From 4af7893838353c0b9f05e1a88d60133160f55c20 Mon Sep 17 00:00:00 2001 From: mudabbir-ahmad Date: Mon, 23 Feb 2026 00:41:54 +0000 Subject: [PATCH] removed the web ID as no longer interested in maintaining website functionality for this project due to current time restraints, switching over to just making a production ready ANDROID apk. --- src/AUTH/GoogleAUTH.js | 24 +++++++++--------------- 1 file changed, 9 insertions(+), 15 deletions(-) diff --git a/src/AUTH/GoogleAUTH.js b/src/AUTH/GoogleAUTH.js index 41fa50f..4973a3d 100644 --- a/src/AUTH/GoogleAUTH.js +++ b/src/AUTH/GoogleAUTH.js @@ -5,16 +5,10 @@ import { AuthServiceBase } from './AuthServiceBase'; WebBrowser.maybeCompleteAuthSession(); -// Web client ID — used for token exchange (authorization code → access token). -// Created in Google Cloud Console as "Web application" type. -// No redirect URIs need to be registered for this client. -const WEB_CLIENT_ID = '313090284964-rgq1u7np6ogucu9o97s134n5nc6nj7kf.apps.googleusercontent.com'; -// Android client ID — used for the authorization request on Android. -// Created in Google Cloud Console as "Android" type with: -// Package name: com.bobthebob.massphotoapp -// SHA-1 fingerprint: -//REMOVE LATER. 59:1C:1A:B2:61:C9:8D:80:C8:E1:96:FE:CA:44:18:CE:91:5E:38:63 IS THE SHA-1 FINGERPRINT FOR THE APP -// Android clients verify by package + SHA-1, no redirect URI registration needed. +// Android client ID — used for both auth requests and token exchange. +// Created in Google Cloud Console as "Android" type with package name +// com.bobthebob.massphotoapp and the SHA-1 from `eas credentials --platform android`. +// Android clients are public (no client_secret needed) — PKCE verifies instead. const ANDROID_CLIENT_ID = '313090284964-pa9p2rs7g60l9t8hr6haee3qbn2a7vl9.apps.googleusercontent.com'; const GOOGLE_DISCOVERY = { @@ -82,11 +76,11 @@ class GoogleAUTH extends AuthServiceBase { throw new Error('Google authentication was cancelled or failed'); } - // Exchange authorization code for tokens using the Web client ID. - // Android public clients don't have a client secret — the code_verifier - // from PKCE is used to verify the exchange instead. + // Exchange authorization code for tokens using the Android client ID. + // Android clients are public (no client secret required) — the PKCE + // code_verifier is used to verify the exchange instead. const tokenBody = new URLSearchParams({ - client_id: WEB_CLIENT_ID, + client_id: ANDROID_CLIENT_ID, code: result.params.code, code_verifier: authRequest.codeVerifier, grant_type: 'authorization_code', @@ -146,7 +140,7 @@ class GoogleAUTH extends AuthServiceBase { async refreshAccessToken() { try { const body = new URLSearchParams({ - client_id: WEB_CLIENT_ID, + client_id: ANDROID_CLIENT_ID, refresh_token: this.refreshToken, grant_type: 'refresh_token', });