[Action Advised] Take action to continue using Google's OAuth authorization endpoint

2,054 views
Skip to first unread message

Google Developers

unread,
Oct 6, 2022, 2:49:04 PM10/6/22
to omegaup...@googlegroups.com
Google Developers logo
Starting February 6, 2023, Google's OAuth 2.0 authorization endpoint will block embedded webviews.
We detected requests to our OAuth 2.0 authorization endpoint from one or more of your OAuth client IDs within an embedded webview context in the past 30 days.

Hello Google Developer,

We're writing to let you know that all OAuth authorization requests coming from embedded webviews will be blocked with a disallowed_useragent error starting February 6, 2023. Affected requests to our authorization endpoint will display a user-facing warning message from now until February 6, 2023.

What do I need to know?

Embedded webview libraries are highly customizable, which can expose your Google's account login and authorization pages to potential "man-in-the-middle" attacks. Google's OAuth 2.0 Use secure browsers policy helps us protect users from these and other types of attacks.

Examples of affected embedded webview libraries include android.webkit.WebView on Android and WKWebView on iOS or macOS.

What do I need to do?

Review the potentially impacted client ID(s) used by your projects below:

For additional information regarding these changes, please read thoughtfully through the Google Developers blog post shared above.

Thanks for choosing Google OAuth.

— The Google OAuth Team

Was this information helpful?
A smiling face     A neutral face     A sad face

© 2022 Google LLC 1600 Amphitheatre Parkway, Mountain View, CA 94043

You have received this mandatory service announcement to update you about important changes to Google services you use.

Reply all
Reply to author
Forward
0 new messages