Why can a Google user without a Glass device complete the OAuth2 process?

I created an application for Glass, and I noticed that Google accounts without the actual Glass device (I personally know these users) may very well complete the OAuth2 process, including the glass areas ( https://www.googleapis.com/auth/glass.timeline and https://www.googleapis.com/auth/glass.location )

This seems to be unexpected and somehow problematic, as these are users who can consume application resources, can expect some functionality, if any, but they cannot get any services in return.

+4
source share
2 answers

All users have a timeline. By requesting these areas, you are requesting access to this abstract data.

If this activates the glass device, their timeline is synchronized with this device.

I understand why you can distinguish between users who have one, many or zero active glass. You can ask for this to be added to the API by sending an improvement request .

+3
source

See also “ How to find out if a user has Glass Glass ) for a similar question, as well as a suggested answer to using a double option as a way to mitigate a resource problem.

0
source

Source: https://habr.com/ru/post/1485895/


All Articles