Home / Companies / Google Cloud / Blog / Post Details
Content Deep Dive

Upcoming security changes to Google's OAuth 2.0 authorization endpoint in embedded webviews

Blog post from Google Cloud

Post Details
Company
Date Published
Author
-
Word Count
1,307
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

Google is enhancing account security by banning Google OAuth 2.0 authorization requests in embedded webviews, effective September 30, 2021, due to their security vulnerabilities. Embedded webviews, commonly used in apps, can act as "man in the middle" agents, intercepting communications and compromising user data. This change aligns with IETF guidelines, which discourage using embedded user-agents for authorization in native apps. Developers are urged to update their applications to comply with these new policies by using platform-appropriate OAuth clients. Apps should route links through default web browsers or approved methods like Android Custom Tabs or iOS's SFSafariViewController. Captive networks are advised to adopt new IETF standards for better user experience. Developers should test their apps for compatibility, making necessary adjustments before the enforcement date, and can use specific query parameters for testing and acknowledging the upcoming changes.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Vector Search 1 108 31 21 -35%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.