使用Google PHP API库获取用户详情时遭遇403错误求助
Google_Client验证ID Token时出现403禁止访问/oauth2/v3/certs错误
我通过new Google_Client(['client_id' => $CLIENT_ID])创建Google_Client对象,尝试获取用户详情时出错。原本想获取指定Gmail账号的$googleUserid、$email、$picture等用户信息,结果收到无法获取验证证书的错误,访问/oauth2/v3/certs时遭403禁止。
使用的代码:
require '/home/nowvibac/vendor/autoload.php'; try{ $CLIENT_ID = '204553466403-o75aj25ktmmjkk1g5a3set3losqvfeqe.apps.googleusercontent.com'; $client = new Google_Client(['client_id' => $CLIENT_ID]); // Specify the CLIENT_ID of the app that accesses the backend $payload = $client->verifyIdToken($id_token); if ($payload) { /*Own-- this id is the same as the one in js but its more authentic to avoid user manipulation */ //verified variables from Google's API $googleUserid = $payload['sub']; $email = $payload['email']; $picture = $payload['picture']; $name = $payload['name']; } }catch(Exception $e){ echo $e; }
错误信息:
Failed to retrieve verification certificates: "<!DOCTYPE html> <html lang=en> <meta charset=utf-8> <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width"> <title>Error 403 (Forbidden)!!1</title> <style> *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat;-webkit-background-size:100% 100%}}#logo{display:inline-block;height:54px;width:150px} </style> <a href=//www.google.com/><span id=logo aria-label=Google></span></a> <p><b>403.</b> <ins>That’s an error.</ins> <p>Your client does not have permission to get URL <code>/oauth2/v3/certs</code> from this server. <ins>That’s all we know.</ins>
解决方法:
- 排查服务器网络:403大概率是服务器无法正常访问Google认证端点,可能是IP被限制、防火墙拦截或代理配置问题。直接在服务器上执行
curl https://www.googleapis.com/oauth2/v3/certs,看能否返回正常的证书内容。 - 更新Google Client库:旧版本库可能存在端点URL配置错误,运行
composer update google/apiclient升级到最新版,新版本会使用正确的证书获取地址。 - 完善Client初始化配置:别只传client_id,建议完整配置客户端参数,比如:
$client = new Google_Client(); $client->setClientId($CLIENT_ID); $client->setAccessType('offline');
- 验证ID Token有效性:确保前端传过来的
$id_token是合法有效的,没有过期或被篡改,可手动检查Token格式是否符合JWT标准。
内容的提问来源于stack exchange,提问作者Muhwezi Deus
相关产品推荐
相关产品推荐

