Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Google OAuth2 how to signin with full account access?

Tags:

google-oauth

I want to develop a tool to access user's google info. it requires the full account access, I found a app can request for the permission. But I cannot find the scope in OAuth 2.0 Scopes for Google APIs.

How could I do this? what is the full account access scope? I develop this tool for myself, not would be used by others.

enter image description here

like image 554
luqiang tian Avatar asked Nov 02 '25 16:11

luqiang tian


2 Answers

As far as I know there is not any scope that can request full access like you want. And my guess is that even if it existed before it was removed due to obvious security reasons. I have also searched for some examples of this scope but I could not find any.

In other words, if I were you I would use multiple scopes for each specific task I need to implement. Hope it helps.

like image 60
Edward Codarcea Avatar answered Nov 04 '25 18:11

Edward Codarcea


It can be some undocumented flow, maybe with https://www.google.com/accounts/OAuthLogin scope. Maybe it is an old screenshot and app from the screenshot was using now deprecated OAuth 1.0.

There was one issue, which seems to be similar: https://searchsecurity.techtarget.com/news/450300257/Pokemon-GO-reveals-full-account-access-flaw-for-Google-authentication

like image 32
Jan Garaj Avatar answered Nov 04 '25 20:11

Jan Garaj



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!