Skip to content

The GA4 Measurement Protocol key #21026

Description

@criticalAY

Context

The GA4 Measurement Protocol api_secret is currently sourced from local.properties (ANALYTICS_API_KEY) or the ANALYTICS_API_KEY env var, with a DUMMY_API_XXX fallback so contributor builds compile.

Question raised by @david-allison

Only an issue with the build.gradle change, and that's mostly my ignorance/wanting reassurance.

I believe in our prior implementation, the key wasn't obscured. Obscuring a publicly-facing analytics key is
semi-understandable from the perspective of not wanting malicious clients, but it's unusual to me, as it's not a > private key.

(For example, with Firebase, this would be a public credential on a website)

If you'd be OK with deferring the conversation, shift it to an issue and merge at will!
cc @mikehardy

TODO

  • Research how other OSS Android projects handle GA4 Measurement Protocol api_secret (Signal, K-9 Mail, F-Droid clients, etc.)
  • Decide: keep obscuring, publish the key, or stand up a separate dev GA4 property
  • Document the decision in the analytics package KDoc

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Fields

    Priority

    None yet

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions