已授予角色调用Cloud Function仍出现401未授权错误求助
Cloud Function跨调用401授权问题求助
我尝试自行解决该问题但未果。创建了一个简单的1st gen Cloud Function(命名为function-test-3),部署后又创建另一个Cloud Function(doom-function-2),希望通过requests请求的Header传递授权参数调用前者,但调用时出现401错误。已为调用方和被调用方的服务账号授予Owner、Cloud Functions Invoker、Cloud Functions Admin等多个角色,问题仍未解决。
若通过CLI生成ID Token并手动粘贴到请求Header中则可正常调用,希望无需使用JSON文件即可解决该问题,恳请提供思路。
被调用方(function-test-3)代码
def hello_world(request): return 'Hello World'
调用方(doom-function-2)代码
import google.oauth2.id_token import google.auth.transport.requests import requests endpoint = 'https://us-central1-sport-app-395020.cloudfunctions.net/function-test-3' def make_authorized_get_request(endpoint): auth_req = google.auth.transport.requests.Request() id_token = google.oauth2.id_token.fetch_id_token(auth_req, endpoint) header_1 = {'Authorization':'Bearer '+id_token} response = requests.get(url=endpoint,headers=header_1) return str(response.content)
补充配置信息
服务账号ID
new-service-account@sport-app-395020.iam.gserviceaccount.com
function-test-3描述信息
availableMemoryMb: 256 buildId: d638badd-4a78-41f7-bb95-9a7c97561e0b buildName: projects/445319123164/locations/us-central1/builds/d638badd-4a78-41f7-bb95-9a7c97561e0b dockerRegistry: CONTAINER_REGISTRY entryPoint: hello_world httpsTrigger: securityLevel: SECURE_OPTIONAL url: https://us-central1-sport-app-395020.cloudfunctions.net/function-test-3 ingressSettings: ALLOW_ALL labels: deployment-tool: console-cloud maxInstances: 3000 name: projects/sport-app-395020/locations/us-central1/functions/function-test-3 runtime: python310 serviceAccountEmail: new-service-account@sport-app-395020.iam.gserviceaccount.com sourceUploadUrl: https://storage.googleapis.com/uploads-890291164480.us-central1.cloudfunctions.appspot.com/d00981be-b7cb-42b9-b443-85b7d1f0c29b.zip status: ACTIVE timeout: 60s updateTime: '2023-08-09T01:11:03.263Z' versionId: '3'
function-test-3 IAM策略
bindings: - members: - serviceAccount:sport-app-395020@appspot.gserviceaccount.com role: roles/cloudfunctions.admin - members: - serviceAccount:new-service-account@sport-app-395020.iam.gserviceaccount.com - serviceAccount:sport-app-395020@appspot.gserviceaccount.com role: roles/cloudfunctions.invoker etag: BwYCcvpm7fc= version: 1
doom-function-2描述信息
availableMemoryMb: 256 buildId: 669735af-ecb6-47de-b57b-a01119eed5b7 buildName: projects/445319123164/locations/us-central1/builds/669735af-ecb6-47de-b57b-a01119eed5b7 dockerRegistry: CONTAINER_REGISTRY entryPoint: make_authorized_get_request httpsTrigger: securityLevel: SECURE_OPTIONAL url: https://us-central1-sport-app-395020.cloudfunctions.net/doom-function-2 ingressSettings: ALLOW_ALL labels: deployment-tool: console-cloud maxInstances: 3000 name: projects/sport-app-395020/locations/us-central1/functions/doom-function-2 runtime: python310 serviceAccountEmail: new-service-account@sport-app-395020.iam.gserviceaccount.com sourceUploadUrl: https://storage.googleapis.com/uploads-890291164480.us-central1.cloudfunctions.appspot.com/c1312040-cb2c-4532-ad15-c33d637bb8d3.zip status: ACTIVE timeout: 60s updateTime: '2023-08-09T01:08:10.996Z' versionId: '29'
doom-function-2 IAM策略
bindings: - members: - allUsers - serviceAccount:sport-app-395020@appspot.gserviceaccount.com role: roles/cloudfunctions.invoker etag: BwYCYOllrBQ= version: 1
实际错误信息
Error: Unauthorized
Your client does not have permission to the requested URL function-test-3
生成的Token内容(JWT解码后)
{ "header": { "alg": "RS256", "kid": "911e39e27928ae9f1e9d1e21646de92d19351b44", "typ": "JWT" }, "payload": { "aud": "<Request 'http://us-central1-sport-app-395020.cloudfunctions.net/' [GET]>", "azp": "113939113937084571622", "email": "new-service-account@sport-app-395020.iam.gserviceaccount.com", "email_verified": true, "exp": 1691553146, "iat": 1691549546, "iss": "https://accounts.google.com", "sub": "113939113937084571622" } }
内容的提问来源于stack exchange,提问作者Rafael Pabon
相关产品推荐
相关产品推荐

