【问题标题】:No email or email_verified claim in Google ID tokenGoogle ID 令牌中没有 email 或 email_verified 声明
【发布时间】:2020-10-13 02:21:54
【问题描述】:
我们的应用允许用户使用 Google 帐户登录并使用 Google API 客户端库进行 ID 令牌验证。
根据Google doc,当范围包括email 范围值时,email 声明应该包含在 ID 令牌负载中。
但是,我注意到在某些情况下,尽管包含 email 范围值,但 ID 令牌负载中缺少 email 或 email_verifiedclaim。
为什么会这样?我想 Google 帐户的个人资料上总是有一个经过验证的电子邮件地址。
【问题讨论】:
标签:
google-oauth
google-openidconnect
【解决方案1】:
几年前我就这个问题问过团队。他们不保证每次通话都会提出索赔。
解决方法是
如果您向 userinfoendpoint 发出请求
GET /oauth2/v2/userinfo HTTP/1.1
Host: www.googleapis.com
Content-length: 0
Authorization: Bearer [accessToken]
回应
{
"picture": "https://lh3.googleusercontent.com/a-/AOh14GhroCYJp2P9xeYeYk1npchBPK-zbtTxzNQo0WAHI20",
"verified_email": true,
"id": "11720047553267277534",
"email": "xxxxxxx@gmail.com"
}
假设您已经请求了电子邮件范围 email 并且 verify_email 每次都会返回。
【解决方案2】:
GET /oauth2/v2/userinfo HTTP/1.1
Host: www.googleapis.com
Content-length: 0
Authorization: Bearer [accessToken]
{
"picture": "https://lh3.googleusercontent.com/a-/AOh14GhroCYJp2P9xeYeYk1npchBPK-zbtTxzNQo0WAHI20",
"verified_email": true,
"id": "11720047553267277534",
"email": "xxxxxxx@gmail.com"
}