Google Form配置Pub/Sub Watch遇invalid_scope错误求助
Google Forms配置Watch触发invalid_scope错误,求拉取数据到Pub/Sub的最佳参考文档
问题背景
我正在寻找通过Apps Script从Google Form拉取数据并发送到Pub/Sub的最佳参考文档,目前已按照官方指南完成Apps Script的触发器配置,但在设置watch时持续触发invalid_scope错误。
我的Python代码
from googleapiclient import discovery from google.auth.transport.requests import Request import google.auth import os # 权限范围 SCOPES = [ "https://www.googleapis.com/auth/drive", "https://www.googleapis.com/auth/drive.file", "https://www.googleapis.com/auth/drive.readonly", "https://www.googleapis.com/auth/forms.body", "https://www.googleapis.com/auth/forms.body.readonly", "https://www.googleapis.com/auth/forms.responses.readonly" ] DISCOVERY_DOC = "forms.googleapis.com/$discovery/rest?version=v1" def get_gcp_credentials(): """获取GCP凭证""" creds = None if os.path.exists("token.json"): from google.oauth2.credentials import Credentials creds = Credentials.from_authorized_user_file("token.json", SCOPES) # 若没有有效凭证,引导用户登录 if not creds or not creds.valid: if creds and creds.expired and creds.refresh_token: creds.refresh(Request()) else: creds, project = google.auth.default( scopes=SCOPES ) # 保存凭证供下次使用 with open("token.json", "w") as token: token.write(creds.to_json()) return creds def main(): """配置表单watch的主函数""" creds = get_gcp_credentials() service = discovery.build( "forms", "v1", credentials=creds, discoveryServiceUrl=DISCOVERY_DOC, static_discovery=False, ) watch_config = { "watch": { "target": {"topic": {"topicName": "<projects/XXX/topics/app_script>"}}, "eventType": "RESPONSES", } } form_id = "XXX" # 创建watch并打印响应 try: result = service.forms().watches().create(formId=form_id, body=watch_config).execute() print(result) except Exception as e: print(f"发生错误: {e}") if __name__ == "__main__": main()
报错信息
Traceback (most recent call last): File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\SMHR_watch\new.py", line 72, in <module> main() File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\SMHR_watch\new.py", line 44, in main creds = get_gcp_credentials() ^^^^^^^^^^^^^^^^^^^^^ File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\SMHR_watch\new.py", line 31, in get_gcp_credentials creds.refresh(Request()) File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\.venv\Lib\site-packages\google\oauth2\credentials.py", line 409, in refresh ) = reauth.refresh_grant( ^^^^^^^^^^^^^^^^^^^^^ File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\.venv\Lib\site-packages\google\oauth2\reauth.py", line 366, in refresh_grant _client._handle_error_response(response_data, retryable_error) File "C:\Users\Mizanur.Choudhury\Documents\Pycharmprojects\SMHR_watch\.venv\Lib\site-packages\google\oauth2\_client.py", line 69, in _handle_error_response raise exceptions.RefreshError( google.auth.exceptions.RefreshError: ('invalid_scope: Bad Request', {'error': 'invalid_scope', 'error_description': 'Bad Request'})
解决方案建议
- 精简权限范围:设置Forms Watch仅需
https://www.googleapis.com/auth/forms.responses.readonly和https://www.googleapis.com/auth/drive(如需访问表单元数据),移除不必要的权限可避免scope冲突。 - 切换凭证类型:
google.auth.default()获取的是服务账号凭证,而设置Forms Watch需要OAuth 2.0用户凭证。删除已有的token.json,重新通过用户授权流程获取凭证。 - 修正Discovery文档地址:确保地址完整,正确格式为
https://forms.googleapis.com/$discovery/rest?version=v1。 - 检查Pub/Sub主题权限:确保凭证对应账号拥有Pub/Sub主题的
pubsub.topics.publish权限,同时Google Forms服务账号forms-notifications@system.gserviceaccount.com也需拥有该权限。
内容的提问来源于stack exchange,提问作者Mizanur Choudhury
相关产品推荐
相关产品推荐

