I created an application for Glass, and I noticed that Google accounts without the actual Glass device (I personally know these users) may very well complete the OAuth2 process, including the glass areas ( https://www.googleapis.com/auth/glass.timeline and https://www.googleapis.com/auth/glass.location )
This seems to be unexpected and somehow problematic, as these are users who can consume application resources, can expect some functionality, if any, but they cannot get any services in return.
source share