skydoves / chatgpt-android

📲 ChatGPT Android demonstrates a Chatbot application using OpenAI's chat API on Android with Stream Chat SDK for Compose.

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Phishing-style OAuth prompt for Google login

gaemyrtagh opened this issue · comments

commented

Logging in through Google, a seemingly Google-branded prompt asking for an email or phone number with a blank field and a next button appears, followed by what appears to be a legitimate Google Sign In page.

This intermediate page does not appear on while logging into chat.openai.com. The page in question appears to accept any random string and can be left empty. I'm unsure if this is an expected feature but as someone testing out this project for the first time, I find it very alarming.

Please let me know if I'm understanding this wrong. I don't mean to wrongly accuse anyone of malice.

I noticed that too, looks phishing to me

Would you provide any screenshots of the page? I can see only this login page when I come to the Google login. I'm not sure how it works like that, feels like the Google intermediate page shows up in the way of bypassing the Cloudflare, which is used by official ChatGPT, OpenAI.

KakaoTalk_Photo_2023-06-21-19-36-21

commented

Here's a screen recording of the issue. I'm sure there's a logical explanation for this.
https://github.com/skydoves/chatgpt-android/assets/13422666/406663e6-982c-4bff-bc5c-dc2a2501ec91