You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何让Laravel识别Angular已登录用户以完成Google Calendar授权?

问题解决思路

核心结论

  • Laravel 无法直接访问前端的localStorage,这是浏览器端的私有存储,后端服务无法直接读取前端客户端的存储内容。

你的方案可行性分析

你提到的「前端触发时后端生成临时token,带token跳转Laravel完成服务端登录再跳Google」的思路是可行的,以下是具体实现步骤:

步骤1:前端发起获取临时token请求

当用户在Angular前端点击「添加Google Calendar权限」按钮时,先向后端Laravel发起请求(携带当前用户的Passport访问令牌),后端验证令牌有效性后,生成一个绑定当前用户ID、有效期5分钟左右的临时授权token,返回给前端。

示例后端代码(Laravel控制器):

public function generateTempAuthToken(Request $request)
{
    // 验证Passport令牌对应的用户
    $user = $request->user();
    if (!$user) {
        return response()->json(['error' => 'Unauthorized'], 401);
    }

    // 生成加密的临时token,包含用户ID和过期时间
    $tempToken = encrypt([
        'user_id' => $user->id,
        'expires_at' => now()->addMinutes(5)->timestamp
    ]);

    return response()->json(['temp_token' => $tempToken]);
}

步骤2:前端跳转至Laravel中转路由

前端拿到临时token后,跳转至Laravel的中转路由,示例地址:/google-calendar/redirect?temp_token={tempToken}

步骤3:Laravel中转路由验证token并完成登录

在Laravel的中转路由中,验证临时token的有效性和过期时间,通过后使用Auth::loginUsingId($userId)完成服务端会话登录,再生成Google授权链接并跳转至Google授权页面。

示例后端代码:

use Illuminate\Contracts\Encryption\DecryptException;

public function redirectToGoogle(Request $request)
{
    $tempToken = $request->get('temp_token');
    try {
        $data = decrypt($tempToken);
        // 检查token是否过期
        if ($data['expires_at'] < now()->timestamp) {
            return redirect()->to(config('app.frontend_url') . '/error')->with('error', '临时授权已过期');
        }

        // 登录用户到服务端会话
        Auth::loginUsingId($data['user_id']);

        // 生成Google授权链接(需提前配置Google API客户端)
        $client = new Google_Client();
        $client->setAuthConfig(config('services.google'));
        $client->addScope(Google_Service_Calendar::CALENDAR);
        $client->setRedirectUri(config('services.google.callback_url'));
        $authUrl = $client->createAuthUrl();

        return redirect()->away($authUrl);
    } catch (DecryptException $e) {
        return redirect()->to(config('app.frontend_url') . '/error')->with('error', '无效的临时授权');
    }
}

步骤4:Google回调Laravel并关联用户

Google授权完成后,回调到Laravel的指定URL,此时Laravel通过服务端会话可直接获取当前用户,处理授权码、获取Google Calendar令牌并关联到用户即可。

示例后端代码:

public function handleGoogleCallback(Request $request)
{
    $user = Auth::user();
    if (!$user) {
        return redirect()->to(config('app.frontend_url') . '/login')->with('error', '请先登录');
    }

    $client = new Google_Client();
    $client->setAuthConfig(config('services.google'));
    $client->addScope(Google_Service_Calendar::CALENDAR);
    $client->setRedirectUri(config('services.google.callback_url'));

    $token = $client->fetchAccessTokenWithAuthCode($request->get('code'));
    // 将Google令牌存储到用户关联数据中
    $user->googleCalendarToken()->create([
        'access_token' => $token['access_token'],
        'refresh_token' => $token['refresh_token'],
        'expires_at' => now()->addSeconds($token['expires_in'])
    ]);

    // 跳转回前端应用的关联页面
    return redirect()->to(config('app.frontend_url') . '/calendar/connected');
}

优化建议

  • 可以用Laravel的签名路由替代自定义临时token,通过URL::signedRoute()生成带签名的跳转链接,后端验证签名有效性,无需手动处理加密解密,安全性更高。
  • 确保Google回调URL已在Google Cloud控制台中正确配置,且属于Laravel应用的域名。

内容的提问来源于stack exchange,提问作者B.T

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.07 18:45:33