@Beta public class GoogleIdTokenVerifier extends IdTokenVerifier
Beta Call IdTokenVerifier.verify(IdToken) to verify a ID token. Use the constructor GoogleIdTokenVerifier(HttpTransport, JsonFactory) for the typical simpler case if your
application has only a single instance of GoogleIdTokenVerifier. Otherwise, ideally you
should use GoogleIdTokenVerifier(GooglePublicKeysManager) with a shared global instance
of the GooglePublicKeysManager since that way the Google public keys are cached. Sample
usage:
GoogleIdTokenVerifier verifier = new GoogleIdTokenVerifier.Builder(transport, jsonFactory)
.setAudience(Arrays.asList("myClientId"))
.build();
...
if (!verifier.verify(googleIdToken)) {...}
| Modifier and Type | Class and Description |
|---|---|
static class |
GoogleIdTokenVerifier.Builder
|
DEFAULT_TIME_SKEW_SECONDS| Modifier | Constructor and Description |
|---|---|
protected |
GoogleIdTokenVerifier(GoogleIdTokenVerifier.Builder builder) |
|
GoogleIdTokenVerifier(GooglePublicKeysManager publicKeys) |
|
GoogleIdTokenVerifier(HttpTransport transport,
JsonFactory jsonFactory) |
| Modifier and Type | Method and Description |
|---|---|
long |
getExpirationTimeMilliseconds()
Deprecated.
(scheduled to be removed in 1.18) Use
getPublicKeysManager() and GooglePublicKeysManager.getExpirationTimeMilliseconds() instead. |
JsonFactory |
getJsonFactory()
Returns the JSON factory.
|
String |
getPublicCertsEncodedUrl()
Deprecated.
(scheduled to be removed in 1.18) Use
getPublicKeysManager() and GooglePublicKeysManager.getPublicCertsEncodedUrl() instead. |
List<PublicKey> |
getPublicKeys()
Deprecated.
(scheduled to be removed in 1.18) Use
getPublicKeysManager() and GooglePublicKeysManager.getPublicKeys() instead. |
GooglePublicKeysManager |
getPublicKeysManager()
Returns the Google public keys manager.
|
HttpTransport |
getTransport()
Returns the HTTP transport.
|
GoogleIdTokenVerifier |
loadPublicCerts()
Deprecated.
(scheduled to be removed in 1.18) Use
getPublicKeysManager() and GooglePublicKeysManager.refresh() instead. |
boolean |
verify(GoogleIdToken googleIdToken)
Verifies that the given ID token is valid using the cached public keys.
|
GoogleIdToken |
verify(String idTokenString)
Verifies that the given ID token is valid using
verify(GoogleIdToken) and returns the
ID token if succeeded. |
getAcceptableTimeSkewSeconds, getAudience, getClock, getIssuer, getIssuers, verifypublic GoogleIdTokenVerifier(HttpTransport transport, JsonFactory jsonFactory)
transport - HTTP transportjsonFactory - JSON factorypublic GoogleIdTokenVerifier(GooglePublicKeysManager publicKeys)
publicKeys - Google public keys managerprotected GoogleIdTokenVerifier(GoogleIdTokenVerifier.Builder builder)
builder - builderpublic final GooglePublicKeysManager getPublicKeysManager()
public final HttpTransport getTransport()
public final JsonFactory getJsonFactory()
@Deprecated public final String getPublicCertsEncodedUrl()
getPublicKeysManager() and GooglePublicKeysManager.getPublicCertsEncodedUrl() instead.@Deprecated public final List<PublicKey> getPublicKeys() throws GeneralSecurityException, IOException
getPublicKeysManager() and GooglePublicKeysManager.getPublicKeys() instead.Upgrade warning: in prior version 1.16 it may return null and not throw any
exceptions, but starting with version 1.17 it cannot return null and may throw GeneralSecurityException or IOException.
GeneralSecurityExceptionIOException@Deprecated public final long getExpirationTimeMilliseconds()
getPublicKeysManager() and GooglePublicKeysManager.getExpirationTimeMilliseconds() instead.Clock.currentTimeMillis()
or 0 for none.public boolean verify(GoogleIdToken googleIdToken) throws GeneralSecurityException, IOException
It verifies:
"accounts.google.com" or "https://accounts.google.com".
googleIdToken - Google ID tokentrue if verified successfully or false if failedGeneralSecurityExceptionIOExceptionpublic GoogleIdToken verify(String idTokenString) throws GeneralSecurityException, IOException
verify(GoogleIdToken) and returns the
ID token if succeeded.idTokenString - Google ID token stringnull if failedGeneralSecurityExceptionIOException@Deprecated public GoogleIdTokenVerifier loadPublicCerts() throws GeneralSecurityException, IOException
getPublicKeysManager() and GooglePublicKeysManager.refresh() instead.getPublicCertsEncodedUrl().
This method is automatically called if the public keys have not yet been initialized or if the expiration time is very close, so normally this doesn't need to be called. Only call this method explicitly to force the public keys to be updated.
GeneralSecurityExceptionIOExceptionCopyright © 2010–2022 Google. All rights reserved.