google / google/GoogleSignIn-iOS

Map alternate scope names in `addScopes`

Open
#599 1 comment 1 reaction 1 assignee Claimed by @w-goog View on GitHub
bug
Dominant language
Objective-C
Stars
750
Forks
282
Avg merge
2d 15h
Merged PRs (30d)
9

Description

**Describe the bug**
When calling `addScopes`, the [check against the existing granted scopes](https://github.com/google/GoogleSignIn-iOS/blob/6ad8c90700ecb28d645c8ff76535732f89c38315/GoogleSignIn/Sources/GIDSignIn.m#L382) doesn't normalize the names. If the [core scopes](https://developers.google.com/identity/protocols/oauth2/scopes#google-sign-in) are passed in using their short names (`email`, `openid`, `profile`), the SDK will prompt unnecessarily, because the granted scopes appear to use [the v2 names](https://developers.google.com/identity/protocols/oauth2/scopes#oauth2).

Obviously this can be easily worked around from the client side by not making that call in the first place, but it creates some unexpected complexity in the Flutter wrapper (see https://github.com/flutter/flutter/issues/184872), which has to bridge across the iOS, Android, and Web sign in APIs (which are all quite different). We can work around it at the wrapper level, but it would be nice if the SDK handled this name mismatch internally.

**To Reproduce**
Steps to reproduce the behavior:
1. Sign in.
2. Call `addScopes:...` with `[@"email", @"openid", @"profile"]` as the scopes.
3. See a user prompt.

**Expected behavior**
Receive `kGIDSignInErrorCodeScopesAlreadyGranted`, since AFAICT signing in grants those scopes automatically, but under different names.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.