How google Calendar authorization works

Viewed 80

I want to create an application that can share my schedule with all users in the same room using google calender api.

When authenticating with web client (oauth), do each user have the authority to view only the information of the user authenticated by his own browser?

For example, suppose user A and user B authenticate with oauth in their respective browsers.

In this case, does User B's browser have permission to view User A's calendar? Or can I only view my own calendar?

If I want to do the above, do I have to use a backend to hold a per-user access token?

1 Answers

its a little more complicated than that.

When user A run your application the user is displayed a consent screen. Asking them if they are willing to give your application access to their data. Assuming the user gives your application access. Then Your application has access to access that users data.

When user B runs the application then the application will request user B for permission to access their data.

The application has access to user B's data and user A's data. User A does not have access to user B's data.

What you could do is create a page where your application then displays data to both users from each others calendars. If you want this to be a permanent thing then the application could also add user A to user Bs calendar and visa versa. Granting them each access to each other's data.

You may end up with some issues here as FAR As GDPR goes you will need to be sure that the two users realise that they are going to be sharing data for their calendars. Does user A really want to show user B that they have an appointment for a hair transplant operation on monday for example. This is private user data and you are treading on some sensitive data here.

Related