-
Notifications
You must be signed in to change notification settings - Fork 215
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Privacy concerns #380
Comments
That's just a redirect / short link. You will notice your browser is being redirected immediately. |
The short answer is No, you are not. Slightly longer answer. |
I have the same question. @NoSubstitute, thanks for the explanation! A couple of questions I have:
More specifically, if I
then shouldn't that be all that GYB requires to download my email? But if I do this, I find that it is asking me to "authorize a third party app". Why is this step required, and what does it do that the steps above don't do? I trust this project given it's FOSS and well used, but for something as private as email, I'd love to trust but verify, hence the questions. Google seems to make it really hard to tell what is being given authorization, which is yet another reason these questions have come up for me. Thanks a bunch in advance! |
When you authorise, it shows you exactly what you are authorising. Yes, you can do all the things manually. The bit about "third-party app", I'm not sure what you are referring to. |
Thank you, @NoSubstitute. I did follow the manual directions, but it's the verification part that brought up the same questions as the OP. I think what's not clear to me is:
Thanks again! |
The third-party link is a redirect to Presumably it does this because the oauth URLs are absolutely massive and if you're in a situation where the user is copy-pasting URLs it's a lot easier to give the short form. (That said, it definitely is not possible to "do all the things manually", or at least, it's not documented -- the "manual" instructions still request permission to "see, edit, configure, and delete your Google Cloud data and see the email address for your Google Account" in order to create the project configuration. Presumably someone familiar with both Google Cloud and GYB could configure a cloud project "by hand" and point GYB at it?) |
@ToxicFrog, thanks, it helps to know curl-ing it verifies it's a 301 redirect. The remaining thing that's unclear to me is what I'm authorizing on the google.com page. It usually says something along the lines of "do you authorize XXX to <read your data, etc.>". Any tips on how a user could verify that 'XXX' is only their desktop GAM client, and not a third party client that can read the user's data? |
The page should contain information about the exact client_id used. |
Hi there - can someone explain to me if, in authorizing this app, I am authorizing a third party access to my private information (emails, etc.)? I am mainly asking because, at one point in the verification process, it asks me to sign in to my Google Account using my password, but the browser window URL is not google.com, but
https://gyb-shortn.jaylee.us/atar2j
Thanks!
The text was updated successfully, but these errors were encountered: