{"id":9205,"date":"2019-05-13T06:50:39","date_gmt":"2019-05-13T06:50:39","guid":{"rendered":"https:\/\/www.gmass.co\/blog\/?p=4205"},"modified":"2020-01-26T03:56:38","modified_gmt":"2020-01-26T03:56:38","slug":"live-updates-google-oauth-verification-security","status":"publish","type":"post","link":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/","title":{"rendered":"Live Updates on the Google OAuth verification process and security audit"},"content":{"rendered":"<p>Earlier I wrote about my feelings on <a href=\"https:\/\/www.gmass.co\/blog\/google-oauth-verification-security-assessment\/\">Google&#8217;s new\u00a0verification process for sensitive and restricted Gmail API scopes<\/a>, and here I&#8217;ll be posting <strong>live updates<\/strong> of GMass&#8217;s journey through the process. We&#8217;re doing this for the benefit of the <strong>thousands of developers that have yet to begin the process<\/strong>, are thinking about the process, or are <strong>frustrated<\/strong> with the process.<\/p>\n<h3>1\/25\/2020<\/h3>\n<p>In my previous update on 1\/5\/2020, I mentioned that Wordzen, by some miracle, had managed to still have full access to the omnipotent <strong>https:\/\/mail.google.com scope<\/strong> despite skipping the security assessment. <strong>I spoke too soon.<\/strong> On January 13, I received word that the project had been reviewed, and my access to that scope was no longer.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-11025 size-large\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png\" alt=\"\" width=\"640\" height=\"715\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png 916w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-268x300.png 268w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-768x859.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-21x24.png 21w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-32x36.png 32w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-43x48.png 43w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29.png 1352w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h3>1\/5\/2020<\/h3>\n<p>Due to time constraints and wanting to keep my sanity, I haven&#8217;t posted live updates in a while, though much has happened. since August of 2019. I&#8217;ll attempt to summarize what&#8217;s happened lately, in this final update.<\/p>\n<p>GMass was approved and<strong> issued the Letter of Assessment from Leviathan in October<\/strong>. Google then approved the restricted scopes that GMass needed to operate.<\/p>\n<p>Also in October, Google announced that developers using the Google Sheets v3 API would need to migrate to v4, <a href=\"https:\/\/www.gmass.co\/blog\/google-sheets-api-v4-bullshit\/\">necessitating a new OAuth verification procedure<\/a>, one that I&#8217;m still navigating.<\/p>\n<p>In addition to GMass, I have <strong>two other apps that use restricted Gmail API scopes<\/strong>, Wordzen and SearchMyEmail.com. After Leviathan completed the assessment of GMass in October, I asked if they would now review Wordzen. Wordzen is a much simpler app than GMass and because I now had the knowledge of what a security assessment is, I figured Wordzen would be much easier. Unfortunately, Leviathan told me they were <a href=\"https:\/\/www.dropbox.com\/s\/g04xpauvfrzqqwb\/Screenshot%202020-01-05%2004.09.30.png?dl=0\" data-rel=\"lightbox-image-0\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\">too busy to review Wordzen<\/a>.<\/p>\n<p>I considered engaging <strong>Bishop Fox<\/strong> or the new assessor, <strong>NCC<\/strong>, for Wordzen and SearchMyEmail, but because both of those apps are non-revenue-generating, I decided against it and to let those apps remain &#8220;unverified&#8221;, which comes with some <a href=\"https:\/\/www.gmass.co\/blog\/five-annoying-issues-google-oauth-scope-verification\/#unverified\">interesting quirks<\/a>.<\/p>\n<p>In mid-November, Leviathan contacted me. Even though I had passed the security assessment, they needed to ensure that I had a Vulnerability Disclosure Program set up. As a result I created the URL <a href=\"http:\/\/gmass.co\/incident\" target=\"_blank\" rel=\"noopener noreferrer\" data-saferedirecturl=\"https:\/\/www.google.com\/url?q=http:\/\/gmass.co\/incident&amp;source=gmail&amp;ust=1578301728923000&amp;usg=AFQjCNGWVaUk-Uj2B1QM-yhMv8JNB8bGJw\">gmass.co\/incident<\/a> and added this to the footer of the GMass website.<\/p>\n<p>For SearchMyEmail.com, in June\/July I had a lengthy back and forth with the OAuth team. I was at the stage where a security assessment was required, and I <strong>informed them that I would not be undergoing the assessment<\/strong>, would happily remain &#8220;unverified&#8221; and that I would just remain under the 100-user unverified app limit. I had planned to do this by revoking inactive tokens and forcing users to re-auth periodically. However, I found that Google&#8217;s counting of active tokens was flawed, and after complaining enough, they <a href=\"https:\/\/www.dropbox.com\/s\/lo948m25mm2xsj7\/Screenshot%202020-01-05%2004.22.11.png?dl=0\" data-rel=\"lightbox-image-1\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\">increased my limit from 100 tokens to 200 tokens<\/a>.<\/p>\n<p>For Wordzen, the outcome was different. After being sent multiple emails informing me I must undergo the security audit, I wrote back, noting that there are only 25 active users for Wordzen, and since I&#8217;m under 100, if Wordzen could continue operating that way. They responded with <a href=\"https:\/\/www.dropbox.com\/s\/5r2djbqpsz4tou0\/Screenshot%202020-01-05%2004.28.46.png?dl=0\" data-rel=\"lightbox-image-2\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\">this detailed explanation which put my concerns at rest<\/a>. Additionally, in a <strong>Google OAuth miracle<\/strong>, as of 2020, the Cloud Console for the Wordzen project is <strong>showing the full https:\/\/mail.google.com scope as an officially approved scope for the Wordzen app<\/strong>. I don&#8217;t know how that happened &#8212; Wordzen never went through the security audit.<\/p>\n<h3>10\/21\/19<\/h3>\n<p>Looks like Google has added a third security company, NCC, that can perform a security assessment. Also, Leviathan is no longer accepting new projects for 2019.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-10159 size-large\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-780x1024.png\" alt=\"\" width=\"640\" height=\"840\" srcset=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-780x1024.png 780w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-228x300.png 228w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-768x1009.png 768w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-18x24.png 18w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-27x36.png 27w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58-37x48.png 37w, https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-10-21-13.57.58.png 1436w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><\/p>\n<h3>8\/26\/19<\/h3>\n<p>The security assessment officially kicks off. On the first day of testing, Leviathan finds a SQL injection issue which they determine is critical. I fix the issue later that evening and report this to Leviathan who then marks the issue as &#8220;resolved&#8221;.<\/p>\n<h3>8\/19\/19<\/h3>\n<p>I create the Slack channel and invite all the relevant members from Leviathan. My first big to-do is to send them a list of all URL endpoints for the GMass Chrome extension. Since a Chrome extension is by nature, public, the endpoints can easily be grepped from the extension&#8217;s JavaScript.<\/p>\n<h3>8\/14\/19<\/h3>\n<p>I have my external alignment phone call with Leviathan. Because I&#8217;m essentially the sole developer of GMass, it&#8217;s just me from GMass, and one rep from Leviathan. He walks me through the process, collects some contact information from me, advises me what to do if their testing causes any technical issues on my end, like downtime, and gives me a timeframe of a few weeks to get everything done. On this call, I&#8217;m told that they&#8217;ve performed &#8220;tens&#8221; of assessments so far, and that no vendor has been unable to pass yet, which sets my mind at ease. Surely though, some software companies probably opted to not even begin the process due to cost. It&#8217;s also decided on this call that I&#8217;ll set up a private Slack channel for myself and a few members from the Leviathan team to coordinate activities related to the security assessment.<\/p>\n<h3>8\/1\/19<\/h3>\n<p>I finally receive information on the &#8220;external alignment&#8221; meeting with Leviathan, which will be the first step in the security assessment.<\/p>\n<p>Within minutes I respond and request the first available time slot, which is August 14th at 1 PM PST.<\/p>\n<h3>7\/29\/19<\/h3>\n<p>It&#8217;s now been 5 days since I sent back the signed contract for Leviathan and haven&#8217;t heard anything further, so I follow up.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4382\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.15.10.png\" alt=\"\" width=\"2244\" height=\"326\" \/><\/p>\n<p>&#8230;and I hear back a few minutes later.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4383\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.15.51.png\" alt=\"\" width=\"2122\" height=\"210\" \/><\/p>\n<h3>7\/24\/19<\/h3>\n<p>After not hearing back from Leviathan, I followed up on July 23rd, and did receive this response today.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4380\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.12.11.png\" alt=\"\" width=\"2118\" height=\"214\" \/><\/p>\n<p>A few minutes later, I received the official proposal. For privacy purposes, I won&#8217;t post the proposal here, but suffice it to say, it&#8217;s a standard contract with a quote, and there&#8217;s nothing specific to the security assessment of GMass in this proposal. The effort is scoped at a 3-day effort at a particular USD rate per day.<\/p>\n<p>I sign and send the contract back on this same day.<\/p>\n<h3>7\/22\/19<\/h3>\n<p>After making some substantial security enhancements to our entire infrastructure, I reach out to Leviathan telling them that I&#8217;m ready to begin the security assessment.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4378\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.10.47.png\" alt=\"\" width=\"1746\" height=\"370\" \/><\/p>\n<h3>6\/25\/19<\/h3>\n<p>Bishop Fox updates me again with some more information, including a <strong>What to Expect<\/strong> document for the security assessment. This document doesn&#8217;t contain any sensitive information, so I&#8217;m making it available for <a href=\"http:\/\/gmass.co\/assets2017\/GP Security Assessment 2019 - What to Expect - v11.pdf\">download<\/a>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4395\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.26.31.png\" alt=\"\" width=\"2166\" height=\"1066\" \/><\/p>\n<p>I let Bishop Fox know that I&#8217;ll be reviewing the information and then letting them know if I want to proceed.<\/p>\n<h3>6\/21\/19<\/h3>\n<p>I&#8217;m told that the <strong>Self Assessment Questionnaire<\/strong> from Bishop Fox has been approved!<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4393\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.24.04.png\" alt=\"\" width=\"2140\" height=\"498\" \/><\/p>\n<h3>6\/4\/19<\/h3>\n<p>My contact at Bishop Fox updates me again on the status of the SAQ approval with Google.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4391\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.22.37.png\" alt=\"\" width=\"2158\" height=\"652\" \/><\/p>\n<p>What I find most interesting about this email is the mention of a deadline to have the security assessment <strong>scheduled<\/strong>. There&#8217;s never been any mention of this in the documentation from Google or my correspondence with the Google OAuth team.<\/p>\n<h3>5\/28\/19<\/h3>\n<p>I email Bishop Fox to ask about the approval status of the SAQ (Self Assessment Questionnaire), because it&#8217;s been a couple weeks and I haven&#8217;t heard anything. If Google approves their use of the SAQ, it\u00a0lessens my cost of the security assessment.<\/p>\n<p>My contact responds a few hours later.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4390\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-08-02-02.20.58.png\" alt=\"\" width=\"2124\" height=\"384\" \/><\/p>\n<h3>5\/16\/19 (update from Google)<\/h3>\n<p>Google sent the below email, informing me that if I don&#8217;t go through with the security assessment, I&#8217;ll lose access to the restricted scopes. It also <strong>clarifies one of the prior points of confusion<\/strong> &#8212; that if my app is to be used within G Suite domains only, then I don&#8217;t have to go through the security assessment. Meaning, <strong>if I don&#8217;t care about taking on @gmail.com users, then I don&#8217;t need to go through with the assessment<\/strong>. The email also asks for confirmation of whether I will be proceeding or not. I have replied confirming my intention to go through with the assessment.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4278\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-28-10.13.31.png\" alt=\"\" width=\"1290\" height=\"2322\" \/><\/p>\n<h3>5\/9\/19 (two quotes arrive from Bishop Fox)<\/h3>\n<p>Bishop Fox explains that they are attempting to get approval from Google to satisfy one portion of the requirements via a &#8220;Self Assessment Questionnaire&#8221; rather than a full deployment review, and policy and procedure review. Of course, I welcome the simpler approach, and I&#8217;m waiting to see if this approach is approved.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.20.12.png\" data-rel=\"lightbox-image-3\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4256 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.20.12.png\" alt=\"\" width=\"2246\" height=\"1026\" \/><\/a><\/p>\n<h3>5\/3\/19 (later that day)<\/h3>\n<p>Bishop Fox acknowledges receipt of the scoping survey.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.18.31.png\" data-rel=\"lightbox-image-4\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4254 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.18.31.png\" alt=\"\" width=\"2426\" height=\"750\" \/><\/a><\/p>\n<h3>5\/3\/19 (I respond to Bishop Fox&#8217;s scoping survey)<\/h3>\n<p>It took a while to fill out, because of the detailed questions in it.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.16.49.png\" data-rel=\"lightbox-image-5\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4252 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.16.49.png\" alt=\"\" width=\"2408\" height=\"740\" \/><\/a><\/p>\n<h3>5\/2\/19 (Proposal arrives from Leviathan)<\/h3>\n<p>I&#8217;m impressed with the speed at which Leviathan handles communication. It was just 15 minutes before I got a response to my initial inquiry, and I have a proposal the very next day after our phone call. I&#8217;ve been asked not to disclose pricing information, so out of respect for Leviathan, I won&#8217;t mention that here.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.13.57.png\" data-rel=\"lightbox-image-6\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4249 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.13.57.png\" alt=\"\" width=\"2476\" height=\"1188\" \/><\/a><\/p>\n<h3>5\/1\/19 (Call with Leviathan and follow-up)<\/h3>\n<p>I have a short phone call with a rep from Leviathan, where I describe the nature of GMass, its public facing interfaces, and a little about its underlying architecture. Given that GMass does not have an API and is only usable as a Chrome extension, the rep indicates that this will be one of their simpler security assessments and would require 2-3 days of work. After the call, he sends me some information to verify and an NDA, which I send back the next morning.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.10.06.png\" data-rel=\"lightbox-image-7\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4248 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.10.06.png\" alt=\"\" width=\"2444\" height=\"794\" \/><\/a><\/p>\n<h3>4\/29\/19 (several hours later)<\/h3>\n<p>Bishop Fox responds within several hours of my email.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.02.21.png\" data-rel=\"lightbox-image-8\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4246 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.02.21.png\" alt=\"\" width=\"2564\" height=\"1096\" \/><\/a><\/p>\n<h3>4\/29\/19 (15 minutes later)<\/h3>\n<p>Leviathan responds within 15 minutes of my email. We eventually schedule a phone call for mid-next week.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.00.39.png\" data-rel=\"lightbox-image-9\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4245 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-02.00.39.png\" alt=\"\" width=\"3382\" height=\"852\" \/><\/a><\/p>\n<h3>4\/29\/19 (later in the day)<\/h3>\n<p>I reach out to both of the security firms, Leviathan Security and Bishop Fox, that have been approved to conduct the security assessment.<br \/>\n<a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.52.12.png\" data-rel=\"lightbox-image-10\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4236 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.52.12.png\" alt=\"\" width=\"3148\" height=\"440\" \/><\/a><\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.51.52.png\" data-rel=\"lightbox-image-11\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4237 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.51.52.png\" alt=\"\" width=\"3118\" height=\"536\" \/><\/a><\/p>\n<h3>4\/29\/19 (earlier in the day)<\/h3>\n<p>Google\u00a0denies\u00a0my request\u00a0to skip the security assessment.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4242\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.56.50.png\" alt=\"\" width=\"1724\" height=\"1824\" \/><\/p>\n<h3>4\/22\/19<\/h3>\n<p>I respond to the notice asking if I can skip the security assessment if I reduce the Gmail API scopes I&#8217;m using for GMass.<\/p>\n<p><a href=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.54.36.png\" data-rel=\"lightbox-image-12\" data-rl_title=\"\" data-rl_caption=\"\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-4240 size-full\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-13-01.54.36.png\" alt=\"\" width=\"2104\" height=\"518\" \/><\/a><\/p>\n<h3>4\/20\/19<\/h3>\n<p>I receive a notice from Google that the fun is only now beginning (proceed with security assessment).<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4222\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.15.29.png\" alt=\"\" width=\"1238\" height=\"1590\" \/><br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4223\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.15.36.png\" alt=\"\" width=\"1234\" height=\"550\" \/><\/p>\n<h3>4\/1\/19<\/h3>\n<p>(April Fool&#8217;s Day &#8212; maybe they&#8217;ll let me know this has all been a joke?)<br \/>\nI&#8217;m told I&#8217;m in the final stages of verification.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4221\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.13.57.png\" alt=\"\" width=\"1410\" height=\"1458\" \/><\/p>\n<h3>3\/31\/19<\/h3>\n<p>I respond with my agreement.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4220\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.13.28.png\" alt=\"\" width=\"1826\" height=\"326\" \/><\/p>\n<h3>3\/26\/19<\/h3>\n<p>Google emails asking me to confirm my\u00a0agreement\u00a0with a statement.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4219\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.12.38.png\" alt=\"\" width=\"1384\" height=\"1390\" \/><\/p>\n<h3>3\/23\/19<\/h3>\n<p>I responded with another video.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4218\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.11.52.png\" alt=\"\" width=\"1852\" height=\"1012\" \/><\/p>\n<h3>3\/21\/19 (a few hours later)<\/h3>\n<p>I received an additional request deeming the first video as insufficient.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4217\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.09.24.png\" alt=\"\" width=\"1262\" height=\"1598\" \/><\/p>\n<h3>3\/21\/19<\/h3>\n<p>I receive this request from Google for an additional video.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4216\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.07.24.png\" alt=\"\" width=\"1414\" height=\"1382\" \/><\/p>\n<h3>3\/18\/19<\/h3>\n<p>I respond, letting Google know I&#8217;ve made the branding changes they suggested.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4215\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.06.20.png\" alt=\"\" width=\"1820\" height=\"852\" \/><\/p>\n<h3>3\/15\/19<\/h3>\n<p>After Google presumably watches my video, they respond, asking them to conform to their branding guidelines.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4214\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.05.15.png\" alt=\"\" width=\"1350\" height=\"1550\" \/><br \/>\n3\/9\/19<br \/>\nI respond with the requested YouTube video.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4213\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.04.18.png\" alt=\"\" width=\"1830\" height=\"812\" \/><\/p>\n<h3>3\/6\/19<\/h3>\n<p>Google responds with their request for a YouTube video.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4212\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.02.53.png\" alt=\"\" width=\"1278\" height=\"1594\" \/><br \/>\n2\/15\/19<br \/>\nI responded to the ambiguous request from Google.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4210\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.01.55.png\" alt=\"\" width=\"1820\" height=\"538\" \/><\/p>\n<h3>2\/15\/19<\/h3>\n<p>Received this email with no project ID listed, and given that I manage multiple apps built for Gmail, I didn&#8217;t know if this pertained to GMass or not.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4209\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-15.00.45.png\" alt=\"\" width=\"1322\" height=\"1564\" \/><\/p>\n<h3>2\/9\/19<\/h3>\n<p>I respond to Google&#8217;s request for the scope explanation.<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4208\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-14.59.09.png\" alt=\"\" width=\"1808\" height=\"1162\" \/><\/p>\n<h3>2\/7\/19<\/h3>\n<p>Email received from Google asking for an explanation of the need for the full mail.google.com scope<br \/>\n<img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4207\" src=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2019-05-01-14.57.20.png\" alt=\"\" width=\"1272\" height=\"1604\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Earlier I wrote about my feelings on Google&#8217;s new\u00a0verification process for sensitive and restricted Gmail API scopes, and here I&#8217;ll be posting live updates of GMass&#8217;s journey through\u2026<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5301],"tags":[],"class_list":["post-9205","post","type-post","status-publish","format-standard","hentry","category-google-oauth"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\r\n<title>Live Updates on the Google OAuth verification process and security audit<\/title>\r\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\r\n<link rel=\"canonical\" href=\"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/\" \/>\r\n<meta property=\"og:locale\" content=\"en_US\" \/>\r\n<meta property=\"og:type\" content=\"article\" \/>\r\n<meta property=\"og:title\" content=\"Live Updates on the Google OAuth verification process and security audit\" \/>\r\n<meta property=\"og:description\" content=\"Earlier I wrote about my feelings on Google&#8217;s new\u00a0verification process for sensitive and restricted Gmail API scopes, and here I&#8217;ll be posting live updates of GMass&#8217;s journey through\u2026\" \/>\r\n<meta property=\"og:url\" content=\"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/\" \/>\r\n<meta property=\"og:site_name\" content=\"GMass Blog\" \/>\r\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/GmailMailMerge\/\" \/>\r\n<meta property=\"article:published_time\" content=\"2019-05-13T06:50:39+00:00\" \/>\r\n<meta property=\"article:modified_time\" content=\"2020-01-26T03:56:38+00:00\" \/>\r\n<meta property=\"og:image\" content=\"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png\" \/>\r\n<meta name=\"author\" content=\"Ajay Goel\" \/>\r\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\r\n<meta name=\"twitter:creator\" content=\"@PartTimeSnob\" \/>\r\n<meta name=\"twitter:site\" content=\"@GMassForGmail\" \/>\r\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Goel\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\r\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/\"},\"author\":{\"name\":\"Ajay Goel\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"headline\":\"Live Updates on the Google OAuth verification process and security audit\",\"datePublished\":\"2019-05-13T06:50:39+00:00\",\"dateModified\":\"2020-01-26T03:56:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/\"},\"wordCount\":1875,\"commentCount\":27,\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/Screenshot-2020-01-25-22.46.29-916x1024.png\",\"articleSection\":[\"Google OAuth\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/\",\"name\":\"Live Updates on the Google OAuth verification process and security audit\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/Screenshot-2020-01-25-22.46.29-916x1024.png\",\"datePublished\":\"2019-05-13T06:50:39+00:00\",\"dateModified\":\"2020-01-26T03:56:38+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/Screenshot-2020-01-25-22.46.29-916x1024.png\",\"contentUrl\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/05\\\/Screenshot-2020-01-25-22.46.29-916x1024.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/live-updates-google-oauth-verification-security\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Live Updates on the Google OAuth verification process and security audit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/\",\"name\":\"GMass Blog\",\"description\":\"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/#\\\/schema\\\/person\\\/b5fa74f8765b860701158fd77162fff8\",\"name\":\"Ajay Goel\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g\",\"caption\":\"Ajay Goel\"},\"description\":\"Ajay is the founder of GMass and has been developing email sending software for 20 years.\",\"sameAs\":[\"https:\\\/\\\/twitter.com\\\/PartTimeSnob\",\"https:\\\/\\\/x.com\\\/PartTimeSnob\"],\"url\":\"https:\\\/\\\/www.gmass.co\\\/blog\\\/author\\\/ajay-goel\\\/\"}]}<\/script>\r\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Live Updates on the Google OAuth verification process and security audit","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/","og_locale":"en_US","og_type":"article","og_title":"Live Updates on the Google OAuth verification process and security audit","og_description":"Earlier I wrote about my feelings on Google&#8217;s new\u00a0verification process for sensitive and restricted Gmail API scopes, and here I&#8217;ll be posting live updates of GMass&#8217;s journey through\u2026","og_url":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/","og_site_name":"GMass Blog","article_publisher":"https:\/\/www.facebook.com\/GmailMailMerge\/","article_published_time":"2019-05-13T06:50:39+00:00","article_modified_time":"2020-01-26T03:56:38+00:00","og_image":[{"url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png","type":"","width":"","height":""}],"author":"Ajay Goel","twitter_card":"summary_large_image","twitter_creator":"@PartTimeSnob","twitter_site":"@GMassForGmail","twitter_misc":{"Written by":"Ajay Goel","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#article","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/"},"author":{"name":"Ajay Goel","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"headline":"Live Updates on the Google OAuth verification process and security audit","datePublished":"2019-05-13T06:50:39+00:00","dateModified":"2020-01-26T03:56:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/"},"wordCount":1875,"commentCount":27,"image":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png","articleSection":["Google OAuth"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/","url":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/","name":"Live Updates on the Google OAuth verification process and security audit","isPartOf":{"@id":"https:\/\/www.gmass.co\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#primaryimage"},"image":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#primaryimage"},"thumbnailUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png","datePublished":"2019-05-13T06:50:39+00:00","dateModified":"2020-01-26T03:56:38+00:00","author":{"@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8"},"breadcrumb":{"@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#primaryimage","url":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png","contentUrl":"https:\/\/www.gmass.co\/blog\/wp-content\/uploads\/2019\/05\/Screenshot-2020-01-25-22.46.29-916x1024.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.gmass.co\/blog\/live-updates-google-oauth-verification-security\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.gmass.co\/blog\/"},{"@type":"ListItem","position":2,"name":"Live Updates on the Google OAuth verification process and security audit"}]},{"@type":"WebSite","@id":"https:\/\/www.gmass.co\/blog\/#website","url":"https:\/\/www.gmass.co\/blog\/","name":"GMass Blog","description":"Tips and tricks for sending mail merge and mass email campaigns directly from Gmail","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.gmass.co\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.gmass.co\/blog\/#\/schema\/person\/b5fa74f8765b860701158fd77162fff8","name":"Ajay Goel","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f3a70af05bbabe47925150d5a1320540e801b78055a74da20658fc97cd0706a2?s=96&d=mm&r=g","caption":"Ajay Goel"},"description":"Ajay is the founder of GMass and has been developing email sending software for 20 years.","sameAs":["https:\/\/twitter.com\/PartTimeSnob","https:\/\/x.com\/PartTimeSnob"],"url":"https:\/\/www.gmass.co\/blog\/author\/ajay-goel\/"}]}},"_links":{"self":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9205","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/comments?post=9205"}],"version-history":[{"count":10,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9205\/revisions"}],"predecessor-version":[{"id":11028,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/posts\/9205\/revisions\/11028"}],"wp:attachment":[{"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/media?parent=9205"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/categories?post=9205"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.gmass.co\/blog\/wp-json\/wp\/v2\/tags?post=9205"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}