You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在GCP API与服务凭据中动态添加JavaScript源和重定向URI

用Java动态修改GCP项目凭据的授权源与重定向URI

可以通过Java代码实现动态添加Authorized JavaScript origins和Authorized redirect URIs,核心是使用Google Cloud IAM API操作OAuth2客户端凭据。你之前的ResourceManager代码仅用于项目管理,要修改凭据需使用专门的IAM服务客户端。

关键步骤与代码示例

1. 添加依赖(Maven)

需要引入Google IAM API的Java客户端库:

<dependency>
  <groupId>com.google.apis</groupId>
  <artifactId>google-api-services-iam</artifactId>
  <version>v1-rev20240209-2.0.0</version>
</dependency>
<dependency>
  <groupId>com.google.oauth-client</groupId>
  <artifactId>google-oauth-client-java6</artifactId>
  <version>1.46.0</version>
</dependency>

2. 实现修改逻辑

以下代码可列出项目下的OAuth2客户端凭据,找到目标后更新授权源和重定向URI:

import com.google.api.services.iam.v1.Iam;
import com.google.api.services.iam.v1.IamScopes;
import com.google.api.services.iam.v1.model.ListOAuth2ClientIdsResponse;
import com.google.api.services.iam.v1.model.OAuth2ClientId;
import com.google.auth.http.HttpCredentialsAdapter;
import com.google.auth.oauth2.GoogleCredentials;

import java.io.IOException;
import java.util.ArrayList;
import java.util.Collections;

public class GcpCredentialsUpdater {
    public static void main(String[] args) throws IOException {
        // 加载默认凭据(优先使用环境变量、服务账号密钥或GCE元数据)
        GoogleCredentials credentials = GoogleCredentials.getApplicationDefault()
                .createScoped(Collections.singleton(IamScopes.CLOUD_PLATFORM));

        // 初始化IAM服务客户端
        Iam iamService = new Iam.Builder(
                com.google.api.client.http.javanet.NetHttpTransport.newTrustedTransport(),
                com.google.api.client.json.gson.GsonFactory.getDefaultInstance(),
                new HttpCredentialsAdapter(credentials))
                .setApplicationName("GCP Credentials Updater")
                .build();

        String projectId = "my-unique-project-id";
        String parentResource = "projects/" + projectId;

        // 列出项目下所有OAuth2客户端凭据
        ListOAuth2ClientIdsResponse credentialsList = iamService.projects().oauth2client().list(parentResource).execute();
        for (OAuth2ClientId targetCredential : credentialsList.getOAuth2ClientIds()) {
            // 匹配你要修改的凭据(可通过client_id或名称筛选)
            if (targetCredential.getClientId().equals("your-target-client-id")) {
                // 新增JavaScript授权源
                ArrayList<String> updatedOrigins = new ArrayList<>(targetCredential.getAuthorizedJavaScriptOrigins());
                updatedOrigins.add("https://new-origin.example.com");
                targetCredential.setAuthorizedJavaScriptOrigins(updatedOrigins);

                // 新增重定向URI
                ArrayList<String> updatedRedirectUris = new ArrayList<>(targetCredential.getAuthorizedRedirectUris());
                updatedRedirectUris.add("https://new-redirect.example.com/callback");
                targetCredential.setAuthorizedRedirectUris(updatedRedirectUris);

                // 提交更新
                iamService.projects().oauth2client()
                        .update(parentResource, targetCredential.getName(), targetCredential)
                        .execute();
                System.out.println("凭据已成功更新");
                break;
            }
        }
    }
}

注意事项

  • 权限要求:执行代码的服务账号需拥有roles/iam.oauthClientEditor或roles/iam.securityAdmin角色,否则无修改凭据的权限。
  • 凭据标识:需提前获取目标凭据的clientId(可在GCP控制台凭据页面查看),或通过名称筛选目标凭据。
  • 依赖版本:建议使用最新版本的Google API客户端库,避免兼容性问题。

相关文档指引

可参考Google Cloud官方文档中以下内容:

  • IAM API的projects.oauth2client.update方法说明,了解参数与请求格式
  • Google Cloud Java客户端库的IAM模块使用指南,掌握客户端初始化与API调用规范

内容的提问来源于stack exchange,提问作者Aamir

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.15 10:15:37