Stay Signed in Google Calendar

Viewed 44

I'm looking at the google calendar QuickStart found here: Google calendar JavaScript quickstart.

Currently, I have to sign in every time I refresh the page. Does anyone know how to get sign in persistence between sessions?

1 Answers

The first thing you need to understand is the differences between authorization and authentication.

Authentication is signin in. A user clicks a button and logs into your application. In some cases using their login from google, facebook, twitter, or github. Googles new Google Identity Services is one such system which allows you to signin via the web using JavaScript to their identity server. Authentication for the most part gives you access only to the users profile information, thats why you can use the google people api with the access token returned from a signin, and why you can access the userinfo endpoint.

Authorization is something completely different. There are two types of data public data and private user data. Public data like public videos on YouTube anyone can access. Private user data like the users calendar data is private data and you must have the consent or permission of the user for your application to access it.

To get that permission we use Oauth2.

When the user consents to your having access to their data you are given an access token, this access token is short lived you only have access for an hour, due to the nature of client side JavaScript implicit flow. After an hour your going to have to ask the user for permission o access their data again.

The code in JavaScript Quickstart is gong to store the data in a session value or a cookie. When the user refreshes the page your going to loose that access and have to request permission again.

To be clear

Currently, I have to sign in everytime I refresh the page. Does anyone know how to get sign in persistence between sessions?

The sample you are using is not for sign-in (authentication) it is for authorization, as this is not sign-in there is no way to make it persistent across sessions.

If you use a server sided programming language you could request an refresh token which will give your application access to the users data when they are offline, by using the refresh token you can request a new access token when ever you need. This is not an option with client side javascript implicit flow.

Related