Firebase(GCP)启用邮箱枚举保护时遭遇403错误求助
问题描述
尝试在Firebase项目中配置邮箱枚举保护,按官方文档操作生成AccessToken后,执行以下PATCH请求时收到403错误:
curl -X PATCH -d "{'email_privacy_config':{'enable_improved_email_privacy':"true"}}" \ -H 'Authorization: Bearer MY_ACCESS_TOKEN_REPLACED_HERE' \ -H 'Content-Type: application/json' \ "https://identitytoolkit.googleapis.com/admin/v2/projects/MY_PROJECT_ID_REPLACED_HERE/config?updateMask=email_privacy_config"
错误详情:
{ "error": { "code": 403, "message": "Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell which are not supported by the identitytoolkit.googleapis.com. We recommend configuring the billing/quota_project setting in gcloud or using a service account through the auth/impersonate_service_account setting. For more information about service accounts and how to use them in your application, see https://cloud.google.com/docs/authentication/. If you are getting this error with curl or similar tools, you may need to specify 'X-Goog-User-Project' HTTP header for quota and billing purposes. For more information regarding 'X-Goog-User-Project' header, please check https://cloud.google.com/apis/docs/system-parameters.", "status": "PERMISSION_DENIED", "details": [ { "@type": "type.googleapis.com/google.rpc.ErrorInfo", "reason": "SERVICE_DISABLED", "domain": "googleapis.com", "metadata": { "consumer": "projects/618104708054", "service": "identitytoolkit.googleapis.com" } } ] } }
已确认Identity Toolkit API已启用,添加X-Goog-User-Project请求头后问题仍存在,当前AccessToken通过Google Cloud SDK生成。
解决方案
问题核心是Identity Toolkit Admin API不支持终端用户凭证(即gcloud默认关联的个人Google账号)认证,必须使用服务账号凭证。按以下步骤操作:
1. 创建并配置服务账号
- 登录GCP控制台,进入IAM与Admin > 服务账号页面
- 点击创建服务账号,填写名称和描述后完成创建
- 为该服务账号分配权限:添加
Identity Toolkit Admin角色(或更细粒度的identitytoolkit.config.update权限) - 进入服务账号的密钥标签页,选择添加密钥 > 创建新密钥,选择JSON格式并下载密钥文件到本地
2. 使用服务账号生成AccessToken
方法一:通过gcloud命令快速生成
# 激活服务账号 gcloud auth activate-service-account --key-file=/path/to/your-service-account-key.json # 生成并输出AccessToken gcloud auth print-access-token
方法二:直接调用OAuth2 Token端点(无需gcloud)
需提前安装openssl工具,替换以下变量后执行:
SERVICE_ACCOUNT_EMAIL="你的服务账号邮箱" PROJECT_ID="你的项目ID" KEY_FILE="/path/to/你的服务账号密钥文件.json" # 构造JWT头部和载荷 HEADER='{"alg":"RS256","typ":"JWT"}' PAYLOAD=$(cat <<EOF { "iss":"$SERVICE_ACCOUNT_EMAIL", "scope":"https://www.googleapis.com/auth/cloud-platform", "aud":"https://oauth2.googleapis.com/token", "exp":$(($(date +%s) + 3600)), "iat":$(date +%s) } EOF ) # 编码头部和载荷 ENCODED_HEADER=$(echo -n "$HEADER" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n') ENCODED_PAYLOAD=$(echo -n "$PAYLOAD" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n') # 生成签名 SIGNATURE=$(echo -n "$ENCODED_HEADER.$ENCODED_PAYLOAD" | openssl dgst -sha256 -sign "$KEY_FILE" | base64 | tr -d '=' | tr '/+' '_-' | tr -d '\n') # 拼接JWT并请求AccessToken JWT="$ENCODED_HEADER.$ENCODED_PAYLOAD.$SIGNATURE" curl -X POST "https://oauth2.googleapis.com/token" \ -H "Content-Type: application/x-www-form-urlencoded" \ -d "grant_type=urn:ietf:params:oauth:grant-type:jwt-bearer&assertion=$JWT"
执行后会返回包含access_token的JSON,提取该值即可使用。
3. 修正PATCH请求的JSON格式
原请求的JSON存在语法错误(混用单双引号、布尔值被错误转为字符串),修正后的curl命令如下:
curl -X PATCH -d '{"email_privacy_config":{"enable_improved_email_privacy":true}}' \ -H 'Authorization: Bearer 服务账号生成的AccessToken' \ -H 'Content-Type: application/json' \ "https://identitytoolkit.googleapis.com/admin/v2/projects/你的项目ID/config?updateMask=email_privacy_config"
4. 验证权限配置
进入GCP控制台的IAM页面,搜索服务账号邮箱,确认已正确分配Identity Toolkit Admin或对应权限角色。
内容的提问来源于stack exchange,提问作者Gustavo Steinmetz
相关产品推荐
相关产品推荐

