You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中通过application.yml配置Google服务账号JSON密钥凭证

Google服务账号API凭证配置(从application.yml读取JSON密钥)

1. 修正application.yml格式

你提供的yml配置里有多余的逗号,而且私钥带换行,需要用|保留格式,否则会读取失败,修正后如下:

google-drive:
  type: "service_account"
  project_id: "xx-387809"
  private_key_id: "xxxxxxx"
  private_key: |
    -----BEGIN PRIVATE KEY-----
    xxxxxxx
    -----END PRIVATE KEY-----
  client_email: "xxxxx-387809.iam.gserviceaccount.com"
  client_id: "00000000"
  auth_uri: "https://accounts.google.com/o/oauth2/auth"
  token_uri: "https://oauth2.googleapis.com/token"
  auth_provider_x509_cert_url: "https://www.googleapis.com/oauth2/v1/certs"
  client_x509_cert_url: "https://www.googleapis.com/robot/v1/metadata/x509/xxxxxxx-387809.iam.gserviceaccount.com"
  universe_domain: "googleapis.com"

2. 创建配置类绑定yml参数

用Spring的配置绑定功能,把yml里的参数映射到实体类,方便后续注入使用:

import org.springframework.boot.context.properties.ConfigurationProperties;
import org.springframework.stereotype.Component;

@Component
@ConfigurationProperties(prefix = "google-drive")
public class GoogleDriveProperties {
    private String type;
    private String projectId;
    private String privateKeyId;
    private String privateKey;
    private String clientEmail;
    private String clientId;
    private String authUri;
    private String tokenUri;
    private String authProviderX509CertUrl;
    private String clientX509CertUrl;
    private String universeDomain;

    // 生成所有字段的Getter和Setter
    public String getType() { return type; }
    public void setType(String type) { this.type = type; }
    public String getProjectId() { return projectId; }
    public void setProjectId(String projectId) { this.projectId = projectId; }
    public String getPrivateKeyId() { return privateKeyId; }
    public void setPrivateKeyId(String privateKeyId) { this.privateKeyId = privateKeyId; }
    public String getPrivateKey() { return privateKey; }
    public void setPrivateKey(String privateKey) { this.privateKey = privateKey; }
    public String getClientEmail() { return clientEmail; }
    public void setClientEmail(String clientEmail) { this.clientEmail = clientEmail; }
    public String getClientId() { return clientId; }
    public void setClientId(String clientId) { this.clientId = clientId; }
    public String getAuthUri() { return authUri; }
    public void setAuthUri(String authUri) { this.authUri = authUri; }
    public String getTokenUri() { return tokenUri; }
    public void setTokenUri(String tokenUri) { this.tokenUri = tokenUri; }
    public String getAuthProviderX509CertUrl() { return authProviderX509CertUrl; }
    public void setAuthProviderX509CertUrl(String authProviderX509CertUrl) { this.authProviderX509CertUrl = authProviderX509CertUrl; }
    public String getClientX509CertUrl() { return clientX509CertUrl; }
    public void setClientX509CertUrl(String clientX509CertUrl) { this.clientX509CertUrl = clientX509CertUrl; }
    public String getUniverseDomain() { return universeDomain; }
    public void setUniverseDomain(String universeDomain) { this.universeDomain = universeDomain; }
}

3. 修改GoogleCredential构建代码

注入配置类,用yml里的私钥和服务账号信息构建凭证,同时修正原代码的语法错误:

import com.google.api.client.googleapis.auth.oauth2.GoogleCredential;
import com.google.api.client.http.javanet.NetHttpTransport;
import com.google.api.client.json.jackson2.JacksonFactory;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.stereotype.Component;

import java.security.GeneralSecurityException;
import java.util.Collections;

@Component
public class GoogleCredentialProvider {

    private final GoogleDriveProperties driveProperties;

    @Autowired
    public GoogleCredentialProvider(GoogleDriveProperties driveProperties) {
        this.driveProperties = driveProperties;
    }

    public GoogleCredential googleCredential() throws GeneralSecurityException, java.io.IOException {
        return new GoogleCredential.Builder()
                .setTransport(new NetHttpTransport())
                .setJsonFactory(JacksonFactory.getDefaultInstance())
                // 绑定服务账号邮箱(对应JSON密钥的client_email)
                .setServiceAccountId(driveProperties.getClientEmail())
                // 设置Drive权限范围
                .setServiceAccountScopes(Collections.singletonList("https://www.googleapis.com/auth/drive"))
                // 加载yml中的私钥
                .setServiceAccountPrivateKey(
                        GoogleCredential.Builder.getPrivateKeyFromPem(driveProperties.getPrivateKey())
                )
                // 绑定Token请求地址(对应JSON密钥的token_uri)
                .setTokenServerUrl(new com.google.api.client.http.GenericUrl(driveProperties.getTokenUri()))
                .build();
    }
}

关键注意点

  • 私钥必须用|保留换行格式,否则会被解析成单行,导致私钥加载失败。
  • 原代码中new GoogleCredential.Builder()末尾多了一个冗余的),已经删除。
  • 确保项目引入了Google API的核心依赖,比如Maven依赖:
<dependency>
    <groupId>com.google.api-client</groupId>
    <artifactId>google-api-client</artifactId>
    <version>1.34.1</version>
</dependency>

内容的提问来源于stack exchange,提问作者MIM

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.17 09:13:24