【发布时间】:2017-03-08 13:35:11
【问题描述】:
我正在使用这个 github 项目https://github.com/openiddict/openiddict-core,这很棒。但是当用户使用外部身份提供者时,我不知道程序应该是什么,或者如何实现它们,在这个例子中,我将使用谷歌。
我有一个 angular2 应用程序正在运行,它带有一个 aspnet 核心 webAPI。我所有的本地登录都运行良好,我使用用户名和密码调用connect/token,并返回一个 accessToken。
现在我需要将 google 实现为外部身份提供者。我已经按照here 的所有步骤实现了一个谷歌登录按钮。这会在用户登录时打开一个弹出窗口。这是我为我的 google 按钮创建的代码。
// Angular hook that allows for interaction with elements inserted by the
// rendering of a view.
ngAfterViewInit() {
// check if the google client id is in the pages meta tags
if (document.querySelector("meta[name='google-signin-client_id']")) {
// Converts the Google login button stub to an actual button.
gapi.signin2.render(
'google-login-button',
{
"onSuccess": this.onGoogleLoginSuccess,
"scope": "profile",
"theme": "dark"
});
}
}
onGoogleLoginSuccess(loggedInUser) {
let idToken = loggedInUser.getAuthResponse().id_token;
// here i can pass the idToken up to my server and validate it
}
现在我有一个来自谷歌的 idToken。在找到here 的谷歌页面上的下一步说我需要验证谷歌 accessToken,我可以这样做,但是如何交换我从谷歌获得的 accessToken,并创建可以在我的应用程序上使用的本地 accessToken ?
【问题讨论】:
-
只是我想知道为什么您需要谷歌客户端库来获取 id 令牌,您是否考虑过使用像 github.com/openiddict/openiddict-core/blob/dev/samples/… 这样的谷歌身份验证?
-
只是因为我有一个客户端应用程序,并且我需要 accessToken 客户端才能让我的应用程序工作,因为我将它存储在客户端的 localStorage 中。我确实尝试过使用该方法,但是我不知道如何将令牌交换为客户端令牌??
标签: c# oauth asp.net-core openid openiddict