Spring Boot调用Google Apps Script接口遇401未授权问题求助
Spring Boot向Google Apps Script发送POST请求遭遇401未授权异常
问题背景
我尝试通过Spring Boot应用向Google Apps Script的函数发送POST请求,但遭遇未授权异常。
Spring Boot控制器代码
@PostMapping("/sendInfo/{id}") public void sendInfoToGoogleAppsScript(@PathVariable Long id) { Object object = objectService.findObjectById(id).get(); String scriptUrl = "https://script.google.com/a/macros/xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx/exec"; RestTemplate restTemplate = new RestTemplate(); HttpHeaders headers = new HttpHeaders(); headers.setContentType(MediaType.APPLICATION_JSON); HttpEntity<Object> objectHttpEntity = new HttpEntity<>(object, headers); restTemplate.exchange( scriptUrl, HttpMethod.POST, objectHttpEntity, String.class ); System.out.println("Data successfully sent to Apps script"); }
注:原代码遗漏
@PathVariable注解,已补充,否则id参数无法正常获取
Google Apps Script代码
function doPost(e) { return ContentService.createTextOutput("Hello World."); }
报错信息
Servlet.service() for servlet [dispatcherServlet] in context with path [] threw exception [Request processing failed: org.springframework.web.client.HttpClientErrorException$Unauthorized: 401 Unauthorized: [no body]] with root cause org.springframework.web.client.HttpClientErrorException$Unauthorized: 401 Unauthorized: [no body] at org.springframework.web.client.HttpClientErrorException.create(HttpClientErrorException.java:106) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.DefaultResponseErrorHandler.handleError(DefaultResponseErrorHandler.java:183) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.DefaultResponseErrorHandler.handleError(DefaultResponseErrorHandler.java:137) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.ResponseErrorHandler.handleError(ResponseErrorHandler.java:63) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.RestTemplate.handleResponse(RestTemplate.java:932) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.RestTemplate.doExecute(RestTemplate.java:881) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.RestTemplate.execute(RestTemplate.java:781) ~[spring-web-6.1.2.jar:6.1.2] at org.springframework.web.client.RestTemplate.exchange(RestTemplate.java:663) ~[spring-web-6.1.2.jar:6.1.2]
已尝试的操作
- 将脚本部署为Web应用
- 设置执行权限为“访问网络的用户”
- 设置访问权限为“组织内任何人”(除了仅自己外无其他可选选项)
- 尝试上述选项的其他组合,但问题仍未解决
解决方案建议
1. 确认Web应用部署权限细节
如果组织政策允许,重新部署Apps Script Web应用时,将执行权限设置为任何人,甚至匿名,这是解决匿名请求未授权最直接的方式。若组织限制该选项,需联系域管理员调整权限策略。
2. 添加OAuth2认证令牌到请求头
若只能限制组织内访问,需在Spring Boot请求中携带Google OAuth2令牌:
- 使用Google服务账号生成令牌,并授予其访问该Apps Script的权限
- 在请求头中添加Bearer令牌:
// 示例:获取服务账号令牌并添加到请求头 String serviceAccountToken = getServiceAccountToken(); // 实现服务账号令牌获取逻辑 headers.setBearerAuth(serviceAccountToken);
3. 验证部署URL有效性
每次重新部署Apps Script Web应用都会生成新的URL,确保使用的是最新的部署链接,而非旧的测试地址。
替代方案
Google Sheets API(若目标是操作表格)
如果需求是读写Google Sheets,直接使用Google Sheets API替代Apps Script Web应用:
- 通过服务账号认证,权限控制更精细
- Spring生态有成熟的客户端库,调用更稳定
Google Cloud Functions
将业务逻辑迁移到Google Cloud Functions:
- 支持HTTP触发,权限设置灵活(可使用API密钥、OAuth2或匿名访问)
- 运行环境更可控,日志和监控更完善
内部中间层转发
若必须使用Apps Script,可在Spring Boot和Apps Script之间添加内部中间服务:
- 中间服务处理认证逻辑(如组织内SSO令牌),再转发请求到Apps Script
- 避免直接暴露Apps Script的权限问题
内容的提问来源于stack exchange,提问作者Lohith
相关产品推荐
相关产品推荐

