How to exchange Google one-time authorization code for a refresh token without callback (intranet)?

Viewed 1533

I'm working on a intranet-based application and I want to use Google services. Currently I have successfully implemented Google Authentication with "Sign-In for Websites" using JavaScript client-side authentication. My users can now sign in or sign up with their Google accounts.

Now I want to use Google API to create and share Google Sheets with my users. These documents will be created with a specific Google account and then shared with my users.

This is why I want to use this server-slide flow to get a one-time authorization code and exchange it for a refresh token: https://developers.google.com/identity/sign-in/web/server-side-flow

Google hybrid Server-side flow

This refresh token will be stored in my database allowing me to user Google services on behalf of this offline user.

Using JavaScript library, I was able to get the one-time authorization code that I send to my server with a AJAX request.

auth2.grantOfflineAccess({'redirect_uri': 'postmessage'}).then(grantOfflineAccessCallback);

var grantOfflineAccessCallback = function(authResult) {
    var auth_code = authResult.code;

    // Exchange the one-time authorization code for tokens
    $.post(...);
}

On server-side I use Google API PHP Client (v2.0.0-RC6) to acquire an access and refresh token.

$this->client = new Google_Client();
$this->client->setClientId($this->clientId);
$this->client->setClientSecret($this->clientSecret);
$this->client->setAccessType('offline');
$this->client->setApprovalPrompt('force');

$response = $this->client->fetchAccessTokenWithAuthCode($oneTimeCode);

I wasn't able to exchange the authorization code.

Client error: `POST https://www.googleapis.com/oauth2/v4/token` resulted in a `400 Bad Request` response:
{
 "error": "invalid_request",
 "error_description": "Missing parameter: redirect_uri"
}

On this page we can read:

On the server, exchange the auth code for access and refresh tokens. Use the access token to call Google APIs on behalf of the user.

On the JAVA example code:

REDIRECT_URI: // Specify the same redirect URI that you use with your web
              // app. If you don't have a web version of your app, you can
              // specify an empty string.

Because the application I working on is an intranet application, I tried to specify an empty string for this redirect_uri parameter before calling fetchAccessTokenWithAuthCode() method:

$this->client->setRedirectUri('');

... result in Redirect URI must be absolute.

Can we use this hybrid server-slide flow without callback URL?

Is there any solution to my problem?

Thanks,


Edit:

redirect_uri is where the user will be redirected to after he signed in. This URL must be registered in the Google Project (developers console). So redirect_uri is NOT the callback...!

Problem is now solved with:

$this->client->setRedirectUri('http://same.url.as.in.developers.console/');
0 Answers
Related