Google updates OAuth incremental authorization | ZDNet

Google has simplified the OAuth authorization process for users who give a third-party app access to Google apps such as Docs and Drive. 

The update, though minor, makes it possible for users to approve access to data in a Google Account a single tap process that’s friendlier for smartphones. 

OAuth is a widely supported standard for giving apps access to account information. It has been abused by attackers in the past and forced Google to introduce stricter rules for developers who use it to connect to Google apps. Today it requires all third-party apps use OAuth to request access to Google Account data, 

The current change is aimed at developers of web apps that use incremental authorization — a feature available from Google’s authorization server that lets developers request access to a certain “scope” of resources. 

Google recommends that permission requests are made at the time access is required rather than upfront, such as when an app saving an event to Google Calendar. The request should only be made after the user presses the ‘Add to Calendar’ button. 

Now, instead of checking a box and clicking ‘continue’ when granting access, users can just press continue for that single scope. 

It’s a continuation of work Google has done for how users can give consent to third-party apps to access Google Account data. In 2019 it introduced fine-grained controls with one screen for each scope requested. This July it consolidated multiple permission requests into a single screen. 

Google explains that developers don’t need to update their apps to support the simpler approval process but it does recommend they implement incremental authorization. 

“There is no change you need to make to your app. However, we recommend using incremental authorization and requesting only one resource at the time your app needs it,” notes Google in a blogpost

“We believe that doing this will make your account data request more relevant to the user and therefore improve the consent conversion.”

image-1-v3.png

Google

Stay connected with us on social media platform for instant update click here to join our  Twitter, & Facebook

We are now on Telegram. Click here to join our channel (@TechiUpdate) and stay updated with the latest Technology headlines.

For all the latest Technology News Click Here 

 For the latest news and updates, follow us on Google News

Read original article here

Denial of responsibility! TechiLive.in is an automatic aggregator around the global media. All the content are available free on Internet. We have just arranged it in one platform for educational purpose only. In each content, the hyperlink to the primary source is specified. All trademarks belong to their rightful owners, all materials to their authors. If you are the owner of the content and do not want us to publish your materials on our website, please contact us by email – [email protected]. The content will be deleted within 24 hours.