How to authorize google-api-php-client with a slim 3 Rest API?

Viewed 1662

I'm trying to create a web-based email client which gets all email data from google mail API. I'm using Slim3 for creating a restful API interface. To access google APIs, I'm using Google-API-PHP-Client (Google does have a rest API access and I really like it but I still haven't figured out how the authorization would work without using the PHP-client-library).

My main problem is how do I structure authentication part of it as google uses Oauth2 for login which gives a code. I can use a simple token based auth in Slim but then how do I achieve the following:

  1. Authentication/Authorization with google.
  2. Identifying new vs returning users.
  3. Maintaining & Retaining both access and refresh tokens from google and local APIs
  4. Since the API will be used on both mobile clients and web-browser, I can't use PHP's default sessions - I'm relying on database driven custom tokens.

How do I structure the APIs?

One way was to use google's token as the only token in the app - but it keeps changing every hour so How do I identify the user from token - calling google API for every incoming call doesn't seem like a graceful solution.

Any leads/links would be really helpful.

Thanks in advance

1 Answers
Related