Search code examples
phpgoogle-oauthgoogle-identity

Error when Using google PHP API library to retrieve user details


I get an error when trying to fetch user details from my 'Google_Client' object created from new Google_Client(['client_id' => $CLIENT_ID]);

This is the code i used;

`
require '/home/nowvibac/vendor/autoload.php';

try{

$CLIENT_ID =  '204553466403-o75aj25ktmmjkk1g5a3set3losqvfeqe.apps.googleusercontent.com';

$client = new Google_Client(['client_id' => $CLIENT_ID]);  // Specify the CLIENT_ID of the app that accesses the backend

$payload = $client->verifyIdToken($id_token);

if ($payload) {
/*Own-- this id is the same as the one in js but its more authentic to avoid user manipulation */    
//verified variables from Google's API
  $googleUserid = $payload['sub'];
$email = $payload['email'];
$picture = $payload['picture'];
$name = $payload['name'];}

}catch(Exception $e){
  echo $e;
}
`

I was expecting to get all user details i.e. $googleUserid,$email,$picture, for a specific gmail account but instead am getting the below error;

`Failed to retrieve verification certificates: "<!DOCTYPE html>
<html lang=en>
  <meta charset=utf-8>
  <meta name=viewport content="initial-scale=1, minimum-scale=1, width=device-width">
  <title>Error 403 (Forbidden)!!1</title>
  <style>
    *{margin:0;padding:0}html,code{font:15px/22px arial,sans-serif}html{background:#fff;color:#222;padding:15px}body{margin:7% auto 0;max-width:390px;min-height:180px;padding:30px 0 15px}* > body{background:url(//www.google.com/images/errors/robot.png) 100% 5px no-repeat;padding-right:205px}p{margin:11px 0 22px;overflow:hidden}ins{color:#777;text-decoration:none}a img{border:0}@media screen and (max-width:772px){body{background:none;margin-top:0;max-width:none;padding-right:0}}#logo{background:url(//www.google.com/images/branding/googlelogo/1x/googlelogo_color_150x54dp.png) no-repeat;margin-left:-5px}@media only screen and (min-resolution:192dpi){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat 0% 0%/100% 100%;-moz-border-image:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) 0}}@media only screen and (-webkit-min-device-pixel-ratio:2){#logo{background:url(//www.google.com/images/branding/googlelogo/2x/googlelogo_color_150x54dp.png) no-repeat;-webkit-background-size:100% 100%}}#logo{display:inline-block;height:54px;width:150px}
  </style>
  <a href=//www.google.com/><span id=logo aria-label=Google></span></a>
  <p><b>403.</b> <ins>That’s an error.</ins>
  <p>Your client does not have permission to get URL <code>/oauth2/v3/certs</code> from this server.  <ins>That’s all we know.</ins>`

Solution

  • I managed to solve this by making use of this URL:

    https://oauth2.googleapis.com/tokeninfo?id_token=$id_token
    

    to fetch the user data instead of relying on the php composer based, Google API library.

    Replace $id_token with the actual token.

    My code now looks like this;

    // Get $id_token via HTTPS POST.
    $in = file_get_contents('php://input');
    $id_token = json_decode($in, true);
    
    try{
      //under this arrangement, app is nolonger making use of google's PHP api
      if(!file_get_contents ( "https://oauth2.googleapis.com/tokeninfo?id_token=$id_token" )){
        //if url fails to give us a result
        throw new Exception("retuned false value");
      }
    $response = file_get_contents ( "https://oauth2.googleapis.com/tokeninfo?id_token=$id_token" );
    $response = json_decode ( $response );
    $response =  (array)$response;
    //verified variables from Google's API
    /*Own-- this id is the same as the one in js but its more authentic to avoid user manipulation */ 
        $googleUserid = $response['sub'];
        $email = $response['email'];
        $picture = $response['picture'];
        $name = $response['name'];
      
    }catch(Exception $e){
      echo json_encode(["message"=>"$e","customStatuscode"=>4004]);
      exit;
    } 
    

    This answer is what helped me arrive at this solution.