Below you can find evidence that Google is using the X-Auto-Login header in production.
Please see my other post for context:
http://ignisvulpis.blogspot.de/2014/09/deviceautologin.html
I am using "wget" to get gmail web page and the HTTP response contains the X-Auto-Login header.
I think that Google should standardize this.
Currently Google is using OpenID2 here but it is probably ease to standardize this with OpenID Connect.
ignisvulpis@namenlos:~/mozilla-central$ wget -S https://mail.google.com/mail --user-agent="Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2049.0 Safari/537.36" --2014-11-03 12:23:50-- https://mail.google.com/mail Connecting to 212.201.109.5:8080... connected. Proxy request sent, awaiting response... HTTP/1.1 302 Moved Temporarily Content-Type: text/html; charset=UTF-8 Cache-Control: no-cache, no-store, max-age=0, must-revalidate Pragma: no-cache Expires: Fri, 01 Jan 1990 00:00:00 GMT Date: Mon, 03 Nov 2014 11:23:51 GMT Location: https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/&ss=1&scc=1<mpl=googlemail&emr=1 X-Content-Type-Options: nosniff X-Frame-Options: SAMEORIGIN X-XSS-Protection: 1; mode=block Server: GSE Alternate-Protocol: 443:quic,p=0.01 Connection: close Location: https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/&ss=1&scc=1<mpl=googlemail&emr=1 [following] --2014-11-03 12:23:51-- https://accounts.google.com/ServiceLogin?service=mail&passive=true&rm=false&continue=https://mail.google.com/mail/&ss=1&scc=1<mpl=googlemail&emr=1 Connecting to 212.201.109.5:8080... connected. Proxy request sent, awaiting response... HTTP/1.1 200 OK Content-Type: text/html; charset=UTF-8 Strict-Transport-Security: max-age=10893354; includeSubDomains Set-Cookie: GAPS=1:lAGQAL021CeF4UofSLjbzRnvJw_Eqw:256mW0v3ZoeLVjLo;Path=/;Expires=Wed, 02-Nov-2016 11:23:51 GMT;Secure;HttpOnly;Priority=HIGH Set-Cookie: GALX=xATUIfBPIN4;Path=/;Secure X-Frame-Options: DENY Cache-control: no-cache, no-store Pragma: no-cache Expires: Mon, 01-Jan-1990 00:00:00 GMT
Transfer-Encoding: chunked Date: Mon, 03 Nov 2014 11:23:51 GMT X-Content-Type-Options: nosniff X-XSS-Protection: 1; mode=block Server: GSE Alternate-Protocol: 443:quic,p=0.01 Connection: close Length: unspecified [text/html] 2014-11-03 12:23:51 (1,44 MB/s) - ‘mail’ saved [70172] ignisvulpis@namenlos:~/mozilla-central$
No comments:
Post a Comment