Files
Media-Aggregation-and-Sorti…/ignorefiles/GOOGLE_OAUTH_SETUP.md
T

2.7 KiB

Google OAuth Setup for Android APK

Step 1: Create a Google Cloud Project

  1. Go to https://console.cloud.google.com/
  2. Click Select a project → New Project
  3. Name it and click Create

Step 2: Enable the Photos Picker API

  1. Go to APIs & Services → Library
  2. Search for Photos Picker API → Enable it
  3. ⚠️ This step is required — without it, all Picker API calls fail
  4. (The old "Photos Library API" is deprecated and no longer works)
  1. Go to APIs & Services → OAuth consent screen
  2. Choose External → Create
  3. Fill in:
    • App name: MASS Photo App
    • User support email: your email
    • Developer contact: your email
  4. Scopes → Add or Remove Scopes → add these:
    • openid
    • https://www.googleapis.com/auth/photospicker.mediaitems.readonly
    • https://www.googleapis.com/auth/userinfo.email
    • https://www.googleapis.com/auth/userinfo.profile
  5. Test users → Add your Google account email address
    • ⚠️ This is critical — if your email is not listed as a test user, Google will silently strip the Photos Picker scope from the granted token.

Step 4: Create an Android OAuth Client ID

  1. Go to APIs & Services → Credentials
  2. + Create Credentials → OAuth client ID
  3. Application type: Android
  4. Package name: com.bobthebob.massphotoapp
  5. SHA-1 certificate fingerprint: get it by running eas credentials --platform android
  6. Click Create and copy the Client ID
  7. Open src/AUTH/GoogleAUTH.js and set ANDROID_CLIENT_ID to the copied value

How it works

  • The Android client ID is used for both the authorization request and the token exchange. Google verifies the request using the app's package name + SHA-1 signing certificate, so no redirect URI registration is needed.
  • The redirect goes to com.bobthebob.massphotoapp:/oauthredirect which Android routes back into the app via the intent filter in app.json.
  • Android clients are public (no client_secret required). PKCE code_verifier is used to secure the authorization code exchange.

Testing the API with OAuth Playground

  1. Go to https://developers.google.com/oauthplayground
  2. Click the gear icon → check "Use your own OAuth credentials"
  3. You will need a Web application client for the playground only (the playground cannot use Android clients). Create one in the console if needed, add https://developers.google.com/oauthplayground to its redirect URIs.
  4. Select Photos Library API scopes and authorize
  5. Copy the access token and run: node TEST/testGooglePhotosAPI.js <TOKEN>