My client(front-end) is a native mobile app (built with Flutter). For the backend, I'm using Spring to expose resources via Rest API endpoints. I want to implement Google Sign-In for my application. Also, I want to use OAuth flow for my own end points.
I found overall flow recommended for this situation Authenticate with a backend server. So as I understood the process is like this:
I use google sing in my native app and it receives token when user signs in, then the app send it to my authorization server(AS). Then AS just directly sends access (+ refresh) token to the app(i.e client). We can say that it is a password grant type, but instead of using user and password to identify user, AS uses token which we received from google. And when the app calls my Resource server(RS) it uses access token issued by my AS. am I right? PS I draw some diagram showing this flow:
In summary, the question is how to build your Oauth flow when you receive google token id? is using password grant type recommended for this situation? Does it make sense using authorization code flow, considering that my client has already received id token?
![[https://drive.google.com/file/d/1mvB6InwLAJeVe8DRqPFodyPRAz6lzUhK/view][2].](https://i.stack.imgur.com/HXPQs.png)