You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

FastAPI中如何用Authlib实现Google OAuth2的PKCE流程

在FastAPI中通过Authlib为Google OAuth2启用PKCE的最佳实践

核心结论

不需要手动生成和存储code_verifier,只要在authorize_redirect中指定code_challenge_method="S256",Authlib会自动完成PKCE流程的所有细节。

为什么不需要手动处理?

当你调用oauth.google.authorize_redirect并传入code_challenge_method参数时,Authlib内部会自动执行以下操作:

  • 生成符合RFC 7636规范的code_verifier(长度在43-128字符之间的随机字符串)
  • 使用指定的S256方法生成对应的code_challenge
  • 将code_verifier自动存储到当前请求的session中

在回调函数里调用await oauth.google.authorize_access_token(request)时,Authlib会自动从session中取出之前存储的code_verifier,和Google返回的授权码一起完成PKCE验证流程,完全不需要你手动干预。

代码对比与推荐

推荐写法(简洁且正确)

@auth_router.get("/login/google")
async def login_google(request: Request):
    redirect_uri = FASTAPI_BACKEND_URL + "/auth/"
    return await oauth.google.authorize_redirect(
        request, 
        redirect_uri,
        code_challenge_method="S256"
    )

冗余的手动写法(不推荐)

手动生成code_verifier并传入的做法是多余的,甚至可能因为生成的字符串不符合规范(比如长度不对),或者session存储逻辑出错,导致PKCE验证失败。

回调函数的正确性

你当前的回调代码完全没问题:

@auth_router.get("/auth")
async def auth_google_callback(request: Request, db: AsyncDB):
    logger.info(request.session)
    try:
        token = await oauth.google.authorize_access_token(request)
    except OAuthError as e:
        logger.error("Unable to get access token")
        return RedirectResponse(url='/')

authorize_access_token方法会自动处理PKCE的验证步骤,不需要额外添加任何代码。

注意事项

  • 确保你的FastAPI应用已经正确配置了SessionMiddleware,因为Authlib依赖session来存储code_verifier
  • Google OAuth2对PKCE的支持是原生的,只要你的应用是公共客户端(无客户端密钥),PKCE会被自动启用,无需在Google Cloud控制台额外配置

内容的提问来源于stack exchange,提问作者Enrico Shippole

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 01:27:10