You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Google Apps Script中调用Cloud Identity API遇401认证错误求助

解决Cloud Identity API调用401未认证错误的方案

核心问题

你的代码未将服务账号的认证凭证附加到API请求中,导致请求缺少OAuth 2.0访问令牌,触发401未授权错误。

解决步骤

1. 完成服务账号域范围授权(必须操作)

要访问Google Workspace的组织级资源,服务账号必须获得域范围授权:

  • 登录Google Workspace Admin Console,进入「安全」>「API控制」>「域范围授权」
  • 添加服务账号的客户端ID(即cloudidentity_credentials中的client_id值)
  • 输入所需的OAuth权限范围,例如:
    • https://www.googleapis.com/auth/cloud-identity.policies(Cloud Identity策略访问权限)
    • https://www.googleapis.com/auth/admin.directory.security(Workspace安全设置访问权限,按需添加)
  • 保存设置

2. 修改代码,添加认证逻辑

更新代码实现服务账号的OAuth令牌生成,并将令牌附加到API请求头中:

新增令牌生成函数

function getServiceAccountToken() {
  // 处理私钥中的换行符问题
  const privateKey = cloudidentity_credentials.private_key.replace(/\\n/g, '\n');
  const privateKeyBytes = Utilities.newBlob(privateKey).getBytes();
  
  // 构造JWT payload
  const payload = {
    iss: cloudidentity_credentials.client_email,
    scope: 'https://www.googleapis.com/auth/cloud-identity.policies', // 按需添加更多权限范围
    aud: cloudidentity_credentials.token_uri,
    exp: Math.floor(Date.now() / 1000) + 3600, // 令牌有效期1小时
    iat: Math.floor(Date.now() / 1000)
  };
  
  // 签名JWT
  const signedPayload = Utilities.computeRsaSha256Signature(JSON.stringify(payload), privateKeyBytes);
  const encodedJwt = `${Utilities.base64EncodeWebSafe(JSON.stringify(payload))}.${Utilities.base64EncodeWebSafe(signedPayload)}`;
  
  // 请求访问令牌
  const tokenResponse = UrlFetchApp.fetch(cloudidentity_credentials.token_uri, {
    method: 'POST',
    payload: {
      grant_type: 'urn:ietf:params:oauth:grant-type:jwt-bearer',
      assertion: encodedJwt
    }
  });
  
  const tokenData = JSON.parse(tokenResponse.getContentText());
  return tokenData.access_token;
}

更新主函数,添加认证头

function get_settings(){
  const ss = SpreadsheetApp.getActiveSpreadsheet();
  const settingsSheet = ss.getSheetByName("02. Google Workspace Security Settings");

  // 获取服务账号访问令牌
  const accessToken = getServiceAccountToken();
  
  // 替换{YOUR_CUSTOMER_ID}为你的Workspace客户ID(格式C0xxxxxxx,可在Admin Console>账号设置中找到)
  const url = "https://cloudidentity.googleapis.com/v1beta1/policies?parent=customers/{YOUR_CUSTOMER_ID}";

  // 携带认证头发起API请求
  const response = UrlFetchApp.fetch(url, {
    headers: {
      'Authorization': `Bearer ${accessToken}`
    }
  });
  
  const json = response.getContentText();
  const data = JSON.parse(json);

  console.log(data);
  // 后续可将数据写入Sheet,示例:
  // settingsSheet.getRange(1,1, Object.keys(data).length, 1).setValues(Object.values(data).map(v => [v]));
}

3. 额外检查项

  • 确认GCP项目中已为服务账号分配Cloud Identity Policy Admin角色(或所需的细粒度权限)
  • 检查API端点的parent参数是否正确,无此参数会导致400错误(解决401后可能出现)
  • 确保服务账号的私钥格式无篡改,代码中已处理换行符问题,但需确认私钥完整

内容的提问来源于stack exchange,提问作者Mark Fraher

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.15 21:35:54