You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何解决GCP全域委派下Google Drive API的文件找不到错误

问题:使用GoogleAuth库模拟用户调用Drive API返回404错误,JWT方法可正常运行

问题详情

已完成以下配置,但调用Google Drive API时返回404文件找不到错误:

  • 服务账号已在Google管理控制台配置https://www.googleapis.com/auth/drive权限的全域委派
  • 目标文件夹ID正确,且由域内用户mark@domain.org创建并拥有所有权
  • 仅使用google.auth.JWT方法可成功调用API,使用GoogleAuth库的方式失败

有问题的代码

const { GoogleAuth } = require('google-auth-library');
const { google } = require('googleapis');
const axios = require('axios');

const SCOPES = ['https://www.googleapis.com/auth/drive'];
const USER_TO_IMPERSONATE = "mark@domain.org"

const FILE = "correct_file_id"

const doStuff = async (gc, id) => {
    try {
        console.log(await gc.getAccessToken());
        const drive = google.drive({ version: 'v3', auth: gc })
        const folderMetadata = await drive.files.get({
            fileId: id,
            fields: 'id, name, mimeType',
        });
        console.log(folderMetadata)
        return folderMetadata
    } catch (error) {
        if (error.response) {
            console.error('Error response:', error.response.data);
        }
        console.error('Error message:', error.message);
        console.error('There was an error!');
        return null
    }
}

exports.logServiceAccount = async (req, res) => {
  try {
    const auth = new GoogleAuth({scopes: SCOPES})
    const client = await auth.getClient()
    client.subject = USER_TO_IMPERSONATE
    const projectId = await auth.getProjectId()
    const metadataUrl = 'http://metadata.google.internal/computeMetadata/v1/instance/service-accounts/default/email'
    const response = await axios.get(metadataUrl, {
      headers: { 'Metadata-Flavor': 'Google' },
    })
    const email = response.data

    const f = await doStuff(client, FILE)

    res.send(`Authenticated as service account: ${email}, Project ID: ${projectId}, file res: ${f == null ? "issue" : f}`)
  } catch (error) {
    console.error('Error retrieving service account details:', error)
    res.status(500).send('Error retrieving service account details')
  }
}

可用的JWT参考代码

const auth = new google.auth.JWT({
            keyFile: KEY_FILE,
            scopes: SCOPES,
            subject: salesFolders[salesRepName]["email"]
        });
const driveClient = google.drive({ version: "v3", auth })

问题原因

GoogleAuth.getClient()默认获取的是应用默认凭据(如GCE/GCF的内置服务账号),这类凭据未配置全域委派权限,直接设置subject属性无法触发用户模拟流程。而google.auth.JWT方法明确指定了服务账号密钥,能正确触发全域委派的模拟逻辑。

解决方案

方案1:通过密钥文件初始化GoogleAuth

修改认证逻辑,明确指定服务账号密钥文件,让GoogleAuth直接创建带模拟用户的JWT客户端:

exports.logServiceAccount = async (req, res) => {
  try {
    // 替换为你的服务账号密钥文件路径
    const auth = new GoogleAuth({
      scopes: SCOPES,
      keyFile: 'path/to/service-account-key.json',
      clientOptions: {
        subject: USER_TO_IMPERSONATE
      }
    });
    const client = await auth.getClient();
    
    const projectId = await auth.getProjectId()
    const email = client.email; // 直接从客户端获取服务账号邮箱,无需调用元数据接口

    const f = await doStuff(client, FILE)

    res.send(`Authenticated as service account: ${email}, Project ID: ${projectId}, file res: ${f == null ? "issue" : f}`)
  } catch (error) {
    console.error('Error retrieving service account details:', error)
    res.status(500).send('Error retrieving service account details')
  }
}

方案2:通过环境变量指定凭据

设置环境变量GOOGLE_APPLICATION_CREDENTIALS指向服务账号密钥文件路径,然后简化认证代码:

exports.logServiceAccount = async (req, res) => {
  try {
    const auth = new GoogleAuth({
      scopes: SCOPES,
      clientOptions: {
        subject: USER_TO_IMPERSONATE
      }
    });
    const client = await auth.getClient();
    
    const projectId = await auth.getProjectId()
    const email = client.email;

    const f = await doStuff(client, FILE)

    res.send(`Authenticated as service account: ${email}, Project ID: ${projectId}, file res: ${f == null ? "issue" : f}`)
  } catch (error) {
    console.error('Error retrieving service account details:', error)
    res.status(500).send('Error retrieving service account details')
  }
}

权限验证方法

  1. 检查全域委派配置

    • 登录Google管理控制台,进入安全 > API控制 > 域宽委派
    • 确认服务账号的客户端ID已添加,授权范围包含https://www.googleapis.com/auth/drive,无拼写错误
  2. 验证模拟用户身份
    在doStuff函数中添加代码,确认是否正确模拟目标用户:

    const tokenInfo = await drive.auth.getTokenInfo(await gc.getAccessToken());
    console.log('当前模拟用户:', tokenInfo.email);
    

    若输出不是mark@domain.org,说明模拟未成功,需检查认证配置

  3. 测试文件访问权限
    调用drive.files.list接口搜索目标文件ID,确认模拟后的账号能检索到该文件:

    const searchRes = await drive.files.list({
      q: `id='${id}'`,
      fields: 'files(id,name)'
    });
    console.log('搜索结果:', searchRes.data.files);
    

内容的提问来源于stack exchange,提问作者jim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 11:12:28