuth 2.0 authorization endpoint in the past 120 days associated with one or more of your OAuth client IDs listed in this email.

    Any affected authorization endpoint requests will be blocked with a disallowed_useragent error starting July 24, 2023. Affected requests to our authorization endpoint will display a user-facing warning message starting in May until July 24, 2023.

    What do you need to know?

    Embedded webview libraries are highly customizable, which can expose Google’s login and account authorization pages to potential “man-in-the-middle” attacks. Google’s OAuth 2.0 “Use secure browsers” policy helps us protect users from these and other types of attacks.

    Examples of affected embedded webview libraries include android.webkit.WebView on Android and WKWebView on iOS or macOS.

    What do you need to do?

    Note: Suppression of the user-facing warning message is not supported

Viewing 2 replies - 1 through 2 (of 2 total)
  • Hello,

    Thank you for reaching out to us.

    You might have received this email due to the mismatched application type of the Google developer application you have created. 

    Please provide me with the following information, it will help us to guide you further:

    • Installed version of the OAuth client SSO plugin.
    • Are you facing any issues with the SSO with Google?
    • Did the application ID mentioned by Google in the mail contain the developer application you have created for SSO with Google through OAuth Client SSO plugin?

    Please send us a query from the support form inside the plugin so that we can reach out to you over email for better assistance and a fast response.

    Thanks,
    Team miniOrange

    Hi @judajo

    We haven’t heard back from you in the last couple of days, so we are marking this thread as resolved. You can always post your queries on this forum if you have any questions or face issues with our plugin. We’d be happy to help you.

    Thanks

    Team miniOrange

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘Google’s OAuth authorization endpoint’ is closed to new replies.