Tools, FAQ, Tutorials:
Validate Google OpenID Connect id_token
How to validate the id_token value received from Google OpenID Connect authentication response?
✍: FYIcenter.com
As you can see from the previous tutorials, you can easily decode the
"id_token" value received from Google OpenID Connect authentication response using a
simple PHP script.
After decoding, you can get all information about the end user from the body component, and trust it without any validation.
But, since the "id_token" is included in the authentication response delivered over the public Internet, you should not trust it and perform a number validation steps:
1. Data structure validation.
2. Data attributes validation.
3. Timestamp attributes validation. This will prevent someone to repost the authentication response to your server script at a later time.
4. "nonce" protection and validation. This will prevent someone to repost the authentication response again immediately.
5. Signature validation. This is to ensure the entire authentication response message has not been modified by someone else. See next tutorial on how to perform "id_token" signature validation.
⇒ Validate Google OpenID Connect id_token Signature
⇐ Decode Google OpenID Connect id_token
2022-02-04, ∼2292🔥, 0💬
Popular Posts:
How to add images to my EPUB books Images can be added into book content using the XHTML "img" eleme...
How To Pad an Array with the Same Value Multiple Times in PHP? If you want to add the same value mul...
How to use "link" command tool to link objet files? If you have object files previously compiled by ...
Why I am getting "The Windows SDK version 8.1 was not found" error, when building my C++ application...
How to troubleshoot the Orderer peer? The Docker container terminated by itself. You can follow this...