创建Google Classroom推送通知注册时遇Missing Grant错误
Google Classroom推送通知注册返回403 @MissingGrant错误求助
已完成以下配置:
- 按照《Classroom API中的推送通知》文档创建了Google Cloud项目、Cloud Pub/Sub主题及对应订阅,给Google Classroom服务账号授予了主题发布权限,项目和Pub/Sub主题归属公司主组织,本人拥有该组织超级管理员权限
- 为Google Cloud项目创建了服务账号,按照《使用OAuth 2.0实现服务器到服务器应用》文档在Google Admin Console中为其分配了包含
classroom.push-notifications在内的Classroom权限范围
使用Python 3.8 + google-api-python-client 1.7.3版本,通过该服务账号调用API获取课程、作业等资源完全正常,但创建推送通知注册时返回如下403错误:
<HttpError 403 when requesting https://classroom.googleapis.com/v1/registrations?alt=json returned "@MissingGrant Using this feature requires the appropriate scopes to be granted to your application using OAuth. In particular, domain-wide delegation is not supported.">
补充说明:
- Cloud Console中该服务账号的高级设置里没有启用/禁用域范围委派的选项,根据之前看到的Stack Overflow帖子,在Admin Console分配权限范围后该功能会自动启用
- 已在Google Admin Console的“域范围委派”部分为服务账号分配以下权限范围:
https://www.googleapis.com/auth/classroom.courses.readonly https://www.googleapis.com/auth/classroom.rosters.readonly https://www.googleapis.com/auth/classroom.student-submissions.students.readonly https://www.googleapis.com/auth/classroom.push-notifications https://www.googleapis.com/auth/cloud-platform https://www.googleapis.com/auth/pubsub
请求参数(已移除隐私信息)如下,未包含registrationId(文档说明由Google设置,刷新现有注册除外,提供的值会被覆盖),时间戳格式符合文档要求,参数结构匹配文档:
params: { 'body': { 'registrationId': None, 'feed': { 'feedType': 'DOMAIN_ROSTER_CHANGES', 'courseWorkChangesInfo': { 'courseId': <courseId string for a Google Classroom I created> } }, 'cloudPubsubTopic': { 'topicName': <topic name string copy/pasted from the topic in my Google Cloud Console> }, 'expiryTime': '2023-10-10T19:04:56.725983+00:00' } }
已排查情况:
- 《使用OAuth 2.0实现服务器到服务器应用》文档末尾的常见错误说明里没有提及此@MissingGrant错误
- 未找到相关Stack Overflow帖子、Github问题或Google Classroom文档对该错误的说明
- 已联系Google开发者支持,但预计等待时间较长
请问有没有人遇到过这个问题?如何解决?或者有相关参考资源可以提供吗?
内容的提问来源于stack exchange,提问作者lawrencek1992
相关产品推荐
相关产品推荐

