Google Credentials

64 views
Skip to first unread message

Erglmop

unread,
Sep 10, 2009, 9:08:57 PM9/10/09
to NewsRob User Group
Mariano,

I just installed NewsRob. Just wondering why we need to enter our
Google credentials, since we are already authenticated to the phone.
Gmail, calendar, etc. sync without entering our credentials again.

Thanks!

Mariano Kamp

unread,
Sep 11, 2009, 4:28:49 AM9/11/09
to new...@googlegroups.com
Hey Erglmop,

  just quickly: There is currently no official way to do this properly. And security is not really the right place to use shortcuts. Right now, asking the user for his or her credentials seems the best way to me.

  Ok, here is the long story:

  There is two qualities to that: convenience and security. 

  For convenience reasons it would be great if you wouldn't have to provide your Google credentials to the apps separately. But even from the convenience point of view this is only (a little) convenient to some and very inconvenient to others. There are users that don't want to use the same account for the phone (e.g. gmail) and for their Google Reader account. This is very often the case for users of Google Apps for your Domain users.

  There is some "pragmatic" solution used by some programmers, but it is nothing official and doesn't significantly improve security. I decided that the little convenience gain you can get with that solution is not worth going down a slippery slope.


  Regarding security. An ideal solution would be that NewsRob fires an intent that it wan't to access the Google Reader part of your Google account and a Google app answers that intent (that's the cross-app re-use mechanism on Android), verifies it, asks the user to grant the permission to NewsRob and then returns an authentification-token that authorizes NewsRob to only use the Google Reader part of your account. 
Ideally the Google app would let you chose between the phone's identity and other Google accounts you may have, but I would already be happy without that.

  If there would be a proper solution from Google I would implement it right away. 

  You can star this issue to show your interest in this topic to Google: http://code.google.com/p/android/issues/detail?id=1073

  Btw. for me this is not an ideal situation too. This issue comes up regularly, I get bad ratings and had to implement my own login mechanism that doesn't add any NewsRob-value to the app. 

  I hope you understand and star the bug report from above, not that I am holding my breath for Google to act on it right away.

Cheers,
Mariano

Erglmop

unread,
Sep 11, 2009, 1:56:04 PM9/11/09
to NewsRob User Group
Thank you for your in-depth reply. It's interesting that google does
not allow third party access to their services through the
authenticated phone. Doesn't sound like they will, either, since the
issue has not been fixed in 1.5. It's less an issue of inconvenience
for me, but rather the reluctancy to enter my google credentials in a
third party app. I agree with your ideal solution, which you posted
on the Android code issue, of using intents and allowing the end user
to decide which account to use.

Thanks,
Erg
> > Thanks!- Hide quoted text -
>
> - Show quoted text -

Yelena Jetpyspayeva

unread,
Sep 14, 2009, 8:35:41 AM9/14/09
to new...@googlegroups.com
same topic, but new question:

Mariano, I don't know whether you solved it already, just quick check.

I have heard from many of my friends whom I recommend NR (they all think it is cool!) a note that it is odd to click refresh button to enter your Google Credentials when you use NR for the first time. why not to ask when you start the app?

me

Mariano Kamp

unread,
Sep 14, 2009, 9:59:06 AM9/14/09
to new...@googlegroups.com
Well, it's a little hard to distinguish between the first time use and after "Logout and Clear Cache", but I see your point Yelena.
I will put it on my TODO list.

Cheers,
Mariano

Yelena Jetpyspayeva

unread,
Sep 14, 2009, 10:19:43 AM9/14/09
to new...@googlegroups.com
my pleasure to help :)

2009/9/14 Mariano Kamp <marian...@gmail.com>



--
________________________________

sincerely,

Yelena Jetpyspayeva,
journalist, New Media consultant

BarCamp Central Asia 2009 organizer (www.barcampkz.net)
NewEurasia.net - Blogging Central Asia project Managing Editor (Russian) (www.neweurasia.net/ru)
Gazeta.kz News Agency Managing Editor (English) (http://eng.gazeta.kz)

+49 152 2 752 88 16 (German mobile)
+41 76 455 18 14 (Swiss mobile)

Rathenaustr. 24A-101
35394 Giessen
Germany

mail to: mur...@gmail.com
Gtalk: mur...@gmail.com
skype lena_jet
my blog on http://lena-jet.blogspot.com
my twitter http://twitter.com/mursya

Mariano Kamp

unread,
Sep 23, 2009, 2:20:26 PM9/23/09
to NewsRob User Group
Oh and I forgot to mention that this also means that the user makes a
sync first and then goes to the settings screen.

But I meanwhile agree it is still smoother this way.

So from NR 3.1.0 (rolling out now) on you will be forwarded to the
login screen after you accepted the license.

On Sep 14, 3:59 pm, Mariano Kamp <mariano.k...@gmail.com> wrote:
> Well, it's a little hard to distinguish between the first time use and after
> "Logout and Clear Cache", but I see your point Yelena.I will put it on my

Yelena Jetpyspayeva

unread,
Sep 23, 2009, 2:38:26 PM9/23/09
to new...@googlegroups.com
cool great!!

2009/9/23 Mariano Kamp <marian...@gmail.com>
Reply all
Reply to author
Forward
0 new messages