You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

无浏览器PC端OOB授权被封禁,求当前Google OAuth授权流程

适配Google Photos Library API的新授权流程

Google已全面禁用OOB(Out-of-Band)授权流程,你需要根据运行环境选择以下两种适配方案:

方案一:本地桌面/带浏览器环境(推荐)

1. 前置配置

在Google Cloud控制台的OAuth 2.0客户端ID设置中,添加http://localhost:8080作为已授权的重定向URI(端口可自定义,需和代码保持一致)。

2. 代码修改(升级到维护中的新库)

旧的oauth2client库已停止维护,建议替换为google-auth系列库,适配后的代码如下:

import os
from google.auth.transport.requests import Request
from google.oauth2.credentials import Credentials
from google_auth_oauthlib.flow import InstalledAppFlow
from googleapiclient.discovery import build
from googleapiclient.errors import HttpError

def get_authenticated_service(self):
    SCOPES = ['https://www.googleapis.com/auth/photoslibrary']
    TOKEN_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'token-oauth2.json')
    CREDS_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), CLIENT_SECRET_FILE)

    creds = None
    # 加载已保存的凭据
    if os.path.exists(TOKEN_FILE):
        creds = Credentials.from_authorized_user_file(TOKEN_FILE, SCOPES)
    
    # 无有效凭据时重新授权
    if not creds or not creds.valid:
        if creds and creds.expired and creds.refresh_token:
            creds.refresh(Request())
        else:
            flow = InstalledAppFlow.from_client_secrets_file(
                CREDS_FILE, SCOPES,
                redirect_uri='http://localhost:8080'  # 和控制台配置一致
            )
            creds = flow.run_local_server(port=8080)  # 启动本地服务器接收回调
        
        # 保存凭据供下次使用
        with open(TOKEN_FILE, 'w') as token:
            token.write(creds.to_json())
    
    self.token = creds.token
    return build('photoslibrary', 'v1', credentials=creds)

授权流程说明

  • 运行代码后会自动打开默认浏览器,跳转至Google授权页面
  • 用户完成授权后,浏览器自动跳转到本地http://localhost:8080,代码会自动捕获授权码并生成凭据
  • 凭据会保存到token-oauth2.json,下次启动无需重复授权

方案二:无界面服务器/无浏览器环境

如果代码运行在无浏览器的服务器上,可使用设备授权流程:

1. 代码示例

import os
from google.auth.transport.requests import Request
from google.oauth2.credentials import Credentials
from google_auth_oauthlib.flow import Flow
from googleapiclient.discovery import build
from googleapiclient.errors import HttpError

def get_authenticated_service(self):
    SCOPES = ['https://www.googleapis.com/auth/photoslibrary']
    TOKEN_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), 'token-oauth2.json')
    CREDS_FILE = os.path.join(os.path.dirname(os.path.abspath(__file__)), CLIENT_SECRET_FILE)

    creds = None
    if os.path.exists(TOKEN_FILE):
        creds = Credentials.from_authorized_user_file(TOKEN_FILE, SCOPES)
    
    if not creds or not creds.valid:
        if creds and creds.expired and creds.refresh_token:
            creds.refresh(Request())
        else:
            flow = Flow.from_client_secrets_file(
                CREDS_FILE,
                scopes=SCOPES,
                redirect_uri='urn:ietf:wg:oauth:2.0:oob'  # 设备流程需保留此URI,需在控制台配置为"其他"类型客户端
            )
            # 启动设备授权流程
            auth_url, state = flow.authorization_url(prompt='consent')
            print(f"请在任意设备的浏览器中打开此链接: {auth_url}")
            print("输入页面显示的授权码:")
            code = input().strip()
            
            flow.fetch_token(code=code)
            creds = flow.credentials
            
            with open(TOKEN_FILE, 'w') as token:
                token.write(creds.to_json())
    
    self.token = creds.token
    return build('photoslibrary', 'v1', credentials=creds)

注意事项

  • 需在Google Cloud控制台创建其他类型的OAuth客户端ID(而非桌面应用)
  • 授权时,用户需在任意带浏览器的设备上打开打印的链接,将页面显示的授权码输入到终端完成验证

关键说明

  • 无论哪种方案,都必须在Google Cloud控制台正确配置重定向URI,否则会触发授权错误
  • 旧的oauth2client库已停止更新,建议尽快迁移到google-auth系列库,避免后续兼容性问题

内容的提问来源于stack exchange,提问作者LA_

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 06:31:08