能否用Gmail账号密码替代Google凭证在SpringBoot中下载Drive文件?
关于Google Drive文件下载的凭证问题及解决方案
一、能不能用Gmail账号密码绕过凭证验证?
不行。Google早已禁用通过用户名+密码直接调用Drive API的验证方式,所有API调用必须使用OAuth 2.0或服务账号这类官方认可的凭证机制,目的是避免密码泄露、提升账号安全性。
二、可行的解决方案
针对你下载自己Drive文件的需求,推荐两种适配不同场景的方案:
方案1:OAuth2交互式授权(适合个人手动触发场景)
这种方式需要首次运行时通过浏览器完成账号授权,授权凭证会自动保存,后续可直接使用。
修改你的代码如下:
import com.google.api.client.auth.oauth2.Credential; import com.google.api.client.extensions.java6.auth.oauth2.AuthorizationCodeInstalledApp; import com.google.api.client.extensions.jetty.auth.oauth2.LocalServerReceiver; import com.google.api.client.googleapis.auth.oauth2.GoogleAuthorizationCodeFlow; import com.google.api.client.googleapis.auth.oauth2.GoogleClientSecrets; import com.google.api.client.googleapis.javanet.GoogleNetHttpTransport; import com.google.api.client.json.gson.GsonFactory; import com.google.api.client.util.store.FileDataStoreFactory; import com.google.api.services.drive.Drive; import com.google.api.services.drive.DriveScopes; import java.io.FileInputStream; import java.io.IOException; import java.io.InputStreamReader; import java.util.Arrays; public static ByteArrayOutputStream downloadFile(String fileId) throws IOException { // 加载OAuth客户端配置文件(从Google Cloud控制台下载的client_secret.json) GoogleClientSecrets clientSecrets = GoogleClientSecrets.load( GsonFactory.getDefaultInstance(), new InputStreamReader(new FileInputStream("client_secret.json")) ); // 创建授权流程 GoogleAuthorizationCodeFlow flow = new GoogleAuthorizationCodeFlow.Builder( GoogleNetHttpTransport.newTrustedTransport(), GsonFactory.getDefaultInstance(), clientSecrets, Arrays.asList(DriveScopes.DRIVE_FILE) // 遵循最小权限原则,仅请求文件访问权限 ).setDataStoreFactory(new FileDataStoreFactory(new java.io.File("tokens"))) .setAccessType("offline") // 允许离线访问,获取刷新令牌 .build(); // 启动本地服务器接收授权码 Credential credential = new AuthorizationCodeInstalledApp( flow, new LocalServerReceiver()).authorize("user"); // 构建Drive服务实例 Drive service = new Drive.Builder( GoogleNetHttpTransport.newTrustedTransport(), GsonFactory.getDefaultInstance(), credential ).setApplicationName("Drive File Downloader").build(); // 执行文件下载 try (ByteArrayOutputStream outputStream = new ByteArrayOutputStream()) { service.files().get(fileId).executeMediaAndDownloadTo(outputStream); return outputStream; } catch (com.google.api.client.googleapis.json.GoogleJsonResponseException e) { System.err.println("无法下载文件: " + e.getDetails()); throw e; } }
操作步骤:
- 登录Google Cloud控制台,创建新项目并启用Google Drive API
- 创建OAuth客户端ID(类型选「桌面应用」),下载
client_secret.json放到项目根目录 - 首次运行代码时,会自动打开浏览器,登录你的Gmail账号完成授权;授权后项目下会生成
tokens目录保存凭证,后续无需重复授权
方案2:服务账号授权(适合后台自动运行场景)
如果程序需要在后台自动下载、无需用户交互,可以使用服务账号。
修改代码如下:
import com.google.api.client.googleapis.javanet.GoogleNetHttpTransport; import com.google.api.client.json.gson.GsonFactory; import com.google.api.services.drive.Drive; import com.google.api.services.drive.DriveScopes; import com.google.auth.http.HttpCredentialsAdapter; import com.google.auth.oauth2.ServiceAccountCredentials; import java.io.FileInputStream; import java.io.IOException; import java.util.Arrays; public static ByteArrayOutputStream downloadFile(String fileId) throws IOException { // 加载服务账号密钥文件(从Google Cloud控制台下载的json文件) ServiceAccountCredentials credentials = ServiceAccountCredentials.fromStream( new FileInputStream("service_account_key.json") ).createScoped(Arrays.asList(DriveScopes.DRIVE_FILE)); // 构建Drive服务实例 Drive service = new Drive.Builder( GoogleNetHttpTransport.newTrustedTransport(), GsonFactory.getDefaultInstance(), new HttpCredentialsAdapter(credentials) ).setApplicationName("Drive Service Account Downloader").build(); // 执行文件下载 try (ByteArrayOutputStream outputStream = new ByteArrayOutputStream()) { service.files().get(fileId).executeMediaAndDownloadTo(outputStream); return outputStream; } catch (com.google.api.client.googleapis.json.GoogleJsonResponseException e) { System.err.println("无法下载文件: " + e.getDetails()); throw e; } }
操作步骤:
- 在Google Cloud控制台创建服务账号,下载密钥文件
service_account_key.json - 把需要下载的Drive文件共享给服务账号的邮箱(密钥文件中
client_email字段的值),权限设为「查看者」即可
内容的提问来源于stack exchange,提问作者Neela
相关产品推荐
相关产品推荐

