Google OAuth2客户端密钥JSON文件无效问题排查求助
OAuth 2.0配置报错:Invalid client secret JSON file
问题详情
我创建了OAuth 2.0 Client IDs,下载的JSON配置如下:
{ "web": { "client_id": "topsecretstuff.apps.googleusercontent.com", "project_id": "health-42", "auth_uri": "https://accounts.google.com/o/oauth2/auth", "token_uri": "https://oauth2.googleapis.com/token", "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs", "client_secret": "GOCSPX-topsecretstuff", "redirect_uris": [ "https://topsecret.domain.tld/oauth2callback.php", "https://topsecret.domain.tld/googlelogin.php" ] } }
使用以下PHP代码配置OAuth认证:
$client = new Google\Client(); $authfile = 'somepath/client_secret.json'; $client->setAuthConfig($authfile); $client->setRedirectUri('https://topsecret.domain.tld/oauth2callback.php'); $client->setAccessType('offline'); // offline access $client->setIncludeGrantedScopes(true); // incremental auth $client->addScope(Google\Service\Fitness::FITNESS_ACTIVITY_READ); $auth_url = $client->createAuthUrl(); header('Location: ' . filter_var($auth_url, FILTER_SANITIZE_URL)); if (isset($_SESSION['access_token']) && $_SESSION['access_token']) { $client->setAccessToken($_SESSION['access_token']); echo "已登录,访问令牌:" . $_SESSION['access_token']; } else { $redirect_uri = 'https://topsecret.domain.tld/oauth2callback.php'; header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL)); }
运行时触发错误:
Fatal error: Uncaught Google_Exception: Invalid client secret JSON file. in somepath/lib/vendor/google/apiclient/src/Google/Client.php:171 Stack trace: #0 somepath/client.php(10): Google_Client->setAuthConfig('/somepath...') #1 somepath/googlelogin.php(32): include_once('/somepath...') #2 {main} thrown in somepath/lib/vendor/google/apiclient/src/Google/Client.php on line 171
我查过相关问题,有人建议下载其他类型的JSON文件,但在Google OAuth2配置界面只能看到下载JSON的选项,配置界面显示的是Web类型客户端凭证,下载按钮仅提供JSON格式选项。
排查与解决方案
检查文件路径正确性
确保$authfile的路径无误:- 相对路径要以当前执行的PHP脚本(如googlelogin.php)为基准,而非被引入的client.php;
- 优先使用绝对路径,比如
$authfile = __DIR__ . '/client_secret.json';,避免路径解析偏差。
验证JSON文件完整性
重新下载JSON凭证文件,确保下载过程未中断,文件内容与你提供的一致;也可通过JSON校验工具确认文件格式无语法错误。调整文件权限
确保Web服务器进程(如www-data、apache)拥有读取该JSON文件的权限,可执行chmod 644 somepath/client_secret.json调整权限。手动配置凭证替代文件读取
如果文件读取始终报错,可跳过setAuthConfig,直接手动设置客户端信息:$client->setClientId('topsecretstuff.apps.googleusercontent.com'); $client->setClientSecret('GOCSPX-topsecretstuff'); $client->setAuthUri('https://accounts.google.com/o/oauth2/auth'); $client->setTokenUri('https://oauth2.googleapis.com/token');更新Google API客户端版本
确保使用的google/apiclient是最新版本,执行composer update google/apiclient更新,旧版本可能存在Web类型凭证的兼容问题。
内容的提问来源于stack exchange,提问作者Bas van den Dikkenberg
相关产品推荐
相关产品推荐

