You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Firebase云函数调用Google Cloud Translate权限被拒问题求助

解决Firebase云函数调用Google Cloud Translate的权限拒绝问题

问题概述

调用Firebase云函数时触发权限错误:

Error: 7 PERMISSION_DENIED: Cloud IAM permission 'cloudtranslate.generalModels.predict' denied.

尝试通过firebase deploy指定用户管理型服务账号时,CLI提示unknown option '--service-account';改用gcloud functions deploy部署成功,但触发函数仍报错。Postman通过OAuth授权调用Translate API可正常工作,疑惑是否需要在代码中写入凭据。

代码示例

exports.ENtranslateES = functions.firestore.document('Users/{userID}/English/Translation_Request').onUpdate((change) => { 
    const { TranslationServiceClient } = require('@google-cloud/translate').v3;
    const translationClient = new TranslationServiceClient();
    const projectId = 'my-awesome-app';
    const location = 'global';
    const text = 'Hello, world!';

    async function translateText() {
        const request = {
            parent: `projects/${projectId}/locations/${location}`,
            contents: [text],
            mimeType: 'text/plain', // mime types: text/plain, text/html
            sourceLanguageCode: 'en',
            targetLanguageCode: 'es',
        };

        const [response] = await translationClient.translateText(request);

        for (const translation of response.translations) {
            console.log(`Translation: ${translation.translatedText}`);
        }
    }

    return translateText()
});

解决方案

1. 配置服务账号权限

确保你创建的google-cloud-translate@my-awesome-app.iam.gserviceaccount.com服务账号拥有Cloud Translate API User角色(该角色包含cloudtranslate.generalModels.predict权限),或直接添加cloudtranslate.generalModels.predict具体权限。

  • 操作路径:GCP控制台 → IAM与管理员 → IAM → 找到目标服务账号 → 编辑权限 → 添加对应角色/权限

2. 验证云函数运行时身份

部署后在GCP控制台的云函数详情页,检查「运行时服务账号」是否为你指定的用户管理型账号。若不符,说明部署参数未生效,需重新部署。

3. Firebase CLI部署的正确配置

Firebase CLI不支持--service-account命令行参数,需在firebase.json中配置:

{
  "functions": {
    "serviceAccount": "google-cloud-translate@my-awesome-app.iam.gserviceaccount.com"
  }
}

配置完成后执行firebase deploy --only functions:ENtranslateES重新部署。

4. 代码无需硬编码凭据

你的代码中new TranslationServiceClient()会自动使用云函数运行时的服务账号身份(默认应用凭据),无需在代码中写入Postman所用的Client ID、Secret等信息,保持现有代码即可。

内容的提问来源于stack exchange,提问作者Thomas David Kehoe

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.18 15:20:42