Closed lirbank closed 8 years ago
The token in the address bar or local storage is a horizon JWT, not the token from the Google servers. The Google token is used internally to check the user's Google account ID and correspond it to a horizon user row; it is never sent to the browser.
Oh, that explains it!
Server version: 2.0.0 Client version: 2.0.0
Response:
Info: https://developers.google.com/identity/protocols/OpenIDConnect#validatinganidtoken