You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在C# Windows窗体的Google OAuth中添加profile与email权限

Adding Google OAuth profile and email Scopes to Your C# WinForms App

Hey there! Let's get those profile and email permissions added to your Google OAuth flow. The key issue right now is that your token request body has an empty scope parameter—we need to fill that in with the correct scopes, and also make sure you're requesting them upfront in the authorization step too.

Step 1: Update the Token Request Body

In your tokenRequestBody string, replace the empty scope= part with the URL-encoded version of email profile (Google uses space-separated scopes, which we need to encode for the form data). Using Uri.EscapeDataString ensures the scopes are properly formatted for the request.

Here's the modified code snippet, with the critical change highlighted:

string tokenRequestURI = "https://www.googleapis.com/oauth2/v4/token";
// Updated: Added encoded scopes to the scope parameter
string tokenRequestBody = string.Format(
    "code={0}&redirect_uri={1}&client_id={2}&code_verifier={3}&client_secret={4}&scope={5}&grant_type=authorization_code",
    code, 
    System.Uri.EscapeDataString(redirectURI), 
    clientID, 
    code_verifier, 
    clientSecret,
    System.Uri.EscapeDataString("email profile") // This is the new, required part!
);

// Rest of your token request code stays the same...
HttpWebRequest tokenRequest = (HttpWebRequest)WebRequest.Create(tokenRequestURI);
tokenRequest.Method = "POST";
tokenRequest.ContentType = "application/x-www-form-urlencoded";
tokenRequest.Accept = "Accept=text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8";
byte[] _byteVersion = Encoding.ASCII.GetBytes(tokenRequestBody);
tokenRequest.ContentLength = _byteVersion.Length;
Stream stream = tokenRequest.GetRequestStream();
await stream.WriteAsync(_byteVersion, 0, _byteVersion.Length);
stream.Close();

Step 2: Don't Skip the Initial Authorization Request

This is a common gotcha! Before you even reach the token exchange step, you must include the same email and profile scopes in the authorization URL that sends the user to Google's login page. For example, your authorization URL should look like this (swap in your client ID and redirect URI):

https://accounts.google.com/o/oauth2/v2/auth?client_id=YOUR_CLIENT_ID&redirect_uri=YOUR_REDIRECT_URI&response_type=code&scope=email%20profile&code_challenge=YOUR_CODE_CHALLENGE&code_challenge_method=S256

Google requires the scopes to match exactly between the authorization request and the token exchange request. If you skip this step, even with correct scopes in the token request, the token won't have access to the user's email or profile data.

Why This Works

Google OAuth operates on an explicit permission model: you must ask the user for the exact scopes you need during their initial login approval. The token exchange step then validates that you're only requesting access to the scopes the user agreed to. By adding email and profile to both parts of the flow, you'll receive a token that lets you access the user's basic profile information and email address.

内容的提问来源于stack exchange,提问作者Noufal

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.11 07:44:39