首次开发YouTube API上传脚本遇OAuth 2 HTTPS安全传输错误求助
解决YouTube API授权时的InsecureTransportError问题
问题背景
首次编写调用YouTube API的视频上传脚本,已设置HTTPS的redirect_uri且client_secrets.json中所有URL均为HTTPS,但输入授权码时触发如下错误:
Traceback (most recent call last): File "uploadtoyoutube2.py", line 90, in <module> upload_video(video_file) File "uploadtoyoutube2.py", line 57, in upload_video youtube = get_authenticated_service() ^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "uploadtoyoutube2.py", line 40, in get_authenticated_service flow.fetch_token(authorization_response=authorization_response) File "\Python\Python311\Lib\site-packages\google_auth_oauthlib\flow.py", line 285, in fetch_token return self.oauth2session.fetch_token(self.client_config["token_uri"], **kwargs) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "Python\Python311\Lib\site-packages\requests_oauthlib\oauth2_session.py", line 244, in fetch_token self._client.parse_request_uri_response( File "Python\Python311\Lib\site-packages\oauthlib\oauth2\rfc6749\clients\web_application.py", line 220, in parse_request_uri_response response = parse_authorization_code_response(uri, state=state) ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ File "Python\Python311\Lib\site-packages\oauthlib\oauth2\rfc6749\parameters.py", line 272, in parse_authorization_code_response raise InsecureTransportError() oauthlib.oauth2.rfc6749.errors.InsecureTransportError: (insecure_transport) OAuth 2 MUST utilize https.
脚本授权部分核心代码:
def get_authenticated_service(): """Gets an authenticated YouTube API service.""" flow = Flow.from_client_secrets_file(client_secrets_file, scopes) flow.redirect_uri = 'https://localhost:8080' authorization_url, state = flow.authorization_url( access_type='offline', include_granted_scopes='true') print('Please go to this URL: {}'.format(authorization_url)) authorization_response = input('Enter the authorization code: ') flow.fetch_token(authorization_response=authorization_response) credentials = flow.credentials return build(api_service_name, api_version, credentials=credentials)
错误原因
你使用的是Web应用类型的OAuth Flow,这类流程要求redirect_uri必须是带有可信SSL证书的HTTPS地址。虽然你设置了https://localhost:8080,但本地localhost的HTTPS通常没有有效的公共SSL证书,OAuth库会判定其为不安全传输,从而抛出错误。
解决方案
方案1:使用桌面应用专用授权流程(推荐)
Google提供InstalledAppFlow,专门为桌面/命令行应用设计,无需手动处理HTTPS证书问题,会自动打开浏览器完成授权,无需手动输入授权码。
修改步骤:
- 补充导入
InstalledAppFlow:
from google_auth_oauthlib.flow import Flow, InstalledAppFlow
- 替换
get_authenticated_service函数:
def get_authenticated_service(): """Gets an authenticated YouTube API service.""" flow = InstalledAppFlow.from_client_secrets_file( client_secrets_file, scopes) # 启动本地服务器自动处理授权回调 credentials = flow.run_local_server(port=8080) return build(api_service_name, api_version, credentials=credentials)
该流程会自动打开浏览器跳转至Google授权页面,授权完成后自动将token返回给本地服务器,无需手动复制授权码,且OAuth库默认信任本地localhost的HTTP传输(仅针对桌面应用场景)。
方案2:临时绕过HTTPS检查(仅开发测试用)
如果坚持使用原有Web Flow,可通过设置环境变量让OAuth库跳过不安全传输检查,但仅适合本地开发测试,绝对不能用于生产环境:
在脚本开头添加:
import os # 仅开发环境使用,生产环境禁止 os.environ['OAUTHLIB_INSECURE_TRANSPORT'] = '1'
额外注意事项
- 确保Google Cloud控制台中,你的OAuth客户端ID类型是桌面应用(而非Web应用),否则可能触发其他授权错误。
- 授权完成后,credentials会自动保存到本地
token.json文件,后续运行脚本无需重复授权。
内容的提问来源于stack exchange,提问作者YTQuiet
相关产品推荐
相关产品推荐

