Rails集成Google OAuth2获取Google Group信息时groups为nil的问题排查
解决OmniAuth Google OAuth2获取groups为nil的问题
检查Google Cloud项目API启用状态
admin.directory.group.readonly权限依赖Admin SDK API,必须先在Google Cloud控制台中找到对应项目,启用Admin SDK API。同时要确认OAuth客户端已在Google Workspace管理控制台中被授权访问目录API权限。修正权限范围格式
虽然逗号分隔带空格不影响功能,但统一用空格分隔更规范:Rails.application.config.middleware.use OmniAuth::Builder do provider :google_oauth2, 'CLIENT_ID', 'CLIENT_SECRET', scope: 'email https://www.googleapis.com/auth/admin.directory.group.readonly' end调整群组数据获取方式
auth.extra.raw_info不会直接返回groups数据,需要通过授权后的access_token调用Admin SDK的Groups API获取。修改SessionsController代码:class SessionsController < ApplicationController def create auth = request.env['omniauth.auth'] access_token = auth.credentials.token # 引入Google API客户端 require 'google/apis/admin_directory_v1' directory = Google::Apis::AdminDirectoryV1::DirectoryService.new directory.authorization = Google::Auth::UserRefreshCredentials.new( client_id: 'CLIENT_ID', client_secret: 'CLIENT_SECRET', refresh_token: auth.credentials.refresh_token, scope: ['https://www.googleapis.com/auth/admin.directory.group.readonly'] ) # 获取当前用户所属群组 groups = directory.list_groups(user_key: auth.info.email) # 处理群组数据 # ... end end注意:需要在Gemfile中添加
google-api-client,执行bundle install安装依赖。验证用户权限与授权流程
确保登录用户是Google Workspace成员,且拥有群组目录读取权限(普通用户默认具备,若被管理员限制需调整);同时确认授权流程中用户已同意"查看您Google Workspace中的群组"权限请求。
内容的提问来源于stack exchange,提问作者Shrikanth Hathwar
相关产品推荐
相关产品推荐

