Google登录授权码换取访问令牌及相关Python依赖库安装咨询
Got it, let's tackle your two questions step by step—installing those missing libraries and exchanging the authorization code for an access token.
Installing the Required Libraries
First, a quick heads-up: some of the libraries your tutorial uses (oauth2client, the old apiclient module) are deprecated by Google. They've been replaced with newer, better-maintained tools, but I'll cover both the deprecated setup (to match your tutorial) and the recommended modern approach.
For the tutorial's deprecated libraries:
Run these pip commands to install the missing packages:
# Install httplib2 and oauth2client pip install httplib2 oauth2client # apiclient is part of google-api-python-client pip install google-api-python-client
Recommended modern alternative (better for long-term maintenance):
Google now suggests using google-auth and related packages instead of oauth2client. Install them with:
pip install google-auth google-auth-oauthlib google-auth-httplib2 google-api-python-client
Exchanging Authorization Code for Access Token
Once your user logs in via Google and you receive the authorization code, here's how to turn it into an access token (both old and new methods):
Using the deprecated oauth2client (matches your tutorial)
from oauth2client import client # Replace these with your actual Google Cloud Console credentials CLIENT_ID = "your-client-id-here" CLIENT_SECRET = "your-client-secret-here" REDIRECT_URI = "your-redirect-uri-here" # Must match console setup exactly # Set up the OAuth flow flow = client.OAuth2WebServerFlow( client_id=CLIENT_ID, client_secret=CLIENT_SECRET, scope="openid email profile", # Adjust scopes based on your app's needs redirect_uri=REDIRECT_URI ) # Exchange the authorization code for credentials credentials = flow.step2_exchange(your_authorization_code) # Extract tokens from the credentials object access_token = credentials.access_token refresh_token = credentials.refresh_token # Use this to get new tokens when access token expires expires_in = credentials.expires_in print(f"Access Token: {access_token}")
Using the recommended google-auth-oauthlib (modern approach)
If you switch to the newer libraries, this is the cleaner way to handle the exchange:
from google.oauth2.credentials import Credentials from google_auth_oauthlib.flow import Flow # Path to your client secrets file downloaded from Google Cloud Console CLIENT_SECRETS_FILE = "client_secret.json" REDIRECT_URI = "your-redirect-uri-here" SCOPES = ["openid", "email", "profile"] # Initialize the flow from the secrets file flow = Flow.from_client_secrets_file( CLIENT_SECRETS_FILE, scopes=SCOPES, redirect_uri=REDIRECT_URI ) # Exchange the authorization code for tokens flow.fetch_token(code=your_authorization_code) # Get the credentials object credentials = flow.credentials # Extract the tokens and expiry access_token = credentials.token refresh_token = credentials.refresh_token expiry = credentials.expiry print(f"Access Token: {access_token}")
Important Notes:
- Double-check that your
REDIRECT_URImatches exactly what you configured in the Google Cloud Console (includinghttp/httpsand any trailing slashes). Mismatches will cause errors. - Choose scopes that only cover what your app actually needs—don't request unnecessary permissions. For basic login,
openid email profileis usually enough. - Never hardcode your
CLIENT_SECRETin public code or commit it to version control. Use environment variables or secure secret management tools instead.
内容的提问来源于stack exchange,提问作者ahmed osama

