Guidance to developers affected by our effort to block less secure browsers/apps
developers.googleblog.com
developers.googleblog.com
However - I think it's worth having a discussion about this. I don't see the issue.
Can someone explain? Embedded browsers are a terrible way to offer 3rd party oAuth login. Apps should redirect to a browser for the login flow.
Anything else trains users that typing their password for company A into an app from company B is fine. And surely that means phishing becomes trivial.
On the original post the comment was:
> Key Quote: > > The browser must not provide automation features. This includes scripts that automate keystrokes or clicks, especially to perform automatic sign-ins.