Q&A

Getting LINE groupId, roomId, or utouId from server-side

When a user opens a LIFF link in a group, room, or utou for the first time, is it possible that my server knows the groupId/roomId/utouId securely? Sending groupId/roomId/utouId obtained from liff.getContext() to my server may be risky because someone may spoof the groupId/roomId/utouId. Sending context token might be the solution but I don't know how to verify that token.

  • 0
  • 1
  • 1239
  • twitter facebook

https://developers.line.biz/en/docs/liff/using-user-profile/#use-user-information-on-server

This page explains your usecase.

To use the user information on the server, send the ID token or access token from the LIFF app to the server. The server can safely retrieve the user's profile by sending the token sent by the LIFF app to the LINE Platform.

  • 0
本当によろしいですか? question.vm