You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

已授予全域权限仍报错:服务账号无法添加日历参会者

解决Google Calendar服务账号添加参会者的403权限错误

问题背景

  • 使用服务账号创建日历条目正常,调用端点:https://www.googleapis.com/calendar/v3/calendars/%7Bin_creator%7D/events
  • 给已有活动添加参会者时触发403错误,错误信息:

"Service accounts cannot invite attendees without Domain-Wide Delegation of Authority"

  • 添加参会者调用端点:https://www.googleapis.com/calendar/v3/calendars/%7BOwner%7D/events/%7Bmeeting_id%7D({Owner}为日历实际所有者,非服务账号)

已配置的权限与调用信息

  • 作为Google Workspace管理员,已给服务账号配置全域权限委托,权限范围:
    • https://googleapis.com/auth/calendar
    • https://googleapis.com/auth/calendar.events
    • https://googleapis.com/auth/admin.directory.resource.calendar
  • 日历所有者已给服务账号授予「Make Changes Event」权限
  • 请求访问令牌的JWT内容:
{
  "iss": "xxxxxx.gserviceaccount.com",
  "scope": "https://www.googleapis.com/auth/calendar https://googleapis.com/auth/calendar.events https://googleapis.com/auth/admin.directory.resource.calendar",
  "aud": "https://oauth2.googleapis.com/token",
  "exp": "{exp}",
  "iat": "{iat}"
}
  • Oracle PL/SQL/Apex调用代码:
apex_web_service.make_rest_request(
  p_url => t_url, 
  p_http_method => 'POST', 
  p_body => t_json_in, 
  p_parm_name => apex_util.string_to_table(
    'conferenceDataVersion:supportsAttachments:maxAttendees:sendNotifications:sendUpdates'
  ), 
  p_parm_value => apex_util.string_to_table('1:True:12:False:False')
);
-- 变量说明:
-- t_url: 目标端点,格式为 https://www.googleapis.com/calendar/v3/calendars/{Owner}/events/{meeting_id}
-- t_json_in: 包含活动完整数据的JSON变量

解决方案

1. 在JWT中添加模拟用户参数

服务账号必须模拟日历所有者的身份发起请求,否则会被判定为自身操作,无法添加参会者。需在JWT中加入sub字段,值为日历所有者的邮箱:

{
  "iss": "xxxxxx.gserviceaccount.com",
  "scope": "https://www.googleapis.com/auth/calendar https://googleapis.com/auth/calendar.events https://googleapis.com/auth/admin.directory.resource.calendar",
  "aud": "https://oauth2.googleapis.com/token",
  "exp": "{exp}",
  "iat": "{iat}",
  "sub": "calendar-owner@your-domain.com"
}

2. 修正请求方法

修改已有活动需使用PATCH增量更新,而非创建新活动的POST方法。调整PL/SQL代码的请求方法:

apex_web_service.make_rest_request(
  p_url => t_url, 
  p_http_method => 'PATCH', 
  p_body => t_json_in, 
  p_parm_name => apex_util.string_to_table(
    'conferenceDataVersion:supportsAttachments:maxAttendees:sendNotifications:sendUpdates'
  ), 
  p_parm_value => apex_util.string_to_table('1:True:12:False:False')
);

同时请求体t_json_in只需包含attendees字段的更新内容,无需传递完整活动数据。

3. 验证全域权限委托配置

  • 登录Google Workspace Admin控制台,进入「安全」→「API控制」→「域宽权限委托」
  • 确认服务账号的权限范围无拼写错误,且状态为已授权
  • 确保权限覆盖日历所有者所在的域或组织单元

4. 检查权限范围一致性

确保JWT中的scope字段与全域委托界面配置的权限范围完全一致,避免遗漏或拼写错误。

验证步骤

  1. 生成带sub字段的新JWT,获取有效访问令牌
  2. 使用PATCH方法调用活动修改端点,传递参会者列表
  3. 检查返回结果,确认参会者成功添加且无403错误

内容的提问来源于stack exchange,提问作者Sacha Bocic

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.04 20:25:23