Allow only requesting the oauth scopes that an app needs
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 2/5
- 見積もり時間
- 1〜3時間
- 初心者へのやさしさ
- 68/100
- issue の種類
- 機能追加
- 明瞭さ
- おおむね明確
- 活発さ
- 静か
- 技術スタック
- ios, objective-c
- 領域
- authentication, mobile
調査の方向性
GoogleSignIn/Sources/GIDSignInInternalOptions.m と GoogleSignIn/Sources/GIDScopes.m から始め、特に参照されている scope の処理を確認してください。email と profile がどのように追加されるかを確認し、そのうえで後方互換性のある opt-out をどこに公開できるかを判断してください。デフォルトの動作が変わらず、opt-out では利用するアプリの scope のみがリクエストされれば完了です。
索引モデルが issue の本文から書いたものです。
説明
Is your feature request related to a problem you're having? Please describe.
My app needs to write new files to Google Drive, and it needs nothing else. As such, the only scope I request is https://www.googleapis.com/auth/drive.file. However, the login screen suggests that the app will be much more invasive than it is:
It appears that additional scopes beyond what the consuming app requests are always requested:
https://github.com/google/GoogleSignIn-iOS/blob/main/GoogleSignIn/Sources/GIDSignInInternalOptions.m#L56
https://github.com/google/GoogleSignIn-iOS/blob/main/GoogleSignIn/Sources/GIDScopes.m#L58
Specifically it looks like the email and profile scopes are always added.
My assumption is that those additional scopes are unnecessary for basic usage, but please tell me if I am incorrect.
As an additional downside, requesting extraneous scopes makes implementing Google's new granular permissions more messy and complicated.
Describe the solution you'd like
In the spirit of the principle of least privilege, it should be possible to use Google SignIn without extraneous scopes added. To do this in a backwards compatible way, the current behavior should remain the default, but it should be possible to set a flag to avoid scopes being added.
This seems like a very small change.
Describe alternatives you've considered
First, it's possible that those other scopes are necessary for all Google API usage. However, the fact that granular permissions allows rejecting them, that seems false.
Second, it's possible that consumers of Google SignIn just live with requesting extra scopes. However, that makes their apps look more invasive than they need, and thus sketchy. Further, it means that developers need to unnecessarily handle the more complicated granular permission case where you request many scopes.
Additional context
I'm happy to contribute this feature if it would be accepted.
- 主要言語
- Objective-C
- スター
- 751
- フォーク
- 282
- 平均マージ
- 4日 20時間
- マージ済み PR(30日)
- 11
環境構築
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
google/GoogleSignIn-iOS のほかの issue
-
enhancement triage
難易度 2/5 1〜3時間 初心者へのやさしさ 72/100
google/GoogleSignIn-iOS#621 ·
メンテナーはふだん 1 日以内に返信
-
enhancement triage
難易度 2/5 1〜3時間 初心者へのやさしさ 76/100
google/GoogleSignIn-iOS#620 ·
メンテナーはふだん 1 日以内に返信
-
enhancement triage
難易度 4/5 3〜5日 初心者へのやさしさ 48/100
google/GoogleSignIn-iOS#611 ·
メンテナーはふだん 1 日以内に返信
-
難易度 4/5 3〜5日 初心者へのやさしさ 45/100
google/GoogleSignIn-iOS#607 ·
メンテナーはふだん 1 日以内に返信
-
enhancement triage
難易度 4/5 3〜5日 初心者へのやさしさ 52/100
google/GoogleSignIn-iOS#602 ·
メンテナーはふだん 1 日以内に返信
google/GoogleSignIn-iOS の issue をすべて見る
似ている issue
-
Nextcloud Desktop 34.0.4 fails TestLocalDiscovery::testFileOpenedAsDirectoryCompletesDiscoveryJob()オープン0. Needs triage bug
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
メンテナーはふだん 1 日以内に返信
-
api: database
難易度 2/5 1〜3時間 初心者へのやさしさ 86/100
firebase/firebase-ios-sdk#16718 · 担当者 1 名 ·
メンテナーはふだん 1 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 65/100
julienXX/terminal-notifier#333 ·
-
難易度 1/5 1時間未満 初心者へのやさしさ 82/100
serhii-londar/open-source-mac-os-apps#1419 ·
メンテナーはふだん 5 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 78/100
prime-radiant-inc/evener#2440 ·
メンテナーはふだん 1 日以内に返信