You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用PSGSuite时OAuth2 Token缺失权限范围的原因排查

Google Workspace测试域用户列表获取权限异常问题

操作场景与已完成步骤

  • 已创建Google Cloud项目并启用Admin API,在OAuth2同意屏幕中配置了代码指定的全部权限范围;授权流程正常,仅当权限范围变更时才会触发重新授权弹窗。
  • 执行的PowerShell代码如下:
Import-Module -Name PSGSuite 
-- 已移除配置行

$Scopes = "https://www.googleapis.com/auth/cloud-platform,
    https://www.googleapis.com/auth/admin.directory.user,
    https://www.googleapis.com/auth/admin.directory.user.readonly
    https://apps-apis.google.com/a/feeds/emailsettings/2.0/,
    https://mail.google.com/,
    https://www.google.com/m8/feeds/contacts,
    https://www.googleapis.com/auth/admin.directory.group,
    https://www.googleapis.com/auth/admin.directory.resource.calendar,
    https://www.googleapis.com/auth/admin.directory.rolemanagement,
    https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,
    https://www.googleapis.com/auth/admin.directory.user,
    https://www.googleapis.com/auth/admin.directory.user.readonly,
    https://www.googleapis.com/auth/admin.directory.user.security,
    https://www.googleapis.com/auth/admin.directory.userschema,
    https://www.googleapis.com/auth/admin.reports.audit.readonly,
    https://www.googleapis.com/auth/admin.reports.usage.readonly,
    https://www.googleapis.com/auth/apps.groups.settings,
    https://www.googleapis.com/auth/gmail.settings.basic,
    https://www.googleapis.com/auth/gmail.settings.sharing,
    https://www.googleapis.com/auth/plus.login,
    https://www.googleapis.com/auth/plus.me,
    https://www.googleapis.com/auth/tasks,
    https://www.googleapis.com/auth/tasks.readonly,
    https://www.googleapis.com/auth/userinfo.email,
    https://www.googleapis.com/auth/userinfo.profile"

$Token = Get-GSToken -Scopes $Scopes -AdminEmail "已移除"
Write-Host "$($Token)"
Get-GSUser -Filter *

异常现象

  1. 权限范围不匹配:获取Token后,通过https://www.googleapis.com/oauth2/v1/tokeninfo?access_token=查询,返回的权限范围远少于请求的范围,返回结果如下:
{
  "issued_to": "已移除,与应用配置一致且正确",
  "audience": "已移除,与应用配置一致且正确",
  "scope": "https://mail.google.com https://www.google.com/m8/feeds https://www.googleapis.com/auth/calendar https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/gmail.settings.basic https://www.googleapis.com/auth/gmail.settings.sharing https://www.googleapis.com/auth/tasks https://www.googleapis.com/auth/tasks.readonly",
  "expires_in": 3549,
  "access_type": "offline"
}
  1. 执行Get-GSUser报错:
Get-GSUser : Exception calling "Execute" with "0" argument(s): "Error:"unauthorized_client", Description:"Unauthorized", Uri:"""

疑问

为何请求的权限范围未全部生效?是否有遗漏的配置步骤?

内容的提问来源于stack exchange,提问作者shaddow

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 06:28:13