OpenID Connect - Authorization Code Flow with new Google Identity JS API

Viewed 265

I'm trying to understand how to implement OpenId Connect Authorization Code Flow (which is the most secure) when using newest Google Identity JS Library. I was able to succeed with legacy Google Sign-In JS library (as per Google Sign-In for server side apps), by using auth2.grantOfflineAccess() which was ultimately providing the required authorization code as per OIDC specs. Now with latest Google Identity library, I cannot find how to support the equivalent OIDC Authorization Code Flow. According to Migrating from Google Sign-In the grantOfflineAccess() JS method has been removed, but don't see how ID Token can replace the orignal authorization code for corresponding OIDC Authorization Code Flow. I hope I might be missing something.

1 Answers

You were not missing anything, but rightly noticed the authorization code flow was as of yet unavailable. After this question was asked, Google Identity Services (GIS) JavaScript SDK support to request an authorization code from Google was released.

To implement the OIDC auth code flow, follow the GIS auth code guide to fulfill steps 1, 2, and 3 of the OIDC guide, this performs the authorization code request from the user-agent and server response. Start at step 4 in the OIDC guide to exchange the verified code for tokens.

Using popup mode during the auth code request is recommended, in part to help minimize risk of future issues due to user-agent security changes, such as link-decoration.

Related