如何使用 google-auth 实例化 Google API 服务?

Kur*_*eek 6 python google-api google-authentication google-oauth google-sheets-api

我正在尝试使用其 API 从 Python 程序填充 Google 表格,使用快速入门指南 ( https://developers.google.com/sheets/api/quickstart/python ) 作为起点:

from __future__ import print_function
from apiclient.discovery import build
from httplib2 import Http
from oauth2client import file as oauth_file, client, tools

# Setup the Sheets API
SCOPES = 'https://www.googleapis.com/auth/spreadsheets.readonly'
store = oauth_file.Storage('token.json')
creds = store.get()
if not creds or creds.invalid:
    flow = client.flow_from_clientsecrets('credentials.json', SCOPES)
    creds = tools.run_flow(flow, store)
service = build('sheets', 'v4', http=creds.authorize(Http()))
Run Code Online (Sandbox Code Playgroud)

但是,我只能使用该flow_from_clientsecrets()方法(默认情况下)在浏览器中打开身份验证页面才能使其工作。这似乎不适合我想在生产服务器上定期运行的东西。

在任何情况下,根据https://pypi.org/project/oauth2client/oauth2client已弃用,建议开发人员google-auth改用。

因此,我尝试按如下方式调整此示例(遵循https://google-auth.readthedocs.io/en/latest/user-guide.html#service-account-private-key-files):

from google.oauth2 import service_account

credentials = service_account.Credentials.from_service_account_file(
    'google_client_secret.json')
Run Code Online (Sandbox Code Playgroud)

'google_client_secret.json'从 API 控制台下载的 JSON 文件在哪里,它看起来像这样(加扰和漂亮的打印):

{
  "installed": {
    "client_id": "33e.apps.googleusercontent.com",
    "project_id": "nps-survey-1532981793379",
    "auth_uri": "https://accounts.google.com/o/oauth2/auth",
    "token_uri": "https://accounts.google.com/o/oauth2/token",
    "auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
    "client_secret": "foobar",
    "redirect_uris": [
      "urn:ietf:wg:oauth:2.0:oob",
      "http://localhost"
    ]
  }
}
Run Code Online (Sandbox Code Playgroud)

但是,当我运行脚本时,出现以下错误:

(lucy-web-CVxkrCFK) bash-3.2$ python nps.py
Traceback (most recent call last):
  File "nps.py", line 25, in <module>
    'google_client_secret.json')
  File "/Users/kurtpeek/.local/share/virtualenvs/lucy-web-CVxkrCFK/lib/python3.7/site-packages/google/oauth2/service_account.py", line 209, in from_service_account_file
    filename, require=['client_email', 'token_uri'])
  File "/Users/kurtpeek/.local/share/virtualenvs/lucy-web-CVxkrCFK/lib/python3.7/site-packages/google/auth/_service_account_info.py", line 73, in from_filename
    return data, from_dict(data, require=require)
  File "/Users/kurtpeek/.local/share/virtualenvs/lucy-web-CVxkrCFK/lib/python3.7/site-packages/google/auth/_service_account_info.py", line 51, in from_dict
    'fields {}.'.format(', '.join(missing)))
ValueError: Service account info was not in the expected format, missing fields token_uri, client_email.
Run Code Online (Sandbox Code Playgroud)

从进入调试器中,我注意到问题基本上是传递给from_dict()方法的字典是文件中的整个字典google_client_secret.json,它只有一个键,"installed". 该from_dict()方法似乎“寻找”的是子字典,因为它包含一个token_uri键,尽管即使它不包含所需的client_email键。

我怀疑我为我的用例创建了错误类型的 OAuth2 客户端,因为包含客户端机密的 JSON 不是预期的格式。有什么想法可以解决这个问题吗?

Kur*_*eek 6

https://developers.google.com/api-client-library/python/guide/aaa_oauth来看,客户端 ID 分为三种类型:

  1. Web 应用程序客户端 ID
  2. 已安装的应用程序客户端 ID
  3. 服务帐户客户端 ID

我的用例是一个Service Account,在创建一个 Service Account 并选择“提供新的私钥”选项后,我发现我获得了一个与预期格式匹配的 JSON 文件。(我的那个是针对已安装的应用程序的)。