fix(auth): add missing profile scope for people/me verification - #120
Merged
Conversation
gro init calls people/me with PersonFields("names,emailAddresses") to
verify the People API and power `gro me`. The contacts scope covers
the contacts list but not the authenticated user's own profile — Google
requires userinfo.profile for that endpoint.
Without this scope, gro init always fails with a 403 on the People API
verification step, making fresh credential setup impossible.
Closes #119
Update the hardcoded count in TestAllScopes (6→7) and add the scope assertion. Add userinfo.profile to the architecture test allowlist with a note that it is read-only and scoped to the authenticated user's own profile, not the contacts list.
Contributor
Author
|
Findings
Notes The production scope choice looks correct. Google’s People API docs show
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Adds
people.UserinfoProfileScope(https://www.googleapis.com/auth/userinfo.profile) toAllScopesandScopeDescriptionsininternal/auth/auth.go.Why
gro initverifies each Google API after OAuth by making a live call. The People API verification callspeople/mewithPersonFields("names,emailAddresses")— this also powersgro me. Google requires theuserinfo.profilescope for this endpoint; thecontactsscope only grants access to the user's contacts list, not their own profile.Without this fix,
gro initalways exits with a 403 on the People API verification step:This makes fresh credential setup completely broken for anyone following the setup instructions.
Migration
Existing users with a stored token will need to re-authenticate after upgrading:
gro config clear && gro initCloses #119