【发布时间】:2021-08-17 17:36:12
【问题描述】:
我正在使用 ionic 创建一个应用程序。我使用谷歌身份验证,使用网络上的说明 (https://www.pragma.com.co/academia/lecciones/como-implementar-un-login-de-google-con-ionic)。 一切正常,我按照 Google (https://developers.google.com/identity/sign-in/web/backend-auth) 的建议获取并验证了 JWT。
我的问题是,在进行身份验证后,我需要向我的后端发出 get/post 请求。保证请愿书真实性的最有效方法是什么? 在每个请求上发送 JWT 并验证它?我认为这不是很有效且不安全。
提交 access_token 并使用https://www.googleapis.com/oauth2/v1/tokeninfo?access_token=
【问题讨论】:
标签: angular security google-authentication ionic5 integrity