From mboxrd@z Thu Jan 1 00:00:00 1970 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: David Engster Newsgroups: gmane.emacs.devel Subject: Re: Making GNUS continue to work with Gmail Date: Thu, 13 Aug 2020 19:40:50 +0200 Message-ID: <87mu2y5tr1.fsf@randomsample> References: <87v9ienz6c.fsf@gnus.org> <878sf9c69y.fsf@gnus.org> <871rkw62t3.fsf@gnus.org> <87bljki71n.fsf@mat.ucm.es> <87364wxlec.fsf@gnus.org> <87imdsgmlw.fsf@mat.ucm.es> <871rkfhkhc.fsf@mat.ucm.es> <875z9p5hnc.fsf@mat.ucm.es> Mime-Version: 1.0 Content-Type: text/plain Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="40365"; mail-complaints-to="usenet@ciao.gmane.io" User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.0.91 (gnu/linux) Cc: Emacs developers To: David De La Harpe Golden Original-X-From: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Thu Aug 13 19:41:34 2020 Return-path: Envelope-to: ged-emacs-devel@m.gmane-mx.org Original-Received: from lists.gnu.org ([209.51.188.17]) by ciao.gmane.io with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1k6HEL-000APL-LG for ged-emacs-devel@m.gmane-mx.org; Thu, 13 Aug 2020 19:41:33 +0200 Original-Received: from localhost ([::1]:53620 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1k6HEK-0005lY-NQ for ged-emacs-devel@m.gmane-mx.org; Thu, 13 Aug 2020 13:41:32 -0400 Original-Received: from eggs.gnu.org ([2001:470:142:3::10]:44028) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1k6HDm-0005KQ-OE for emacs-devel@gnu.org; Thu, 13 Aug 2020 13:40:58 -0400 Original-Received: from zplane.randomsample.de ([2a03:4000:42:1a1:9400:eeff:feb4:c8a0]:57506) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1k6HDk-0001BK-Rd for emacs-devel@gnu.org; Thu, 13 Aug 2020 13:40:58 -0400 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=randomsample.de; s=a; h=Content-Type:MIME-Version:Message-ID:Date: References:In-Reply-To:Subject:Cc:To:From:Sender:Reply-To: Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Id: List-Help:List-Unsubscribe:List-Subscribe:List-Post:List-Owner:List-Archive; bh=9UyAFQNuxcGvLHROnRuy9fyeeKg/R7ASBl1IL5wxsH8=; b=T7rKX3JxVc53OSuukjSB8lcbL fkxkHKrZMFexKcognK8mNczQwu5upLr2q/hpS/io02I32aZF/7lcHmKebJUx5ghtnc1LvHb25f6Sn 6BEMJx1+X6ZTMBsDZg7QNyirc+s5BrysH7pwKcrXdI7f6BD+uTNTvhB6NANkLk/D2D+sdahfQdpAt S0TCFWX8B/Uktig62AJCktkVniXgh621CWhrgYFZ3Mh1AyaH7a9q8+mBVUDvzSxCLmGmbhfgOVglt +4fz6Vwhbh3f6kOGDYpCgSdcZaC7GBv8+RkdxY2ZXYzU8ZOniT64ptMMadgRpQUhWvJcuchabol8C sZfvnMlLw==; Original-Received: from vpn23b.hotsplots.net ([176.74.57.164] helo=void) by zplane.randomsample.de with esmtpsa (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1k6HDg-0006Nd-0o; Thu, 13 Aug 2020 19:40:52 +0200 In-Reply-To: (David De La Harpe Golden's message of "Thu, 13 Aug 2020 16:39:44 +0100") Received-SPF: pass client-ip=2a03:4000:42:1a1:9400:eeff:feb4:c8a0; envelope-from=deng@randomsample.de; helo=zplane.randomsample.de X-detected-operating-system: by eggs.gnu.org: First seen = 2020/08/13 13:40:53 X-ACL-Warn: Detected OS = ??? X-Spam_score_int: 12 X-Spam_score: 1.2 X-Spam_bar: + X-Spam_report: (1.2 / 5.0 requ) BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, RCVD_IN_SBL_CSS=3.335, SPF_HELO_NONE=0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001 autolearn=no autolearn_force=no X-Spam_action: no action X-BeenThere: emacs-devel@gnu.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: "Emacs development discussions." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: emacs-devel-bounces+ged-emacs-devel=m.gmane-mx.org@gnu.org Original-Sender: "Emacs-devel" Xref: news.gmane.io gmane.emacs.devel:253741 Archived-At: > Google do appear to recognise and accept such > desktop app hardcoded static client ids and "secrets" they issue > aren't actually secret in this case, just some bits anyone can easily > snaffle e.g. > > https://developers.google.com/identity/protocols/oauth2/native-app > > """ > Note: incremental authorization with installed apps is not supported > due to the fact that the client cannot keep the client_secret > confidential. > """ Yes, they aknowledge this fact. And yet they explicitly forbid embedding these secrets into (F)OSS applications. See https://developers.google.com/terms Section 4b, first paragraph. So what Thunderbird and many other applications do is against these terms of service. Google can at any point revoke the client id and ban the corresponding developer account. Maybe the FSF should simply register a client id and secret and make it public for any GPL application to use. -David