You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已授予角色调用Cloud Function仍出现401未授权错误求助

Cloud Function跨调用401授权问题求助

我尝试自行解决该问题但未果。创建了一个简单的1st gen Cloud Function(命名为function-test-3),部署后又创建另一个Cloud Function(doom-function-2),希望通过requests请求的Header传递授权参数调用前者,但调用时出现401错误。已为调用方和被调用方的服务账号授予Owner、Cloud Functions Invoker、Cloud Functions Admin等多个角色,问题仍未解决。

若通过CLI生成ID Token并手动粘贴到请求Header中则可正常调用,希望无需使用JSON文件即可解决该问题,恳请提供思路。

被调用方(function-test-3)代码

def hello_world(request): 
    return 'Hello World'

调用方(doom-function-2)代码

import google.oauth2.id_token
import google.auth.transport.requests
import requests

endpoint = 'https://us-central1-sport-app-395020.cloudfunctions.net/function-test-3'

def make_authorized_get_request(endpoint):
    auth_req = google.auth.transport.requests.Request()
    id_token = google.oauth2.id_token.fetch_id_token(auth_req, endpoint)
    header_1 = {'Authorization':'Bearer '+id_token}
    response = requests.get(url=endpoint,headers=header_1)
    return str(response.content)

补充配置信息

服务账号ID

new-service-account@sport-app-395020.iam.gserviceaccount.com

function-test-3描述信息

availableMemoryMb: 256
buildId: d638badd-4a78-41f7-bb95-9a7c97561e0b
buildName: projects/445319123164/locations/us-central1/builds/d638badd-4a78-41f7-bb95-9a7c97561e0b
dockerRegistry: CONTAINER_REGISTRY
entryPoint: hello_world
httpsTrigger:
  securityLevel: SECURE_OPTIONAL
  url: https://us-central1-sport-app-395020.cloudfunctions.net/function-test-3
ingressSettings: ALLOW_ALL
labels:
  deployment-tool: console-cloud
  maxInstances: 3000
  name: projects/sport-app-395020/locations/us-central1/functions/function-test-3
  runtime: python310
serviceAccountEmail: new-service-account@sport-app-395020.iam.gserviceaccount.com
sourceUploadUrl: https://storage.googleapis.com/uploads-890291164480.us-central1.cloudfunctions.appspot.com/d00981be-b7cb-42b9-b443-85b7d1f0c29b.zip
status: ACTIVE
timeout: 60s
updateTime: '2023-08-09T01:11:03.263Z'
versionId: '3'

function-test-3 IAM策略

bindings:
- members:
  - serviceAccount:sport-app-395020@appspot.gserviceaccount.com
  role: roles/cloudfunctions.admin
- members:
  - serviceAccount:new-service-account@sport-app-395020.iam.gserviceaccount.com
  - serviceAccount:sport-app-395020@appspot.gserviceaccount.com
  role: roles/cloudfunctions.invoker
etag: BwYCcvpm7fc=
version: 1

doom-function-2描述信息

availableMemoryMb: 256
buildId: 669735af-ecb6-47de-b57b-a01119eed5b7
buildName: projects/445319123164/locations/us-central1/builds/669735af-ecb6-47de-b57b-a01119eed5b7
dockerRegistry: CONTAINER_REGISTRY
entryPoint: make_authorized_get_request
httpsTrigger:
  securityLevel: SECURE_OPTIONAL
  url: https://us-central1-sport-app-395020.cloudfunctions.net/doom-function-2
ingressSettings: ALLOW_ALL
labels:
  deployment-tool: console-cloud
maxInstances: 3000
name: projects/sport-app-395020/locations/us-central1/functions/doom-function-2
runtime: python310
serviceAccountEmail: new-service-account@sport-app-395020.iam.gserviceaccount.com
sourceUploadUrl: https://storage.googleapis.com/uploads-890291164480.us-central1.cloudfunctions.appspot.com/c1312040-cb2c-4532-ad15-c33d637bb8d3.zip
status: ACTIVE
timeout: 60s
updateTime: '2023-08-09T01:08:10.996Z'
versionId: '29'

doom-function-2 IAM策略

bindings:
- members:
  - allUsers
  - serviceAccount:sport-app-395020@appspot.gserviceaccount.com
  role: roles/cloudfunctions.invoker
etag: BwYCYOllrBQ=
version: 1

实际错误信息

Error: Unauthorized
Your client does not have permission to the requested URL function-test-3

生成的Token内容(JWT解码后)

{
    "header": {
        "alg": "RS256",
        "kid": "911e39e27928ae9f1e9d1e21646de92d19351b44",
        "typ": "JWT"
    },
    "payload": {
        "aud": "<Request 'http://us-central1-sport-app-395020.cloudfunctions.net/' [GET]>",
        "azp": "113939113937084571622",
        "email": "new-service-account@sport-app-395020.iam.gserviceaccount.com",
        "email_verified": true,
        "exp": 1691553146,
        "iat": 1691549546,
        "iss": "https://accounts.google.com",
        "sub": "113939113937084571622"
    }
}

内容的提问来源于stack exchange,提问作者Rafael Pabon

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 18:54:51