Turbolinks 5 Android and Omniauth/OAuth2

Viewed 243

Thoroughly impressed by the Turbolinks 5 Android wrapper. Its existence prompted my first steps into android development. Everything is moving smoothly except for handling the existing user authentication process. Given this is security, I really want to make sure it's handled correctly

User authentication and session management has been handled cleanly by a vanilla implementation of the 'omniauth-google-oauth2' gem, linked in to devise. This has been functioning live for a web-app serving around 1 million users per month.

The user clicks log-in and the omniauth callback process starts. The issue arises for the turbolinks-android implementation since this link is not a turbolink. I've successfully captured when a user clicks this button from within the android app:

public void visitProposedToLocationWithAction(String location, String action) {
    Intent intent = new Intent(this, MainActivity.class);
    intent.putExtra(INTENT_URL, location);
    if (location.equals("https://example.com/users/auth/google_oauth2")) {
        Log.d("linkclicked", "oauthcaptured");
        //handle OAuth
    } else {
        this.startActivity(intent);
    }
}

I beleived I had two options to handle this:

  1. Open a separate webview activity that has a copy of the turbolinks session cookie, let it authenticate, then pass back to the turbolinks session somehow.

  2. Use this click to start an android native authentication process, then pass the authentication token received back to the app server using an HTTPS POST as described by google.

Approach (1) was recommended by the gem contributors and on a separate thread for the ios version of this wrapper (sorry I can't link more than two URLs). But as I understand, google has banned web-views from initiating oauth2 flows and any attempt I have made has resulted in a block and warning from google.

I believe Approach (2) is the only path forward now, but I have no idea how to post the authentication token back to the rails server and have it picked up by the existing omniauth/devise flow and connected to the turbolinks android session. I presume I would also have to send the turbolinks session cookie along with the authentication token so that somehow after machinations, the app could tie the authenticated user back to the session contained in the android turbolinks session cookie.

I'm not really sure how to go forward however and it all just feels sketchy, and security really shouldn't. Given Omniauth is so ubiquitous and how easy turbolinks makes having an android and ios version of your web-app, this must be an issue others are/will be facing.

0 Answers
Related