Skip to main content

google-auth-required

Makes Google the only permitted sign-in method for the project's members, in the platform's standard sign-in service. Ovok's tenant sign-in routes, the current way to sign in to a project, do not apply this check, so enabling it does not make a project Google-only. Test every sign-in path your apps use before you rely on it.

TypeProject feature
Value in featuresgoogle-auth-required
Change withPATCH /v1/projects/me/features (replaces the whole list)
Who can change itProject admin. Any practitioner can read the list.
On for new projectsNo
When onNon-Google sign-in is refused where the check applies
When offNo restriction

Where the check applies​

Sign-in pathApplies?
POST /auth/tenant/Patient/login/* and POST /auth/tenant/Practitioner/login/* (the current sign-in)No. These routes verify the user and complete the session themselves.
The platform's standard OAuth2 sign-in (/oauth2/*)Yes. A non-Google sign-in is refused with 400 and Google authentication is required.
The older POST /v2/auth/loginYes, but the failure is reported as a generic 400, the same as a wrong password.
TAN sign-inNo
POST /auth/external/google and /auth/external/appleNo

The check is made when a session is created. Sessions that already exist keep working until they end.

Turn it on​

curl --request PATCH \
--url 'https://api.sandbox.ovok.com/v1/projects/me/features' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"features":["bots","cron","email","transaction-bundles","websocket-subscriptions","google-auth-required"]}'

Start from the list GET /v1/projects/me/features returns, and add google-auth-required to it.

Gotchas​

  • It is not a project-wide Google-only switch. The tenant sign-in routes, TAN sign-in and social sign-in do not apply it, so users can still sign in with a password through the tenant routes. To stop those paths, use PATIENT_LOGIN_ENABLED and PRACTITIONER_LOGIN_ENABLED, and check which paths each switch covers.
  • It can lock admins out of the standard sign-in. With the feature on, a password sign-in through the standard OAuth2 flow is refused for everyone in the project, including project admins. Keep a signed-in admin session open until you have confirmed that your admins can sign in with Google.
  • The error is not always specific. Only the OAuth2 flow reports Google authentication is required. Do not parse it out of the deprecated route.
  • It does not sign anyone out. Turn it on and existing sessions continue, and can refresh.
  • Google sign-in must work first. The feature restricts methods; it does not set up Google. Confirm that your Google sign-in works with your members before you require it.