【问题标题】:Google Directory API and PHP: Unauthorized client or scope in requestGoogle Directory API 和 PHP:请求中的未经授权的客户端或范围
【发布时间】:2016-07-22 05:13:01
【问题描述】:

我正在使用 Google Directory API、oauth2 的服务帐户和 PHP,从命令行运行。

作为第一步,我只是尝试检索单个用户对象。代码如下:

require_once realpath(__DIR__ . '/../vendor/autoload.php');
session_start();
define('APPLICATION_NAME', 'Directory API PHP Quickstart');
define('SCOPES', implode(' ', 
array(Google_Service_Directory::ADMIN_DIRECTORY_USER_READONLY)));
putenv('GOOGLE_APPLICATION_CREDENTIALS=/path/to/XXXXXXXX.json');
$client = new Google_Client();
$client->useApplicationDefaultCredentials();
$client->addScope(SCOPES);
$client->setSubject('me@mydomain.com');
$httpClient = $client->authorize();
$response = 
$httpClient->get('https://www.googleapis.com/admin/directory/v1/users/me@mydomain.com');
print $response->getBody();

这是我得到的回复:

Uncaught exception 'GuzzleHttp\Exception\ClientException' with message 'Client error: `POST https://www.googleapis.com/oauth2/v4/token` resulted in a `401 Unauthorized` response:
{
 "error": "unauthorized_client",
 "error_description": "Unauthorized client or scope in request."
}

' in /var/www/feeds/vendor/guzzlehttp/guzzle/src/Exception/RequestException.php:107
Stack trace: #0 /var/www/feeds/vendor/guzzlehttp/guzzle/src/Middleware.php(65): GuzzleHttp\Exception\RequestException::create(Object(GuzzleHttp\Psr7\Request), Object(GuzzleHttp\Psr7\Response))
#1 /var/www/feeds/vendor/guzzlehttp/promises/src/Promise.php(203): GuzzleHttp\Middleware::GuzzleHttp\{closure}(Object(GuzzleHttp\Psr7\Response))
#2 /var/www/feeds/vendor/guzzlehttp/promises/src/Promise.php(156): GuzzleHttp\Promise\Promise::callHandler(1, Object(GuzzleHttp\Psr7\Response), Array)
#3 /var/www/feeds/vendor/guzzlehttp/promises/src/TaskQueue.php(61): GuzzleHttp\Promise\Promise::GuzzleHttp\Promise\{closure}()
#4 /var/www/feeds/vendor/guzzlehttp/promis in /var/www/feeds/vendor/guzzlehttp/guzzle/src/Exception/RequestException.php on line 107

在管理控制台 > 安全 > 管理 API 客户端访问中,我输入了具有这些 API 范围的客户端 ID:

View and manage the provisioning of groups on your domain
https://www.googleapis.com/auth/admin.directory.group
View and manage the provisioning of users on your domain
https://www.googleapis.com/auth/admin.directory.user
Groups Settings
https://www.googleapis.com/auth/apps.groups.settings 

我用于该主题的帐户 ('me@mydomain.com') 是该域的超级管理员。为服务帐户启用了域范围的委派。

我在这里忽略了什么?任何帮助将不胜感激。

【问题讨论】:

    标签: php google-directory-api


    【解决方案1】:

    检查您是否已在管理控制台中启用 API,同时检查您的 Google Project for Admin SDK 中是否已启用该服务。

    【讨论】:

      猜你喜欢
      • 2015-07-06
      • 2015-02-01
      • 1970-01-01
      • 2017-02-22
      • 2016-10-13
      • 2022-09-19
      • 2015-10-11
      • 2018-07-11
      • 2014-11-06
      相关资源
      最近更新 更多