You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase(GCP)启用邮箱枚举保护时遭遇403错误求助

问题描述

尝试在Firebase项目中配置邮箱枚举保护,按官方文档操作生成AccessToken后,执行以下PATCH请求时收到403错误:

curl -X PATCH -d "{'email_privacy_config':{'enable_improved_email_privacy':"true"}}" \
    -H 'Authorization: Bearer MY_ACCESS_TOKEN_REPLACED_HERE' \
    -H 'Content-Type: application/json' \
    "https://identitytoolkit.googleapis.com/admin/v2/projects/MY_PROJECT_ID_REPLACED_HERE/config?updateMask=email_privacy_config"

错误详情:

{
  "error": {
    "code": 403,
    "message": "Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell which are not supported by the identitytoolkit.googleapis.com. We recommend configuring the billing/quota_project setting in gcloud or using a service account through the auth/impersonate_service_account setting. For more information about service accounts and how to use them in your application, see https://cloud.google.com/docs/authentication/. If you are getting this error with curl or similar tools, you may need to specify 'X-Goog-User-Project' HTTP header for quota and billing purposes. For more information regarding 'X-Goog-User-Project' header, please check https://cloud.google.com/apis/docs/system-parameters.",
    "status": "PERMISSION_DENIED",
    "details": [
      {
        "@type": "type.googleapis.com/google.rpc.ErrorInfo",
        "reason": "SERVICE_DISABLED",
        "domain": "googleapis.com",
        "metadata": {
          "consumer": "projects/618104708054",
          "service": "identitytoolkit.googleapis.com"
        }
      }
    ]
  }
}

已确认Identity Toolkit API已启用,添加X-Goog-User-Project请求头后问题仍存在,当前AccessToken通过Google Cloud SDK生成。

解决方案

问题核心是Identity Toolkit Admin API不支持终端用户凭证(即gcloud默认关联的个人Google账号)认证,必须使用服务账号凭证。按以下步骤操作:

1. 创建并配置服务账号

  • 登录GCP控制台,进入IAM与Admin > 服务账号页面
  • 点击创建服务账号,填写名称和描述后完成创建
  • 为该服务账号分配权限:添加Identity Toolkit Admin角色(或更细粒度的identitytoolkit.config.update权限)
  • 进入服务账号的密钥标签页,选择添加密钥 > 创建新密钥,选择JSON格式并下载密钥文件到本地

2. 使用服务账号生成AccessToken

方法一:通过gcloud命令快速生成

# 激活服务账号
gcloud auth activate-service-account --key-file=/path/to/your-service-account-key.json

# 生成并输出AccessToken
gcloud auth print-access-token

方法二:直接调用OAuth2 Token端点(无需gcloud)

需提前安装openssl工具,替换以下变量后执行:

SERVICE_ACCOUNT_EMAIL="你的服务账号邮箱"
PROJECT_ID="你的项目ID"
KEY_FILE="/path/to/你的服务账号密钥文件.json"

# 构造JWT头部和载荷
HEADER='{"alg":"RS256","typ":"JWT"}'
PAYLOAD=$(cat <<EOF
{
  "iss":"$SERVICE_ACCOUNT_EMAIL",
  "scope":"https://www.googleapis.com/auth/cloud-platform",
  "aud":"https://oauth2.googleapis.com/token",
  "exp":$(($(date +%s) + 3600)),
  "iat":$(date +%s)
}
EOF
)

# 编码头部和载荷
ENCODED_HEADER=$(echo -n "$HEADER" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n')
ENCODED_PAYLOAD=$(echo -n "$PAYLOAD" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n')

# 生成签名
SIGNATURE=$(echo -n "$ENCODED_HEADER.$ENCODED_PAYLOAD" | openssl dgst -sha256 -sign "$KEY_FILE" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n')

# 拼接JWT并请求AccessToken
JWT="$ENCODED_HEADER.$ENCODED_PAYLOAD.$SIGNATURE"
curl -X POST "https://oauth2.googleapis.com/token" \
  -H "Content-Type: application/x-www-form-urlencoded" \
  -d "grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=$JWT"

执行后会返回包含access_token的JSON,提取该值即可使用。

3. 修正PATCH请求的JSON格式

原请求的JSON存在语法错误(混用单双引号、布尔值被错误转为字符串),修正后的curl命令如下:

curl -X PATCH -d '{"email_privacy_config":{"enable_improved_email_privacy":true}}' \
    -H 'Authorization: Bearer 服务账号生成的AccessToken' \
    -H 'Content-Type: application/json' \
    "https://identitytoolkit.googleapis.com/admin/v2/projects/你的项目ID/config?updateMask=email_privacy_config"

4. 验证权限配置

进入GCP控制台的IAM页面,搜索服务账号邮箱,确认已正确分配Identity Toolkit Admin或对应权限角色。

内容的提问来源于stack exchange,提问作者Gustavo Steinmetz

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.03 12:51:56