无浏览器PC端OOB授权被封禁,求当前Google OAuth授权流程
适配Google Photos Library API的新授权流程
Google已全面禁用OOB(Out-of-Band)授权流程,你需要根据运行环境选择以下两种适配方案:
方案一:本地桌面/带浏览器环境(推荐)
1. 前置配置
在Google Cloud控制台的OAuth 2.0客户端ID设置中,添加http://localhost:8080作为已授权的重定向URI(端口可自定义,需和代码保持一致)。
2. 代码修改(升级到维护中的新库)
旧的oauth2client库已停止维护,建议替换为google-auth系列库,适配后的代码如下:
import os from google.auth.transport.requests import Request from google.oauth2.credentials import Credentials from google_auth_oauthlib.flow import InstalledAppFlow from googleapiclient.discovery import build from googleapiclient.errors import HttpError def get_authenticated_service(self): SCOPES = ['https://www.googleapis.com/auth/photoslibrary'] TOKEN_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'token-oauth2.json') CREDS_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), CLIENT_SECRET_FILE) creds = None # 加载已保存的凭据 if os.path.exists(TOKEN_FILE): creds = Credentials.from_authorized_user_file(TOKEN_FILE, SCOPES) # 无有效凭据时重新授权 if not creds or not creds.valid: if creds and creds.expired and creds.refresh_token: creds.refresh(Request()) else: flow = InstalledAppFlow.from_client_secrets_file( CREDS_FILE, SCOPES, redirect_uri='http://localhost:8080' # 和控制台配置一致 ) creds = flow.run_local_server(port=8080) # 启动本地服务器接收回调 # 保存凭据供下次使用 with open(TOKEN_FILE, 'w') as token: token.write(creds.to_json()) self.token = creds.token return build('photoslibrary', 'v1', credentials=creds)
授权流程说明
- 运行代码后会自动打开默认浏览器,跳转至Google授权页面
- 用户完成授权后,浏览器自动跳转到本地
http://localhost:8080,代码会自动捕获授权码并生成凭据 - 凭据会保存到
token-oauth2.json,下次启动无需重复授权
方案二:无界面服务器/无浏览器环境
如果代码运行在无浏览器的服务器上,可使用设备授权流程:
1. 代码示例
import os from google.auth.transport.requests import Request from google.oauth2.credentials import Credentials from google_auth_oauthlib.flow import Flow from googleapiclient.discovery import build from googleapiclient.errors import HttpError def get_authenticated_service(self): SCOPES = ['https://www.googleapis.com/auth/photoslibrary'] TOKEN_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'token-oauth2.json') CREDS_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), CLIENT_SECRET_FILE) creds = None if os.path.exists(TOKEN_FILE): creds = Credentials.from_authorized_user_file(TOKEN_FILE, SCOPES) if not creds or not creds.valid: if creds and creds.expired and creds.refresh_token: creds.refresh(Request()) else: flow = Flow.from_client_secrets_file( CREDS_FILE, scopes=SCOPES, redirect_uri='urn:ietf:wg:oauth:2.0:oob' # 设备流程需保留此URI,需在控制台配置为"其他"类型客户端 ) # 启动设备授权流程 auth_url, state = flow.authorization_url(prompt='consent') print(f"请在任意设备的浏览器中打开此链接: {auth_url}") print("输入页面显示的授权码:") code = input().strip() flow.fetch_token(code=code) creds = flow.credentials with open(TOKEN_FILE, 'w') as token: token.write(creds.to_json()) self.token = creds.token return build('photoslibrary', 'v1', credentials=creds)
注意事项
- 需在Google Cloud控制台创建其他类型的OAuth客户端ID(而非桌面应用)
- 授权时,用户需在任意带浏览器的设备上打开打印的链接,将页面显示的授权码输入到终端完成验证
关键说明
- 无论哪种方案,都必须在Google Cloud控制台正确配置重定向URI,否则会触发授权错误
- 旧的
oauth2client库已停止更新,建议尽快迁移到google-auth系列库,避免后续兼容性问题
内容的提问来源于stack exchange,提问作者LA_
相关产品推荐
相关产品推荐

