New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 627592 link

Starred by 4 users

Issue metadata

Status: WontFix
Owner:
Closed: Jul 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: All
Pri: 3
Type: Bug



Sign in to add a comment

Chrome has "full access" to my signed-in Google account

Project Member Reported by akalin@chromium.org, Jul 12 2016

Issue description

Version: 53.0.2785.8
OS: N/A

Looking at my account on https://security.google.com/settings/security/permissions , I see

Google Chrome
Has full access to your Google Account
REMOVE
Google Chrome has access to:	
	Full account access
Learn more
Authorization date:	
March 6, 3:12 AM

This seems, at best, confusing (c.f. recent hullabaloo with Pokemon Go having the same issue, see https://gist.github.com/arirubinstein/fd5453537436a8757266f908c3e41538 ). Is there a reason Chrome is doing this?

Putting the component as Security for now...
 

Comment 1 by palmer@chromium.org, Jul 12 2016

Cc: -palmer@chromium.org
Components: Services>Sync
Labels: OS-All
Owner: ew...@chromium.org
Status: Assigned (was: Untriaged)
Passing to ewald to triage.

Comment 2 by palmer@chromium.org, Jul 12 2016

Cc: rpop@chromium.org

Comment 3 by rpop@chromium.org, Jul 12 2016

Cc: anthonyvd@chromium.org pav...@chromium.org
Pavel, can you explain why this is the case? I believe this refers to the sync token, which is in turn used to mint other down-scoped tokens for apps, the content area, etc.

Comment 4 by pav...@chromium.org, Jul 12 2016

Components: -Services>Sync Services>SignIn
When user signs in, chrome requests login scoped refresh token (the one that has full account access). This token is later used for minting access tokens with reduced scopes for different components communicating with servers: sync, invalidations, gcm, identity_api,... . about:signin-internals shows list of currently requested access tokens and their corresponding scopes.

Requesting token with full access allows to mint access tokens for all these components and not ask user for credentials.

In a way this token is similar to the one issued to Android phone when user signs in. Android token is later exposed through AccountManager.getAuthToken API.

Comment 5 by ew...@chromium.org, Jul 13 2016

Cc: gogerald@chromium.org
Thanks for the explanation Pavel. Anthony, Ganggui - do either of you have anything to add?

This seems WAI to me.

Comment 6 by ew...@chromium.org, Jul 14 2016

Status: WontFix (was: Assigned)
Marking as WontFix for now (before I go OOO), since I believe this is WAI.

Sign in to add a comment