Google API PHP - Login as user with oauth2 and service account in the same application?












0














So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.



So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.



The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.



So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.



I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.



I have enabled delegation of the service accounts rights within our g suite account.



I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.



I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.



I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.










share|improve this question






















  • Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
    – MαπμQμαπkγVπ.0
    Nov 23 at 8:15










  • I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
    – ndom91
    Nov 23 at 8:27


















0














So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.



So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.



The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.



So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.



I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.



I have enabled delegation of the service accounts rights within our g suite account.



I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.



I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.



I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.










share|improve this question






















  • Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
    – MαπμQμαπkγVπ.0
    Nov 23 at 8:15










  • I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
    – ndom91
    Nov 23 at 8:27
















0












0








0







So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.



So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.



The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.



So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.



I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.



I have enabled delegation of the service accounts rights within our g suite account.



I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.



I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.



I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.










share|improve this question













So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.



So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.



The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.



So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.



I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.



I have enabled delegation of the service accounts rights within our g suite account.



I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.



I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.



I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.







php oauth-2.0 gmail-api service-accounts






share|improve this question













share|improve this question











share|improve this question




share|improve this question










asked Nov 22 at 18:25









ndom91

136




136












  • Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
    – MαπμQμαπkγVπ.0
    Nov 23 at 8:15










  • I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
    – ndom91
    Nov 23 at 8:27




















  • Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
    – MαπμQμαπkγVπ.0
    Nov 23 at 8:15










  • I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
    – ndom91
    Nov 23 at 8:27


















Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15




Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15












I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27






I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27



















active

oldest

votes











Your Answer






StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");

StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);

StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});

function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});


}
});














draft saved

draft discarded


















StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53436442%2fgoogle-api-php-login-as-user-with-oauth2-and-service-account-in-the-same-appli%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown






























active

oldest

votes













active

oldest

votes









active

oldest

votes






active

oldest

votes
















draft saved

draft discarded




















































Thanks for contributing an answer to Stack Overflow!


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.





Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


Please pay close attention to the following guidance:


  • Please be sure to answer the question. Provide details and share your research!

But avoid



  • Asking for help, clarification, or responding to other answers.

  • Making statements based on opinion; back them up with references or personal experience.


To learn more, see our tips on writing great answers.




draft saved


draft discarded














StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53436442%2fgoogle-api-php-login-as-user-with-oauth2-and-service-account-in-the-same-appli%23new-answer', 'question_page');
}
);

Post as a guest















Required, but never shown





















































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown

































Required, but never shown














Required, but never shown












Required, but never shown







Required, but never shown







Popular posts from this blog

What visual should I use to simply compare current year value vs last year in Power BI desktop

Alexandru Averescu

Trompette piccolo