Nexttag.Auth.Identity.Google 1.1.2

dotnet add package Nexttag.Auth.Identity.Google --version 1.1.2
                    
NuGet\Install-Package Nexttag.Auth.Identity.Google -Version 1.1.2
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Nexttag.Auth.Identity.Google" Version="1.1.2" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Nexttag.Auth.Identity.Google" Version="1.1.2" />
                    
Directory.Packages.props
<PackageReference Include="Nexttag.Auth.Identity.Google" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Nexttag.Auth.Identity.Google --version 1.1.2
                    
#r "nuget: Nexttag.Auth.Identity.Google, 1.1.2"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Nexttag.Auth.Identity.Google@1.1.2
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Nexttag.Auth.Identity.Google&version=1.1.2
                    
Install as a Cake Addin
#tool nuget:?package=Nexttag.Auth.Identity.Google&version=1.1.2
                    
Install as a Cake Tool

Nexttag.Auth.Identity.Google

Login social com Google para ASP.NET Identity, em cima de Nexttag.Auth.Identity. Valida o id_token que o cliente (web/mobile) obtém no Google Sign-In, acha-ou-cria o usuário no Identity e emite um JWT local. Sem Firebase.

Instalação

dotnet add package Nexttag.Auth.Identity.Google

Configuração

// Program.cs — depois de configurar o Identity da Nexttag
builder.Services.AddNexttagIdentity<AppDbContext, AppUser>(builder.Configuration);
builder.Services.AddNexttagGoogleLogin<AppUser>(builder.Configuration);
// appsettings.json — informe os client IDs do OAuth do Google (web/android/ios)
"Google": {
  "ClientId": "xxxxx.apps.googleusercontent.com",
  "ClientIds": [
    "web.apps.googleusercontent.com",
    "android.apps.googleusercontent.com"
  ]
}

Todos os client IDs informados são aceitos como audiência (aud) válida do token.

Segurança (obrigatório): configurar ao menos um Client ID é obrigatório. Sem ClientId/ClientIds, a validação falha fechado (retorna token inválido) — nunca aceita audiência arbitrária, o que permitiria account takeover com um id_token de outro app OAuth do Google.

Além disso, apenas contas com e-mail verificado pelo Google (email_verified) são aceitas para login/vínculo/criação — e-mail não verificado é rejeitado (401).

Uso no endpoint

[HttpPost("api/auth/google")]
public async Task<IActionResult> Google(
    [FromBody] GoogleLoginRequest body,
    IdentityGoogleAuthService<AppUser> auth)
{
    var r = await auth.LoginAsync(body.IdToken);
    if (!r.IsSuccess)
        return Problem(detail: r.Error!.Message, statusCode: r.Error.StatusCode);

    return Ok(new { token = r.Value!.Token, novoUsuario = r.Value.NovoUsuario });
}

public record GoogleLoginRequest(string IdToken);

Como funciona

  1. O cliente faz o Google Sign-In nativo e obtém um id_token.
  2. Envia o id_token para a API.
  3. IdentityGoogleAuthService valida o token no Google (assinatura + audiência via IGoogleTokenValidator), então:
    • se já houver login externo Google vinculado → faz login;
    • se houver conta com o mesmo e-mail → vincula o Google a ela;
    • senão → cria o usuário (EmailConfirmed = true, sem senha) e vincula o login.
  4. Emite um JWT local via IJwtService (mesmo token do login por e-mail/senha).

O vínculo do provedor usa a tabela padrão do Identity (AspNetUserLogins) — nenhum campo extra é necessário no usuário. IdentityLoginResult.NovoUsuario indica primeiro acesso (útil para onboarding).

Testabilidade

A validação do token fica atrás de IGoogleTokenValidator (implementação padrão: GoogleTokenValidator, usando Google.Apis.Auth). Em testes, injete um mock do validador para exercitar o fluxo acha-ou-cria sem chamar o Google.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.1.2 137 7/28/2026
1.1.1 116 7/28/2026
1.1.0 119 7/28/2026
1.0.0 121 7/27/2026