使用 OIDC 的授权码流程
实施安全的授权码流程,并通过 OIDC 对其进行扩展,使其在返回访问令牌的同时返回 ID Token。
使用 OIDC 的授权码流程 是 CoddyKit 上的免费 OAuth2 & OpenID Connect Deep Dive 课时。 这是第 1 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 OAuth2 & OpenID Connect Deep Dive 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
OIDC & Auth Code Flow Intro
Welcome! In this lesson, we'll combine the secure Authorization Code Flow from OAuth2 with OpenID Connect (OIDC). This allows an application to not only get permission to access resources (OAuth2) but also to verify the user's identity (OIDC).
Think of it as getting both a key to a safe and a valid ID card for the person holding the key, all in one go!
Requesting Identity with OIDC
When using the Authorization Code Flow with OIDC, your application (the Client) starts by sending an authorization request to the Authorization Server. This request is similar to OAuth2 but includes specific OIDC parameters.
response_type=code: Specifies we want an Authorization Code.scope=openid ...: Crucially, includes theopenidscope to signal an OIDC request.nonce: A unique string to prevent replay attacks (optional but recommended).
The Essential `openid` Scope
The openid scope is the magic flag that tells the Authorization Server you're performing an OpenID Connect request, not just a plain OAuth2 request.
Without openid in your request's scope, the Authorization Server will treat it as a standard OAuth2 flow and will not issue an ID Token.
You can combine openid with other standard OAuth2 scopes like profile, email, or custom scopes.
Beyond `openid`: More Scopes
While openid is mandatory, other OIDC-specific scopes allow you to request more user information:
profile: Access to default profile claims (name, family name, gender, picture, etc.).email: Access to the user's email address and verification status.address: Access to the user's postal address.phone: Access to the user's phone number and verification status.
These claims are then included in the ID Token or accessible via the UserInfo Endpoint.
User Consent & Code Grant
After your app sends the authorization request, the user is redirected to the Authorization Server. They log in (if needed) and are prompted to consent to your app's requested scopes.
If the user approves, the Authorization Server redirects the user back to your app's registered redirect URI, including the Authorization Code in the URL query parameters.
The Token Exchange
Now, your application (running on a server, for confidential clients) takes the received Authorization Code and exchanges it directly with the Authorization Server's token endpoint.
This is a back-channel request, meaning it happens directly between your server and the Authorization Server, not through the user's browser.
Crucially, this exchange now returns three important pieces of information:
- Access Token
- Refresh Token (if requested)
- ID Token
What is the ID Token?
The ID Token is a JSON Web Token (JWT) that contains claims about the authenticated user. It's signed by the Authorization Server, allowing your application to verify its authenticity.
Unlike the Access Token (which is for resource access), the ID Token is specifically for identity verification. It tells your application *who* the user is, not *what* they can do.
ID Token for Identity, Access Token for API
Once your application receives the tokens:
- ID Token: You can decode and validate the ID Token to confirm the user's identity and retrieve basic profile information (claims). This is often used for user login sessions.
- Access Token: This token is then used to make requests to protected Resource Servers (APIs) on behalf of the user, granting access to specific resources based on the requested scopes.
OIDC Auth Code Flow in Action
Here's a simplified conceptual look at the server-side token exchange. In a real application, you'd use an OIDC client library.
public class OidcClientExample {
public static void main(String[] args) {
// 1. User is redirected to Auth Server
// Example URL:
// https://auth.example.com/oauth/authorize?
// response_type=code&
// client_id=my_app_id&
// scope=openid%20profile%20email&
// redirect_uri=https://my-app.com/callback&
// nonce=random_string
// 2. User grants consent, redirected back with code
String authCode = "some_long_authorization_code"; // From redirect URI
// 3. Exchange code for tokens (server-side POST request)
System.out.println("Exchanging Authorization Code for tokens...");
// This part would typically be handled by an HTTP client
// sending a POST request to the token endpoint.
// The response would contain:
// {
// "access_token": "...",
// "token_type": "Bearer",
// "expires_in": 3600,
// "refresh_token": "...",
// "id_token": "..." // The OIDC addition!
// }
System.out.println("Received Access Token, Refresh Token, and ID Token!");
System.out.println("ID Token contains user identity claims.");
}
}OIDC Auth Code Flow Check
Consider an application implementing the OpenID Connect Authorization Code Flow.
Which of the following parameters is essential in the initial authorization request to ensure an ID Token is returned?
OIDC Auth Code Flow Recap
Great job! You've learned how the secure Authorization Code Flow is extended by OpenID Connect to provide both authorization and identity.
- We use
response_type=codeand include theopenidscope. - The Authorization Server returns an Authorization Code.
- This code is exchanged for an Access Token (for resource access) and an ID Token (for user identity).
- The ID Token is a JWT carrying user claims, signed by the Authorization Server.
This flow is highly recommended for confidential clients like web applications.
常见问题解答
「使用 OIDC 的授权码流程」课时是免费的吗?
是的 — 「使用 OIDC 的授权码流程」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 OAuth2 & OpenID Connect Deep Dive 课程的其余内容,请升级到 CoddyKit PRO。 OAuth2 & OpenID Connect Deep Dive 课程共包含 4 节课。
「使用 OIDC 的授权码流程」这节课中我会学到什么?
实施安全的授权码流程,并通过 OIDC 对其进行扩展,使其在返回访问令牌的同时返回 ID Token。 你通过在浏览器中直接运行的动手代码来练习 OAuth2 & OpenID Connect Deep Dive,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 OAuth2 & OpenID Connect Deep Dive 需要有经验吗?
无需任何先前经验。CoddyKit 上的 OAuth2 & OpenID Connect Deep Dive 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 1 节课,共 4 节。
「使用 OIDC 的授权码流程」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 OAuth2 & OpenID Connect Deep Dive 课中编写并运行代码吗?
能。每节 OAuth2 & OpenID Connect Deep Dive 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 使用 OIDC 的授权码流程
- 使用 OIDC 的隐式流程
- 使用 OIDC 的混合流程
- 使用 nonce 防止重放