The OAuth keys for Google are defined in EDS itself (src/modules/ubuntu-
online-accounts/google-*.service.in.in). They were registered by me, but
I gave access to them to the EDS developers themselves (though I suspect
that it was still at the time when Matthew Barnes was the lead developer
- I'm not sure Milan has access).

Anyway, I just checked the stats and I've verified that we are well
below the maximum quota, with no errors reported, for the last 30 days.
So I believe that we are fine there, and that we don't need to act on
this.

I'll leave this bug in incomplete state; if new data emerges that
convinces us that we indeed have a problem, we'll address it.

** Package changed: account-plugins (Ubuntu) => evolution-data-server
(Ubuntu)

** Changed in: evolution-data-server (Ubuntu)
       Status: New => Incomplete

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to evolution-data-server in
Ubuntu.
https://bugs.launchpad.net/bugs/1650007

Title:
  Consider changing Google API key

Status in evolution-data-server package in Ubuntu:
  Incomplete

Bug description:
  evolution-data-server (e-d-s) 3.20 before 3.20.6 and 3.22 before
  3.22.2 had bugs that caused users using Google services to experience
  daily limit timeouts and authentication errors. Unfortunately, users
  using older versions are causing those problems for everyone that
  still uses the affected API key. Therefore GNOME is updating the API
  key used by GNOME Online Accounts. For more info, see LP: #1649995 and
  https://bugzilla.gnome.org/774202

  - I don't know yet if e-d-s before 3.20 is also affected. I asked but
  you're welcome to ask the Evolution devs yourself.
  https://bugzilla.gnome.org/show_bug.cgi?id=771547#c61

  - Upstream evolution has two ways to configure a Google account: GNOME
  Online Accounts and e-d-s. I assume Ubuntu Online Accounts is a 3rd
  way. (I think e-d-s will need to switch to a new Google API key too
  but that hasn't happened yet.)

  - For Ubuntu 16.10, we need the latest evolution-data-server SRU (LP:
  #1639926) to be pushed to yakkety-updates and fully 100% phased before
  publishing the new key.

  - Therefore, assuming Ubuntu Online Accounts is affected, I suggest
  you consider changing the Google API key used in Ubuntu 16.10 and
  above. Once we figure out if e-d-s needs to be updated for 16.04 (and
  possibly earlier releases), I believe we'll need to update the key
  there too.

  - On the other hand, since we control Ubuntu updates (unlike GNOME
  which has not control over who uses what version of their stuff) maybe
  we don't need to change the key after all. Maybe we just need to push
  the e-d-s SRUs as security updates to ensure people use the fixed
  versions?

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/evolution-data-server/+bug/1650007/+subscriptions

-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to