使用Google登录时未在Cookie头中收到g_csrf_token
我正在开发一个需要Google登录的应用,前端运行在http://localhost:3000,后端运行在http://localhost:8000。目前前端已实现One-Tap和登录按钮组件,代码如下:
/* |-------------------------------------------------------------------------- | SIGN-IN WITH GOOGLE BUTTON |-------------------------------------------------------------------------- */ export const SignInWithGoogle = () => { return ( <> <div id="g_id_onload" data-client_id="205349973317-s5h03qvn3hlnjhoe52nu66aso811nlml.apps.googleusercontent.com" data-context="use" data-ux_mode="popup" data-login_uri="https://65ab-80-14-235-204.ngrok-free.app/auth/webhook/google-sign-in" data-itp_support="true" /> <div class="g_id_signin" data-type="standard" data-shape="rectangular" data-theme="filled_black" data-text="continue_with" data-size="large" data-logo_alignment="left" /> </> ); };
开发环境中我用ngrok将Google的HTTP请求转发到本地后端。当通过前端按钮或OneTap完成Google登录时,Google会向data-login_uri指定的URL发送POST请求,请求体内容是正确的:
{ credential: string, g_csrf_token: string }
但请求中缺少Cookie头——g_csrf_token Cookie不存在,导致我无法验证请求体中的g_csrf_token。我已通过ngrok的本地界面查看过Google发送的原始请求,确认请求头里确实没有Cookie。
内容的提问来源于stack exchange,提问作者Alexandre Schaffner
相关产品推荐
相关产品推荐

