Skip to content

Migration to Credential Manager for Sign-in process - #2755

Merged
sosnovsky merged 39 commits into
masterfrom
issue_2531_Migrate_to_Credential_Manager
Sep 23, 2026
Merged

sosnovsky merged 39 commits into
masterfrom
issue_2531_Migrate_to_Credential_Manager

Conversation

@DenBond7

@DenBond7 DenBond7 commented Jun 6, 2024 •

Copy link
Copy Markdown
Collaborator

This PR migrates Google Sign-In from the deprecated Google Sign-In API to Credential Manager.

  • Uses GetSignInWithGoogleOption for authentication.
  • Uses AuthorizationClient separately for Gmail scope authorization.
  • Uses the email extracted from GoogleIdTokenCredential.
  • Restarts authentication safely after process recreation.
  • Clears Credential Manager state during logout.
  • Replaces background silentSignIn() calls with GoogleAuthUtil token retrieval, including invalid-token eviction and retry.
  • Updates UI test mocks and adds AccountEntity tests.

close #2531


Tests (delete all except exactly one):

  • Tests added or updated

To be filled by reviewers

I have reviewed that this PR... (tick whichever items you personally focused on during this review):

  • addresses the issue it closes (if any)
  • code is readable and understandable
  • is accompanied with tests, or tests are not needed
  • is free of vulnerabilities

@DenBond7 DenBond7 changed the title Migration to Credential Manager Migration to Credential Manager for Sign-in process Jun 11, 2024
@DenBond7

Copy link
Copy Markdown
Collaborator Author

Current changes cover only sign-in action for the UI interaction case. But still is no available way to get idToken silently. And many tests will be disabled after these changes. I prefer not to update this library yet. I will wait for more functionality.

@DenBond7
DenBond7 marked this pull request as ready for review September 21, 2026 13:25
@DenBond7
DenBond7 requested a review from sosnovsky as a code owner September 21, 2026 13:25
IntentSenderRequest.Builder(pendingIntent.intentSender).build()
)
} else {
continueAfterGoogleAuthorization()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it looks like here we don't check if Gmail access was granted during authorization, causing creation of FlowCrypt account without Gmail access. It should be better to require Gmail access here, so app will function correctly.

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for pointing this out. Currently, the authorization request contains only one non-sign-in scope: https://mail.google.com/. For a single non-sign-in scope, Google does not use granular consent—the user either grants or denies the entire request. Also, getAuthorizationResultFromIntent() returns a result only for successful authorization and throws an ApiException otherwise. Therefore, reaching continueAfterGoogleAuthorization() should currently imply that Gmail access was granted.

However, I agree that explicitly checking AuthorizationResult.grantedScopes would make this requirement clear and protect the flow if more scopes are added later. I’ll add this validation to both the no-resolution path and the activity-result path before continuing with account creation.

@DenBond7
DenBond7 marked this pull request as draft September 22, 2026 04:56
@DenBond7
DenBond7 marked this pull request as ready for review September 22, 2026 18:24

@sosnovsky sosnovsky left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

all good now 👍

@sosnovsky
sosnovsky merged commit fcd8c47 into master Sep 23, 2026
7 checks passed
@sosnovsky
sosnovsky deleted the issue_2531_Migrate_to_Credential_Manager branch September 23, 2026 10:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Integrate Credential Manager with Sign in with Google

2 participants