skydoves / chatgpt-android

📲 ChatGPT Android demonstrates a Chatbot application using OpenAI's chat API on Android with Stream Chat SDK for Compose.
Apache License 2.0
3.74k stars 439 forks source link

Phishing-style OAuth prompt for Google login #170

Closed gaemyrtagh closed 8 months ago

gaemyrtagh commented 1 year ago

Logging in through Google, a seemingly Google-branded prompt asking for an email or phone number with a blank field and a next button appears, followed by what appears to be a legitimate Google Sign In page.

This intermediate page does not appear on while logging into chat.openai.com. The page in question appears to accept any random string and can be left empty. I'm unsure if this is an expected feature but as someone testing out this project for the first time, I find it very alarming.

Please let me know if I'm understanding this wrong. I don't mean to wrongly accuse anyone of malice.

CollinsU99 commented 1 year ago

I noticed that too, looks phishing to me

skydoves commented 1 year ago

Would you provide any screenshots of the page? I can see only this login page when I come to the Google login. I'm not sure how it works like that, feels like the Google intermediate page shows up in the way of bypassing the Cloudflare, which is used by official ChatGPT, OpenAI.

KakaoTalk_Photo_2023-06-21-19-36-21

gaemyrtagh commented 1 year ago

Here's a screen recording of the issue. I'm sure there's a logical explanation for this. https://github.com/skydoves/chatgpt-android/assets/13422666/406663e6-982c-4bff-bc5c-dc2a2501ec91

skydoves commented 8 months ago

Hello everyone, I'm excited to announce that this repository has now migrated to utilize OpenAI's official chat API. Please refer to the new guidelines for instructions on running this project. Thank you for your attention!