3 ms·
Thank you very much for your input here. You are 100% correct. It is the same implementation that DarwinMail uses. -- This document explains how to implement
by DarwinMailApp 7y ago
Thank you very much for your input here. You are 100% correct. It is the same implementation that DarwinMail uses.
--
This document explains how to implement OAuth 2.0 authorization to access Google APIs from a JavaScript web application. OAuth 2.0 allows users to share specific data with an application while keeping their usernames, passwords, and other information private. For example, an application can use OAuth 2.0 to obtain permission from users to store files in their Google Drives.
This OAuth 2.0 flow is called the implicit grant flow. It is designed for applications that access APIs only while the user is present at the application. These applications are not able to store confidential information.
In this flow, your app opens a Google URL that uses query parameters to identify your app and the type of API access that the app requires. You can open the URL in the current browser window or a popup. The user can authenticate with Google and grant the requested permissions. Google then redirects the user back to your app. The redirect includes an access token, which your app verifies and then uses to make API requests.
--
DarwinMail basically sits on top of Google's servers and displays the data in the same manner (and in time using the exact same features + more) as Inbox did.
Darwin does not store any of your email data whatsoever. In fact, if it did, Google would have asked me to audit the tool - but they instead granted me Google verification. It took them almost a month to break down DarwinMail and make sure it did not store any user email data.
Further reading:
https://developers.google.com/gmail/api/auth/about-auth https://developers.google.com/gmail/api/auth/about-auth
https://support.google.com/cloud/answer/9110914 https://support.google.com/cloud/answer/9110914