Box SDK as_user请求权限不足问题排查求助
Box服务账号模拟用户后调用API返回403 insufficient_scope错误
我在Django项目中编写了以下代码,用于让Box服务账号模拟指定主账号用户:
# implementation module_dir = os.path.dirname(os.path.dirname(os.path.dirname(__file__))) # get current directory box_config_path = os.path.join(module_dir, 'py_scripts/transactapi_funded_trades/config.json') # the config json downloaded config = JWTAuth.from_settings_file(box_config_path) #creating a config via the json file client = Client(config) #creating a client via config user_to_impersonate = client.user(user_id='8********6') #get main user user_client = client.as_user(user_to_impersonate) #impersonate main user
模拟过程没有抛出错误,但执行获取文件的逻辑时,调用GET https://api.box.com/2.0/folders/0/items返回403错误,日志如下:
[2022-09-13 02:50:26,146: INFO/MainProcess] GET https://api.box.com/2.0/folders/0/items {'headers': {'As-User': '8********6', 'Authorization': '---LMHE', 'User-Agent': 'box-python-sdk-3.3.0', 'X-Box-UA': 'agent=box-python-sdk/3.3.0; env=python/3.10.4'}, 'params': {'offset': 0}} [2022-09-13 02:50:26,578: WARNING/MainProcess] "GET https://api.box.com/2.0/folders/0/items?offset=0" 403 0 {'Date': 'Mon, 12 Sep 2022 18:50:26 GMT', 'Transfer-Encoding': 'chunked', 'x-envoy-upstream-service-time': '100', 'www-authenticate': 'Bearer realm="Service", error="insufficient_scope", error_description="The request requires higher privileges than provided by the access token."', 'box-request-id': '07cba17694f7ea32f0c2cd42790bce39e', 'strict-transport-security': 'max-age=31536000', 'Via': '1.1 google', 'Alt-Svc': 'h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"'} b'' [2022-09-13 02:50:26,587: WARNING/MainProcess] Message: None Status: 403 Code: None Request ID: None Headers: {'Date': 'Mon, 12 Sep 2022 18:50:26 GMT', 'Transfer-Encoding': 'chunked', 'x-envoy-upstream-service-time': '100', 'www-authenticate': 'Bearer realm="Service", error="insufficient_scope", error_description="The request requires higher privileges than provided by the access token."', 'box-request-id': '07cba17694f7ea32f0c2cd42790bce39e', 'strict-transport-security': 'max-age=31536000', 'Via': '1.1 google', 'Alt-Svc': 'h3=":443"; ma=2592000,h3-29=":443"; ma=2592000,h3-Q050=":443"; ma=2592000,h3-Q046=":443"; ma=2592000,h3-Q043=":443"; ma=2592000,quic=":443"; ma=2592000; v="46,43"'} URL: https://api.box.com/2.0/folders/0/items Method: GET Context Info: None
错误提示请求需要更高权限,已经困扰一周,求排查方向。
排查建议
- 检查服务账号权限范围:确认
config.json中的scopes字段是否包含root_read或root_readwrite,访问用户根目录(folders/0)需要对应权限。 - 验证用户模拟权限:在Box开发者控制台的应用设置里,确保“Advanced Features”下的“User Impersonation”已启用,且应用拥有模拟用户的权限。
- 确认被模拟用户的资源权限:检查ID为
8********6的用户本身是否能正常访问自己的根目录,避免用户账号被限制访问。 - 核对配置与SDK版本:确认
config.json中的企业ID、客户端ID等信息正确,同时检查box-python-sdk-3.3.0是否存在已知的权限相关bug,必要时尝试升级或降级版本。 - 解析令牌权限:解码请求中的access token(移除
Bearer前缀),查看令牌内的scopes字段,确认是否包含访问目标资源所需的权限。
内容的提问来源于stack exchange,提问作者Prosy A.
相关产品推荐
相关产品推荐

