You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Flutter/Dart中Google Identity Platform OIDC认证配置故障求助

Google Identity Platform OIDC认证配置问题排查

问题回顾

我之前配置过OAuth2认证,现在要在Google Identity Platform里配置OIDC认证,总觉得漏了基础配置导致跑不起来。已经完成提供商配置,指定重定向URL为https://my-fancy-project.firebaseapp.com/__/auth/handler,Issuer对应的.well-known/openid-configuration也存在。沙箱环境里创建了OAuth2应用,拿到ClientId(12345-67890-abcdef-ghijklm),并且把应用的重定向URL设成了上面的地址。

Flutter代码实现:

Future<void> request(Uri fhirCallback) async {
  await Firebase.initializeApp(options: DefaultFirebaseOptions.currentPlatform);
  firebaseAuth.FirebaseAuth auth = firebaseAuth.FirebaseAuth.instance;
  final provider = firebaseAuth.OAuthProvider('oidc.brand-new-auth');
  // provider.setScopes(['openid', 'profile', 'fhirUser']);
  final res1 = await auth.signInWithPopup(provider);
}

Implicit Flow (id_token) 模式错误

调用后弹出窗口短暂关闭,返回400错误:

POST https://identitytoolkit.googleapis.com/v1/accounts:signInWithIdp?key=alphanumeric-string 400

[firebase_auth/invalid-credential] Error getting verification code from oidc.brand-new-auth 
response: error=unsupported_response_type&state=another-string_of-alphanumeric-characters-here

Code Flow模式错误

改用Code Flow并填入应用密钥后,返回:

[firebase_auth/invalid-credential] The supplied auth credential is malformed or has expired.

问题排查与修复方案

针对unsupported_response_type错误(Implicit Flow)

  1. 验证提供商支持的响应类型
    查看提供商的.well-known/openid-configuration中的response_types_supported字段,确认是否包含id_token。如果提供商不支持Implicit Flow,就会返回这个错误,此时必须切换到Code Flow。

  2. 启用OIDC必填Scope
    取消代码中setScopes的注释,OIDC认证必须包含openid scope,缺少该Scope会导致请求不符合OIDC规范,触发提供商的响应类型不支持错误:

    provider.setScopes(['openid', 'profile', 'fhirUser']);
    
  3. 确认Google Identity Platform流程配置
    在Google Identity Platform的OIDC提供商设置中,确认选择的流程和提供商支持的一致。如果选了Implicit Flow,必须确保提供商明确支持该模式。

针对Code Flow的凭证错误

  1. 检查Client Secret配置
    确认在Google Identity Platform的OIDC提供商设置中,填入的Client Secret和沙箱OAuth2应用生成的完全一致,注意区分大小写和特殊字符。

  2. 确认提供商开启Code Flow
    部分OIDC提供商需要手动开启Authorization Code Flow模式,检查沙箱应用的设置,确保该流程已启用。

  3. 校验重定向URL一致性
    确保Google Identity Platform和沙箱OAuth2应用中的重定向URL完全匹配,包括是否有结尾斜杠、大小写等细节,任何差异都会导致凭证验证失败。

  4. 查看详细错误日志
    在Google Cloud Console的Identity Platform日志中查看具体的错误详情,日志会给出更明确的失败原因(比如授权码无效、签名验证失败等)。

通用检查项

  • Issuer URL匹配:确认Google Identity Platform中配置的Issuer URL和提供商.well-known/openid-configuration里的issuer字段完全一致,不能有多余的路径或参数。
  • Firebase版本兼容:检查firebase_auth_web插件版本是否与Firebase SDK版本匹配,版本不兼容可能导致认证流程异常。
  • API密钥有效性:确认Firebase项目的API密钥是否正确,且未被限制使用权限。

内容的提问来源于stack exchange,提问作者Grey

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 04:10:26