Hacker News new | ask | show | jobs
by judge2020 1992 days ago
The meat of this story is that, instead of showing the Google oauth flow which would say “sign in to continue to <app>” with the list of permissions shown to the user, he embedded a web view that is actually a URL for setting up a new android device. This is exactly the reason Google is doing things like restricting embedded browser sign-ins[0], which HN was particularly critical about[1].

0: https://9to5google.com/2019/04/18/google-block-man-in-the-mi...

1: https://news.ycombinator.com/item?id=25155451