Our website allows users to create a new account using a registration page where we collect username, email, passwords, avatar, etc. The users activate their account and then login and browse, buy, comment, etc like normal.
We recently added the Login with Google button to our site as an additional option. Currently the system does the following:
- Get a post request from Google
- Verify the signature on the JWT and prepare the credentials
- Do some security checks on the request
- Check if the
emailexists with an existing user in our system - if it does, authorize them and login - If the
emailandsubdon't exist, create a new account and load the data from Googles credential POST to make a new account
The conflict here is whether or not we should be doing step 4 on existing accounts that were not created using Google or if those accounts should be converted to Google only accounts when they login.
For example,
I register with john@gmail.com as my account name with a password created on the register page. One day, I accidentally, or on purpose, click Sign in with Google. The system sees my email from the oauth login and finds my account already in the system.
Should it:
- Log me into the account without checking password, since its already my Google account, and keep everything else the same.
- Give me an error that my email is already in use on another account and abort the login process.
- Convert the account to a Google only sign-in and remove the password to prevent me from logging in without using Google in the future.
- Update the account with the Google sub id but keep the password option and allow them to reset their website password independently from Google should they wish to "unlink" their Google account in the future.
I believe step 4 would be the most logical, but as we have not implemented this before we want to follow the standard that most other developers would use - or maybe there's an even better way.