使用PSGSuite时OAuth2 Token缺失权限范围的原因排查
Google Workspace测试域用户列表获取权限异常问题
操作场景与已完成步骤
- 已创建Google Cloud项目并启用Admin API,在OAuth2同意屏幕中配置了代码指定的全部权限范围;授权流程正常,仅当权限范围变更时才会触发重新授权弹窗。
- 执行的PowerShell代码如下:
Import-Module -Name PSGSuite -- 已移除配置行 $Scopes = "https://www.googleapis.com/auth/cloud-platform, https://www.googleapis.com/auth/admin.directory.user, https://www.googleapis.com/auth/admin.directory.user.readonly https://apps-apis.google.com/a/feeds/emailsettings/2.0/, https://mail.google.com/, https://www.google.com/m8/feeds/contacts, https://www.googleapis.com/auth/admin.directory.group, https://www.googleapis.com/auth/admin.directory.resource.calendar, https://www.googleapis.com/auth/admin.directory.rolemanagement, https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly, https://www.googleapis.com/auth/admin.directory.user, https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.user.security, https://www.googleapis.com/auth/admin.directory.userschema, https://www.googleapis.com/auth/admin.reports.audit.readonly, https://www.googleapis.com/auth/admin.reports.usage.readonly, https://www.googleapis.com/auth/apps.groups.settings, https://www.googleapis.com/auth/gmail.settings.basic, https://www.googleapis.com/auth/gmail.settings.sharing, https://www.googleapis.com/auth/plus.login, https://www.googleapis.com/auth/plus.me, https://www.googleapis.com/auth/tasks, https://www.googleapis.com/auth/tasks.readonly, https://www.googleapis.com/auth/userinfo.email, https://www.googleapis.com/auth/userinfo.profile" $Token = Get-GSToken -Scopes $Scopes -AdminEmail "已移除" Write-Host "$($Token)" Get-GSUser -Filter *
异常现象
- 权限范围不匹配:获取Token后,通过
https://www.googleapis.com/oauth2/v1/tokeninfo?access_token=查询,返回的权限范围远少于请求的范围,返回结果如下:
{ "issued_to": "已移除,与应用配置一致且正确", "audience": "已移除,与应用配置一致且正确", "scope": "https://mail.google.com https://www.google.com/m8/feeds https://www.googleapis.com/auth/calendar https://www.googleapis.com/auth/drive https://www.googleapis.com/auth/gmail.settings.basic https://www.googleapis.com/auth/gmail.settings.sharing https://www.googleapis.com/auth/tasks https://www.googleapis.com/auth/tasks.readonly", "expires_in": 3549, "access_type": "offline" }
- 执行
Get-GSUser报错:
Get-GSUser : Exception calling "Execute" with "0" argument(s): "Error:"unauthorized_client", Description:"Unauthorized", Uri:"""
疑问
为何请求的权限范围未全部生效?是否有遗漏的配置步骤?
内容的提问来源于stack exchange,提问作者shaddow
相关产品推荐
相关产品推荐

