google-auth-required
Makes Google the only permitted sign-in method for the project's members, in the platform's standard sign-in service. Ovok's tenant sign-in routes, the current way to sign in to a project, do not apply this check, so enabling it does not make a project Google-only. Test every sign-in path your apps use before you rely on it.
| Type | Project feature |
Value in features | google-auth-required |
| Change with | PATCH /v1/projects/me/features (replaces the whole list) |
| Who can change it | Project admin. Any practitioner can read the list. |
| On for new projects | No |
| When on | Non-Google sign-in is refused where the check applies |
| When off | No restriction |
Where the check applies
| Sign-in path | Applies? |
|---|---|
POST /auth/tenant/Patient/login/* and POST /auth/tenant/Practitioner/login/* (the current sign-in) | No. These routes verify the user and complete the session themselves. |
The platform's standard OAuth2 sign-in (/oauth2/*) | Yes. A non-Google sign-in is refused with 400 and Google authentication is required. |
The older POST /v2/auth/login | Yes, but the failure is reported as a generic 400, the same as a wrong password. |
| TAN sign-in | No |
POST /auth/external/google and /auth/external/apple | No |
The check is made when a session is created. Sessions that already exist keep working until they end.
Turn it on
curl --request PATCH \
--url 'https://api.sandbox.ovok.com/v1/projects/me/features' \
--header "Authorization: Bearer ${OVOK_TOKEN}" \
--header 'Content-Type: application/json' \
--data '{"features":["bots","cron","email","transaction-bundles","websocket-subscriptions","google-auth-required"]}'
Start from the list GET /v1/projects/me/features returns, and add google-auth-required to it.
Gotchas
- It is not a project-wide Google-only switch. The tenant sign-in routes, TAN sign-in and social sign-in do not apply it, so users can still sign in with a password through the tenant routes. To stop those paths, use PATIENT_LOGIN_ENABLED and PRACTITIONER_LOGIN_ENABLED, and check which paths each switch covers.
- It can lock admins out of the standard sign-in. With the feature on, a password sign-in through the standard OAuth2 flow is refused for everyone in the project, including project admins. Keep a signed-in admin session open until you have confirmed that your admins can sign in with Google.
- The error is not always specific. Only the OAuth2 flow reports
Google authentication is required. Do not parse it out of the deprecated route. - It does not sign anyone out. Turn it on and existing sessions continue, and can refresh.
- Google sign-in must work first. The feature restricts methods; it does not set up Google. Confirm that your Google sign-in works with your members before you require it.