4.2 KiB
4.2 KiB
Google Authentication Setup
OAuth Credentials Summary
You now have TWO OAuth credentials configured in Google Cloud Console:
1. Web Application (for backend)
- Client ID:
416332591622-godddvcplbobkhv6uvabg94pvtukp61u.apps.googleusercontent.com - Type: Web application
- Purpose: Backend token exchange (
POST /auth/google-token) - Authorized redirect URIs: Configured on your backend
2. Android Application (for mobile app)
- Client ID:
416332591622-41ioels091g0am6v5m1catf0tt69ohk4.apps.googleusercontent.com - Type: Android
- Package name:
com.example.resbuilder - SHA-1 fingerprint:
38:A9:E7:27:69:40:77:77:A7:3D:A1:AC:21:F2:8E:50:5D:C9:AC:7F - Purpose: Android Credential Manager + Google Sign-In
What Was Changed
Dependencies Added
// gradle/libs.versions.toml
credentialManager = "1.5.0-beta01"
googleid = "1.1.1"
kotlinxCoroutines = "1.9.0"
androidx-credential-manager
androidx-credential-manager-play-services
googleid
kotlinx-coroutines-android
Code Migration
The LoginActivity.kt now uses:
- Credential Manager API (primary) - Modern, recommended approach
- Legacy Google Sign-In (fallback) - For devices that don't support Credential Manager
Key changes:
- Uses
androidClientIdfor Credential Manager flow - Uses
webClientIdfor backend token exchange - Automatic fallback to legacy API if Credential Manager fails
- Coroutines for suspend function support
- Nonce generation for enhanced security
Verification Steps
-
Build the app:
./gradlew assembleDebugAPK:
app/build/outputs/apk/debug/app-debug.apk -
Install on device/emulator with your debug keystore SHA-1
-
Test sign-in flow:
- Tap "Sign in with Google"
- Account picker should appear
- Select an account
- Should authenticate and navigate to main screen
Troubleshooting
Error 10: Developer Error
- SHA-1 fingerprint doesn't match Google Cloud Console
- Package name doesn't match
- Fix: Verify SHA-1 in Google Cloud Console matches
38:A9:E7:27:69:40:77:77:A7:3D:A1:AC:21:F2:8E:50:5D:C9:AC:7F
Error 16: Sign In Cancelled
- User cancelled the account picker
- Normal behavior, not an error
Credential Manager not working
- Device may not support Credential Manager
- Fix: App automatically falls back to legacy Google Sign-In
API Flow
┌─────────────────┐
│ User taps │
│ Sign In │
└────────┬────────┘
│
v
┌─────────────────┐
│ Credential │
│ Manager │◄─── Uses androidClientId
└────────┬────────┘
│
v
┌─────────────────┐
│ Google returns │
│ ID Token │
└────────┬────────┘
│
v
┌─────────────────┐
│ App sends ID │
│ Token to backend│
│ POST /auth/ │
│ google-token │◄─── Backend validates with webClientId
└────────┬────────┘
│
v
┌─────────────────┐
│ Backend returns │
│ session token │
└────────┬────────┘
│
v
┌─────────────────┐
│ App stores │
│ session token │
│ (Bearer auth) │
└─────────────────┘
Next Steps (Optional)
For production release:
- Get release SHA-1 from Play Console or your release keystore
- Add release SHA-1 to Google Cloud Console (same Android OAuth client)
- Build signed release APK/AAB
- Test with release credentials