You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Google OAuth2的登录令牌生成及AngularJS前后端验证实现

嘿,我看你已经搭建了AngularJS前端通过Gmail登录、把Google OAuth2令牌传给Django后端验证的流程,我来帮你把这段验证代码梳理清楚,再给点实用的优化和注意事项:

后端核心验证逻辑整理

你提供的代码应该是截断了,我先补全并整理成可运行的完整版本:

from django.views.decorators.csrf import csrf_exempt
from django.http import JsonResponse
import json
import requests
from google.oauth2 import id_token

@csrf_exempt 
def check(request):
    # 替换成你在Google Cloud Console中创建的OAuth客户端ID
    CLIENT_ID = 'xxxxx'  
    try:
        # 解析前端POST过来的JSON数据
        json_data = json.loads(request.body.decode('utf-8'))
        # 调用Google官方库验证令牌合法性
        idinfo = id_token.verify_oauth2_token(
            json_data['google_token'], 
            requests.Request(), 
            CLIENT_ID
        )
        
        # 额外校验令牌签发者,确保来自Google官方
        if idinfo['iss'] not in ['accounts.google.com', 'https://accounts.google.com']:
            raise ValueError('Wrong issuer.')
            
        # 验证通过后,提取用户核心信息
        user_details = {
            'google_id': idinfo.get('sub'),  # Google用户唯一ID
            'email': idinfo.get('email'),
            'name': idinfo.get('name'),
            'avatar': idinfo.get('picture')
        }
        print("验证通过的用户信息:", user_details)
        
        # 这里可以添加业务逻辑:比如创建/关联本地用户、返回登录态等
        return JsonResponse({
            'status': 'success',
            'data': user_details
        })
        
    except ValueError as e:
        # 令牌验证失败(无效、过期、受众不匹配等)
        return JsonResponse({
            'status': 'error',
            'message': f"令牌验证失败: {str(e)}"
        }, status=400)
    except json.JSONDecodeError:
        # 前端传来的JSON格式错误
        return JsonResponse({
            'status': 'error',
            'message': '无效的JSON请求格式'
        }, status=400)
    except KeyError:
        # 请求中缺少google_token字段
        return JsonResponse({
            'status': 'error',
            'message': '请求缺少google_token参数'
        }, status=400)

关键细节说明

  • @csrf_exempt:因为前端是AngularJS(通常是异步JSON提交),所以暂时禁用了CSRF校验,但如果是同域部署,建议通过AngularJS的$http传递CSRF令牌来提升安全性,避免CSRF攻击。
  • 官方验证库:用google.oauth2.id_token来验证是最安全的,它会自动处理签名验证、令牌过期检查、受众(aud)匹配(确保令牌是发给你的CLIENT_ID的),不用自己手动写这些复杂逻辑。
  • 签发者校验:额外检查iss字段是为了防止伪造的令牌,确保确实来自Google的认证服务。

常见踩坑提示

  1. CLIENT_ID必须一致:后端的CLIENT_ID要和前端AngularJS中使用的Google OAuth客户端ID完全一致,否则会直接验证失败。
  2. 令牌有效期:Google ID令牌的有效期只有1小时,前端需要在令牌过期前通过Google的刷新令牌机制获取新的ID令牌,或者提示用户重新登录。
  3. 跨域问题:如果前端和后端是不同域名,记得在Django中配置CORS允许前端域名的请求,推荐用django-cors-headers库来快速配置。
  4. 用户邮箱验证:如果需要确保用户邮箱是已验证的,可以检查idinfo.get('email_verified')字段是否为True。

内容的提问来源于stack exchange,提问作者Nnnn

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:10:35