【问题标题】:Google Service Account Authentication PHP谷歌服务账户认证 PHP
【发布时间】:2014-01-16 18:22:06
【问题描述】:

我正在尝试对服务帐户进行身份验证,以便可以将访问令牌与客户端 JSON_API 库一起使用。

我看过这些文章:

https://code.google.com/p/google-api-php-client/source/browse/trunk/examples/prediction/serviceAccount.php
https://code.google.com/p/google-api-php-client/wiki/UsingTheLibrary

https://developers.google.com/storage/docs/authentication#service_accounts https://developers.google.com/accounts/docs/OAuth2#scenarios

这是我的 PHP 代码

<?php

require_once 'google-api-php-client/src/Google_Client.php';

const CLIENT_ID = "";
const SERVICE_ACCOUNT_NAME = "";
const KEY_FILE = "super secret path of course ;)";

$client = new Google_Client();

// Loads the key into PKCS 12 format
$key = file_get_contents(KEY_FILE);
$client->setAssertionCredentials(new Google_AssertionCredentials(
    SERVICE_ACCOUNT_NAME,
    array('https://www.googleapis.com/auth/prediction'),
    $key
  )
);

$client->setClientId(CLIENT_ID);
$auth = $client->authenticate();
print $auth ? "Returned true" : "Returned false";
print "<br>";
print is_null($client->getAccessToken()) ? "It's null" : "Works";

?>

这是我的输出:

返回真
是空的

【问题讨论】:

    标签: php google-oauth google-cloud-storage google-authentication


    【解决方案1】:

    在混合使用不同资源后,我终于想出了如何使用 PHP API 库进行身份验证。

    这是我的 google php api 库的身份验证类

    <?php
    require_once 'google-api-php-client/src/Google_Client.php';
    require_once 'google-api-php-client/src/contrib/Google_StorageService.php';
    
    class Model_Storage_Auth
    {
        const CLIENT_ID = "someuniquenumber.apps.googleusercontent.com";
        const SERVICE_ACCOUNT_NAME = "myserviceaccountname@developer.gserviceaccount.com";
        const KEY_FILE = "/supersecretpath/key.p12";
        const ACCESS_TOKEN = 'access_token';
        const APP_NAME = 'My App Name';
    
        private $google_client;
    
        function __construct()
        {
            $this->google_client = new Google_Client();
            $this->google_client->setApplicationName(self::APP_NAME);
        }
    
        public function getToken()
        {
            if(!is_null($this->google_client->getAccessToken())){}
            elseif(!is_null(Session::get(self::ACCESS_TOKEN, null)))
            {
                $this->google_client->setAccessToken(Session::get(self::ACCESS_TOKEN, null));
            }
            else
            {
                $scope = array();
                $scope[] = 'https://www.googleapis.com/auth/devstorage.full_control';
                $key = file_get_contents(self::KEY_FILE);
                $this->google_client->setAssertionCredentials(new Google_AssertionCredentials(
                    self::SERVICE_ACCOUNT_NAME,
                    $scope,
                    $key)
                );
                $this->google_client->setClientId(self::CLIENT_ID);
                Google_Client::$auth->refreshTokenWithAssertion();
                $token = $this->google_client->getAccessToken();
                Session::set(self::ACCESS_TOKEN, $token);
            }
            return $this->google_client->getAccessToken();
        }
    
    }
    

    【讨论】:

      【解决方案2】:

      需要检查的几件事:

      • 首先,我假设 CLIENT_IDSERVICE_ACCOUNT_NAME 被设置为您的实际客户端 ID 和服务帐户名称,而不仅仅是空字符串,对吧?

      • 其次,您正在使用 OAuth 范围 https://www.googleapis.com/auth/prediction 但试图使用它来访问 GCS。您需要使用只读、读写或完全控制范围,您可以找到 here。例如,如果您想要读写访问权限,则可以使用范围 https://www.googleapis.com/auth/devstorage.read_write

      【讨论】:

      • 是的,我的 CLIENT_ID 和 SERVIE_ACCOUNT_NAME 设置为正确的值,我在范围内设置了该 URL。仍然得到相同的输出:\
      猜你喜欢
      • 1970-01-01
      • 2022-12-17
      • 1970-01-01
      • 2019-04-24
      • 2016-07-19
      • 2021-02-23
      • 1970-01-01
      • 1970-01-01
      • 1970-01-01
      相关资源
      最近更新 更多