Passport.js / Google OAuth2 策略 - 如何在登录时使用令牌进行 API 访问

Jen*_*010 5 javascript google-api express google-oauth passport.js

我使用 Passport.js 通过他们的域 Google 帐户登录用户。这很好用,但现在我需要让这个应用程序访问一些 Google API(驱动器、工作表等)。

当用户登录时,日志中会出现一条消息,这使得护照看起来拥有所有必需的信息:

info: [06/Jun/2019:21:24:37 +0000] "302 GET /auth/callback?code=** USER ACCESS TOKEN HERE **&scope=email%20profile%20https://www.googleapis.com/auth/drive.file%20https://www.googleapis.com/auth/spreadsheets%20https://www.googleapis.com/auth/userinfo.email%20https://www.googleapis.com/auth/userinfo.profile%20https://www.googleapis.com/auth/drive HTTP/1.1" [46]
Run Code Online (Sandbox Code Playgroud)

这是通过通过 Passport.authenticate() 传递附加范围来实现的,它向用户提供“授予此应用程序对您 Google 帐户上这些内容的访问权限吗?”的信息。屏幕 :

//Initial auth call to Google
router.get('/',
  passport.authenticate('google', {
    hd: 'edmonds.wednet.edu',
    scope: [
      'email',
      'profile',
      'https://www.googleapis.com/auth/drive',
      'https://www.googleapis.com/auth/drive.file',
      'https://www.googleapis.com/auth/spreadsheets'
    ],
    prompt: 'select_account'
  })
);
Run Code Online (Sandbox Code Playgroud)

但是,当我尝试使用以下内容调用 API 时:

const {google} = require('googleapis');
const sheets = google.sheets({version: 'v4', auth});

router.post('/gsCreate', function(req,res,next){

  sheets.spreadsheets.create({
    // Details here.....
  });

});
Run Code Online (Sandbox Code Playgroud)

我除了错误什么也没有得到(当前的错误是debug: authClient.request is not a function

我的问题是:我是否可以使用这样的设置,要求用户登录并授予权限一次,然后以某种方式通过护照将其保存到用户会话中?

Ran*_*age 5

我有同样的问题,但我能够通过使用以下过程指定“范围”来访问 Google Gmail API 功能以及 Passport.js 用户身份验证。首先,创建一个文件来在 NodeJS 中设置 Passport-google-strategy,如下所示。

护照设置.js

const passport = require('passport')
const GoogleStrategy = require('passport-google-oauth20')
const fs = require("fs");
const path = require('path');
//make OAuth2 Credentials file using Google Developer console and download it(credentials.json)
//replace the 'web' using 'installed' in the file downloaded
var pathToJson = path.resolve(__dirname, './credentials.json');
const config = JSON.parse(fs.readFileSync(pathToJson));


passport.serializeUser((user, done) => {
    done(null, user.id)
})

passport.deserializeUser((id, done) => {

    const query = { _id: id }
    Users.findOne(query, (err, user) => {
        if (err) {
            res.status(500).json(err);
        } else {
            done(null, user)
        }
    })
})

//create a google startergy including following details
passport.use(
    new GoogleStrategy({
        clientID: config.installed.client_id,
        clientSecret: config.installed.client_secret,
        callbackURL: config.installed.redirect_uris[0]
    }, (accessToken, refreshToken,otherTokenDetails, user, done) => {
        
        //in here you can access all token details to given API scope
        //and i have created file from that details
        let tokens = {
            access_token: accessToken,
            refresh_token: refreshToken,
            scope: otherTokenDetails.scope,
            token_type: otherTokenDetails.token_type,
            expiry_date:otherTokenDetails.expires_in
        }
        let data = JSON.stringify(tokens);
        fs.writeFileSync('./tokens.json', data);


        //you will get a "user" object which will include the google id, name details, 
        //email etc, using that details you can do persist user data in your DB or can check 
        //whether the user already exists

        //after persisting user data to a DB call done
        //better to use your DB user objects in the done method

        done(null, user)
  
    })
)
Run Code Online (Sandbox Code Playgroud)

然后在nodejs中创建index.js文件用于API路由管理并调用Gmail API的send方法。另外,运行以下命令来安装“google-apis”

npm install googleapis@39 --save
Run Code Online (Sandbox Code Playgroud)

索引.js

const express = require("express")
//import passport_setup.js
const passportSetup = require('./passport_setup')
const cookieSeesion = require('cookie-session');
const passport = require("passport");
//import google api
const { google } = require('googleapis');
//read credentials file you obtained from google developer console
const fs = require("fs");
const path = require('path');
var pathToJson_1 = path.resolve(__dirname, './credentials.json');
const credentials = JSON.parse(fs.readFileSync(pathToJson_1));


//get Express functionalities to app
const app = express();

// **Middleware Operations**//

//cookie encryption
app.use(cookieSeesion({
    name:'Reserve It',
    maxAge: 1*60*60*1000,
    keys: ['ranmalc6h12o6dewage']
}))

//initialize passort session handling
app.use(passport.initialize())
app.use(passport.session())

app.use(express.json());    

//**API urls**//

//route to authenticate users using google by calling google stratergy in passport_setup.js 
//mention access levels of API you want in the scope
app.get("/google", passport.authenticate('google', {
scope: ['profile',
    'email',
    'https://mail.google.com/'
],
accessType: 'offline',
prompt: 'consent'
}))

//redirected route after obtaining 'code' from user authentication with API scopes
app.get("/google/redirect", passport.authenticate('google'), (req, res) => {

    try {
        //read token file you saved earlier in passport_setup.js
        var pathToJson_2 = path.resolve(__dirname, './tokens.json');
        //get tokens to details to object
        const tokens = JSON.parse(fs.readFileSync(pathToJson_2));
        //extract credential details
        const { client_secret, client_id, redirect_uris } = credentials.installed

        //make OAuth2 object
        const oAuth2Client = new google.auth.OAuth2(client_id,
        client_secret,
        redirect_uris[0])

        // set token details to OAuth2 object
        oAuth2Client.setCredentials(tokens)
     
       //create gmail object to call APIs
       const gmail = google.gmail({ version: 'v1', auth: oAuth2Client })

       //call gmail APIs message send method
       gmail.users.messages.send({
             userId: 'me',//'me' indicate current logged in user id
             resource: {
                raw: //<email content>
               }
        }, (err, res) => {
            if (err) {
              console.log('The API returned an error: ' + err)
              throw err
            }
            console.log('Email Status : ' + res.status)
            console.log('Email Status Text : ' + res.statusText)
         })

        res.status(200).json({ status:true })
        
    } catch (err) {
        res.status(500).json(err)
    }

})

app.listen(3000, () => { console.log('Server Satrted at port 3000') })
Run Code Online (Sandbox Code Playgroud)

为了清楚起见,您可以使用express.Router()将index.js文件中的路由分离到不同的文件

如果你想调用另一个Google API服务,只需更改此代码段及其下面的代码即可;

   const gmail = google.gmail({ version: 'v1', auth: oAuth2Client })
   gmail.users.messages.send(....Send Method internal implementation given above....)
Run Code Online (Sandbox Code Playgroud)

对于谷歌云端硬盘:

const drive = google.drive({version: 'v3', auth: oAuth2Client});
drive.files.list(...Refer "Google Drive API" documentation for more details....)
Run Code Online (Sandbox Code Playgroud)


use*_*611 2

我相信您不能使用 Passport.js 为 Sheets 或 Drive 等 API 进行三足 oauth。

请查看使用OAuth for Web 服务器文档