You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

网站集成Google登录功能时无法正常连接的问题求助

网站集成Google登录功能时无法正常连接的问题求助

我正在尝试在我的网站上实现Google登录功能,按照官方指南一步步操作的:

  • 第一步:创建了凭证
  • 第二步:将Google平台库代码放在head标签末尾
  • 第三步:紧接着配置了应用的客户端ID(用第一步获取到的ID替换了示例内容)
  • 第四步:在页面上添加了官方提供的测试按钮代码:<div class="g-signin2" data-onsuccess="onSignIn"></div>

但现在打开浏览器加载页面时,控制台出现了以下错误(我把错误里的域名和客户端ID替换成了占位符):

[Report Only] Refused to load the script 'https://www.gstatic.com/_/mss/boq-identity/_/js/k=boq-identity.IdpIFrameHttp.sv.IwDkfwbeEEg.es5.O/am=DAY/d=1/rs=AOaEmlEdZyiJuV_FbDciB-VB31grkH9-LA/m=base' because it violates the following Content Security Policy directive: "script-src 'unsafe-inline' 'unsafe-eval' blob: data:". Note that 'script-src-elem' was not explicitly set, so 'script-src' is used as a fallback.

cb=gapi.loaded_0?le=scs:115  Uncaught {error: 'idpiframe_initialization_failed', details: "Not a valid origin for the client: https://recensi…egister this origin for your project's client ID."}details: "Not a valid origin for the client: https://mywebsite.com has not been registered for client ID xxxxxx.apps.googleusercontent.com. Please go to https://console.developers.google.com/ and register this origin for your project's client ID."error: "idpiframe_initialization_failed"[[Prototype]]: Object
(anonymous) @ cb=gapi.loaded_0?le=scs:115
setTimeout
_.nh @ cb=gapi.loaded_0?le=scs:115
(anonymous) @ cb=gapi.loaded_0?le=scs:155
Wj @ cb=gapi.loaded_0?le=scs:146
Promise.then
gk @ cb=gapi.loaded_0?le=scs:148
_.ik @ cb=gapi.loaded_0?le=scs:148
Ak @ cb=gapi.loaded_0?le=scs:154
jk @ cb=gapi.loaded_0?le=scs:153
(anonymous) @ cb=gapi.loaded_0?le=scs:148
(anonymous) @ cb=gapi.loaded_0?le=scs:252
xu.dispatchEvent @ cb=gapi.loaded_0?le=scs:167
_.yv.Nr @ cb=gapi.loaded_0?le=scs:206
(anonymous) @ cb=gapi.loaded_0?le=scs:199
_.g.iea @ cb=gapi.loaded_0?le=scs:191
(anonymous) @ cb=gapi.loaded_0?le=scs:194
iframe:1 

POST https://accounts.google.com/_/IdpIFrameHttp/cspreport/fine-allowlist 400 (Bad Request)

我已经尝试过的解决方法

  1. 我尝试更新了.htaccess文件,添加了以下配置,但错误还是一样:
<IfModule mod_headers.c>
Header set Content-Security-Policy "
    default-src 'self';
    script-src 'self' https://apis.google.com https://www.gstatic.com 'unsafe-inline' 'unsafe-eval' blob: data:;
    connect-src 'self' https://accounts.google.com;
    frame-src 'self' https://accounts.google.com https://www.gstatic.com;
    object-src 'none';
"
</IfModule>
  1. 我还为我的测试网站(已经部署到公网)添加了授权JavaScript来源,但情况也没有任何改善。

我的问题

有没有大佬能告诉我该怎么解决这个问题?是需要服务商那边调整什么设置,还是我自己哪里漏了步骤?

备注:内容来源于stack exchange,提问作者eligolf

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.14 18:29:35