Google Signin

Use when implementing, reviewing or debugging Google login / sign-in / sign-up on a website — wiring the GIS button or One Tap, verifying Google ID tokens on the server, linking Google to existing password accounts, or fixing "origin is not allowed for the given client ID". Covers GCP OAuth client setup, backend ID-token verification, three-way account linking with the pre- hijacking guard, login-CSRF defense, nonce/replay protection and a mandatory security checklist. Triggers - "sign in with google", "google login", "google sign-in button", "GIS", "google.accounts.id", "gsi/client", "verify google token", "one tap", "account linking", "login csrf", "g_csrf_token", "вход через Google", "кнопка входа Google", "связать аккаунты", "проверить токен Google". For the broader library surface use google-auth instead.

ssheleg 5a4a286 2 files · 33.7 KB Updated

File contents

ssheleg/sheleg-dev/tree/main/plugins/sheleg-dev/skills/google-signin commit 5a4a286b59

Frequently asked questions

npx skillmds@latest add ssheleg/google-signin