Conversation
added 2 commits
September 27, 2026 21:42
The legacy GoogleSignIn APIs are removed in play-services-auth 22, which blocks the pending dependency updates. GoogleAccountProvider now gets Google ID tokens from Credential Manager instead: - Interactive login uses GetSignInWithGoogleOption and exchanges the ID token with the existing AuthApi. - Silent re-authentication uses GetGoogleIdOption limited to authorized accounts, and only accepts a refreshed credential for the same account. - Credential Manager has no getLastSignedInAccount equivalent, so the account id, ID token and GodTools user id are persisted in the provider's private SharedPreferences. The user id now lives under a new key, so existing Google users sign in again once. - Logout calls clearCredentialState() and clears the local state. The AccountProvider launcher API is unchanged; the Google provider returns a launcher that runs the suspend login on the composition scope. The tests now mock CredentialManager and GoogleIdTokenCredential parsing. CredentialManager loads its Play Services provider by reflection, so :library:account now ships a consumer R8 rule that keeps androidx.credentials.playservices, as the Sign in with Google guide asks. Without it, R8 strips the provider from release and QA builds and Google sign-in fails.
GoogleAccountProvider no longer uses GoogleSignIn, GoogleSignInKtx or the Task await() helpers, so play-services-auth, gto-support-play-auth and kotlinx-coroutines-play-services are no longer needed by :library:account. They had no other users, so their catalog entries go too.
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## develop #4656 +/- ##
===========================================
+ Coverage 53.56% 53.70% +0.13%
===========================================
Files 440 440
Lines 11572 11594 +22
Branches 1944 1946 +2
===========================================
+ Hits 6199 6227 +28
+ Misses 4790 4787 -3
+ Partials 583 580 -3 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Resolves #4612 (GT-3079)
GoogleAccountProviderstill used the legacyGoogleSignInAPIs that were removed inplay-services-auth22, which blocks the dependency updates in #4575 and #4582. This moves Google login to Credential Manager, following the same provider shape asFacebookAccountProvider.Changes
GoogleAccountProvider:GetSignInWithGoogleOptionusing the Activity context fromLocalContext. It then exchanges the Google ID token through the existingAuthApi(AuthToken.Request(googleIdToken = ...)), so the server contract does not change.authenticateWithMobileContentApi(), used byMobileContentApiSessionInterceptor) tries the stored ID token first. If the token is missing or the API rejects it, it gets a new credential withGetGoogleIdOption(authorized accounts only, auto-select). It only accepts that credential if it is for the same account.getLastSignedInAccount, so the account id, the latest ID token and the GodTools user id are saved in the provider's private SharedPreferences (org.godtools.account.google).userId,isAuthenticatedand the flows now read only from those prefs, so they still work after process recreation.MissingCredentials. A failed or mismatched silent refresh becomesUnableToRefreshCredentials. Network errors (IOException) are passed through as before, and API errors go throughextractAuthToken().logout()callsclearCredentialState()(aClearCredentialExceptionis logged at.d) and then clears the local prefs..d.GoogleModule: providesCredentialManager,GetSignInWithGoogleOptionandGetGoogleIdOptionfromGoogleBuildConfig.serverClientId. These replaceGoogleSignInOptionsandGoogleSignInClient.androidx-credentials,androidx-credentials-play-services-auth(sharedandroidx-credentialsversion) andgoogleidto the version catalog and:library:account.library/account/src/main/proguard-credentials.pro).play-auth(play-services-auth),gtoSupport-play-authandkotlin-coroutines-play-servicesfrom:library:accountand the catalog. These are orphaned by the migration and are removed in a separate commit.Intentionally not changed: the
AccountProvider.rememberLauncherForLogin()API and the login UI. The Google provider returns anActivityResultLauncher<AccountType>that runs the suspend login on the composition's coroutine scope, the same wayGodToolsAccountManagerwraps its launchers. SoLoginLayoutand the Circuit login work in #4610 are not affected.Behavior changes to be aware of:
user_id_<googleId>pref entries are left unused in the same prefs file, and the next logout clears them.silentSignIn(). With auto-select and one authorized account this should need no user input, but Credential Manager may show its "signing in" UI. Because this runs from the API interceptor, it uses the application context. This needs a manual check on a device (see Tests).play-services-authis no longer a direct dependency. It now comes in transitively throughcredentials-play-services-auth.Dependency versions (please verify)
Google Maven (
dl.google.com) is blocked in the environment where this was written, so no Gradle resolution was possible.androidx.credentials:credentials/credentials-play-services-auth1.6.0: taken from the official AndroidX release notes page (latest stable, April 8, 2026). Not resolved locally.com.google.android.libraries.identity.googleid:googleid1.2.1: NOT verified from an official source. The Google release notes page was unreachable. 1.2.0 is widely used, and 1.2.1 only showed up in third-party Renovate/Dependabot PRs from September 2026. If 1.2.1 does not resolve, fall back to 1.2.0.:library:accountnow ships a consumer rule (src/main/proguard-credentials.pro) that keepsandroidx.credentials.playservices.**. The Sign in with Google guide asks for this becauseCredentialManagerloads the Play Services provider by reflection. If the 1.6.0 artifact already ships the same rule, this one is a harmless duplicate. A release or QA build should still be used to check Google sign-in.Tests
GoogleAccountProviderTestwas rewritten around mockedCredentialManagerandGoogleIdTokenCredential.createFrom(). It covers:login(): success, cancellation, no credentials, unexpected credential type, parsing failure, network error, API rejectionlogout(): clears Credential Manager and local state, and still clears local state whenclearCredentialState()failsauthenticateWithMobileContentApi(): stored token success, network error, not authenticated, missing token refresh, rejected token refresh, refresh failure, refresh for a different account./gradlew :library:account:test,./gradlew :build-logic:ktlintCheck ktlintCheck,./gradlew lintand./gradlew bundlestill need to pass in CI. Every Credential Manager and googleid API used was checked against the official Sign in with Google implementation guide, not against the resolved artifacts.Review
Checked against the project conventions, a correctness review, a security review and a simplification pass:
GoogleAccountProviderneedsAuthApi, the appContext,CredentialManager,GetSignInWithGoogleOptionandGetGoogleIdOption. All are provided.GoogleBuildConfigcomes fromapp/.../dagger/AccountModule.kt. No@TestInstallInmodule or other code still refers toGoogleSignInClientorGoogleSignInOptions.googleidis declared inline because only one artifact uses it, likeplay-base. The two credentials artifacts share aversion.ref. Both follow the repo's pattern and are in alphabetical order. Neither version could be resolved here (Google Maven is blocked).GoogleSignIn,gms.authorcoroutines-play-servicesremain. The login button string comes fromplay-services-base, which:appdepends on directly.user_id_<sub>value would be unsafe. Those users have no stored account id and no ID token. Once their API session expires,authenticateWithMobileContentApi()would fail, and the app would still show them as logged in. Fixing that would mean weakening the same-account check on refresh.getCredential()with the application context. It runs from the OkHttp interceptor insiderunBlocking, often while the app is in the background. It may fail, or show UI, wheresilentSignIn()never did. If it fails, the user stays logged in but API calls go without auth until they sign in again.Generated by Claude Code