Authenticate my "app" to Google Cloud Endpoints not a "user"

Viewed 1706

What I'm trying to do is to authenticate my Android app to the Google Cloud Endpoint. Basically the endpoints should only allow my Android app to access the methods and nothing else.

I have done these things -

  1. Create a client id using my SHA1 value in Eclipse in the Google Cloud Console.

  2. Create a web client id in the Google Cloud Console for my endpoint project.

  3. Add both these client id's in the "@Api" mentioned on each endpoint.

  4. Add an extra "user" parameter in the endpoint methods.

  5. Regenerate and deploy the backend to the cloud.

But when I'm running this the "user" is always coming as "null". I'm at my wits end trying to find a proper working method for doing all this.

I've searched many forums but no proper answers anywhere.

Here's another similar post Restrict access to google cloud endpoints to Android app

This is the reference I'm using - https://developers.google.com/appengine/docs/java/endpoints/auth

Has anyone here done this before? My main goal is to not allow unauthenticated apps and outside world to access the endpoints, for obvious security reasons. I don't want to use end-user based authentication since I want to keep my app very simple.

3 Answers

It sounds like it's working as intended. You control which client apps can call your endpoint methods via the client IDs as you have already done. The User parameter is coming in as null precisely because you aren't doing end-user authentication. The User parameter represents an actual real user (Google Account). So if you don't need end-user authenticated methods, you can just simply not define the User parameter, or else ignore the null value. You said your problem is that the User parameter is set null. What are you expecting it to be in this scenario?

Related