Skip to content
This page View Markdown Open in ChatGPT Open in Claude

Auth with Google

Your app signs people in with Google and sends the id token to API Maker. An auth provider of type Google checks it against your OAuth client, finds the person in a table of yours, and runs the call with the groups of that person.

Page API Security → Auth Providers → type Google.
Header x-google-authorization: <Google id token>
In code g.req.auth.authGoogle : the opened token, and the columns selected from your table.
The provider
1
2
3
4
5
6
7
8
9
import * as T from 'types';

let googleTokenGenerator: T.IAuthTokenGoogle & { name: string; testObj?: any; } = {
    name: 'google_token_generator',
    clientId: '<OAuth client id>.apps.googleusercontent.com',
    sourceFieldOfUniqueId: 'sub',        // or 'email'
    groupsDataSource: { instance: 'mongodb', database: 'shop', collection: 'users', targetFieldForUniqueId: 'google_sub', groupsColumn: 'groups', select: { name: 1, email: 1 } },
};
module.exports = googleTokenGenerator;

The groups of the person

  • sourceFieldOfUniqueId is the claim of the token which identifies the person (an email, sub, oid).
  • groupsDataSource names the table of yours which holds that person : targetFieldForUniqueId is the column with the same value, groupsColumn the comma separated groups of the person, select the columns to put in g.req.auth.
  • Without groupsDataSource, the token is checked but the person gets no group of its own : only the API user decides.

Require it

  • authProviders: ['google_token_generator'] in the settings of the APIs, tables or databases, or in common.authProviders of the secret.
  • The call carries the API user token in x-am-authorization and the token of the provider in x-google-authorization.
  • testObj in the provider is the person the API testing page pretends to be.