Google#
Sign in with a Google account.
Warning
Provider-side steps are not verified. The Plone side below is read from this package's source and is accurate. The Google Cloud console steps have not been walked through against a live project, and that console changes often, so follow Google's own OpenID Connect documentation for the console and use the tables here for Plone.
1. What you need from Google#
Create an OAuth 2.0 Client ID of type Web application in the Google Cloud console, and note the client ID and client secret.
The authorized redirect URI is:
https://www.example.com/login-identity
2. Add the provider#
Open the Identity providers control panel.
Add a provider and choose Google (
google).On the Settings tab:
Field
Value
Title
GoogleClient ID
from step 1
Client secret
from step 1
Scope
leave empty for the default
openid email profileSave, then Test connection.
There is no issuer field: the driver fixes the issuer at
https://accounts.google.com and discovers everything else from it.
3. The trust switches#
On the Accounts tab.
This driver ships with email verification trusted. google and github are
the only two shipped drivers that do.
Field |
Default |
Guidance |
|---|---|---|
Trust this provider's email verification |
on |
Reasonable for consumer Google accounts |
Attach to an existing account with the same verified email |
off |
Turn on to merge with existing accounts |
Let this provider create accounts |
on |
Turn off to admit only people who already have an account |
Warning
A Google Workspace domain you do not control is not the same trust decision as consumer Google. If someone else administers the domain, they decide who gets an address in it, and therefore who reaches an account here by email matching.
4. Groups#
There is no Groups tab for a Google provider. The google driver's settings
schema is IOAuth2Settings, which carries no group claim, no allowed-groups
list, and no sync switch. Google sends this package no groups it can read.
To restrict which Google accounts may sign in, turn off account creation and add the accounts yourself. See How to control account creation.
Verify#
/loginshows the Google button.Signing in returns you signed in.
/identitieslists the identity; the subject is Google'ssub.The audit log has an
authenticatedentry.
Known quirks#
The subject is
sub, not the email address. A person who changes their Google address keeps their Plone account.Unverified Google accounts exist. Google sends
email_verified: falsefor them, and this package then treats the address as unverified regardless of the trust switch. That is the switch working.