I've built an app for Glass and I've noticed that Google accounts without the actual Glass device (I personally know those users) are perfectly able to complete the OAuth2 process including the Glass scopes (https://www.googleapis.com/auth/glass.timeline
and https://www.googleapis.com/auth/glass.location
)
It seems unexpected and somehow problematic as those are users who might be consuming resources of the app, may expect some functionality our if it, but they can't get any services in return.