Google API PHP - Login as user with oauth2 and service account in the same application?
So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.
So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.
The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.
So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.
I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.
I have enabled delegation of the service accounts rights within our g suite account.
I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.
I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.
I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.
php oauth-2.0 gmail-api service-accounts
add a comment |
So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.
So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.
The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.
So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.
I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.
I have enabled delegation of the service accounts rights within our g suite account.
I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.
I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.
I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.
php oauth-2.0 gmail-api service-accounts
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27
add a comment |
So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.
So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.
The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.
So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.
I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.
I have enabled delegation of the service accounts rights within our g suite account.
I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.
I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.
I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.
php oauth-2.0 gmail-api service-accounts
So I'm having some trouble adding the service account to my php web app. Little background - it's a little web app that works off my colleagues gmail inboxes and manages and organizes maintenance notifications ( regarding datacenter circuits) from suppliers based on which we need to lookup the affected customers and forward the info on to them so everyone is aware of scheduled down time.
So I have an "incoming maintenance" table which just lists the unread mails in a specific label and allows the user to then save the gmail message ID and a bunch of other info to a sql db.
The problem I've run into is that even among messages sent to every user, gmail assigns different message IDs for everyone's inbox.
So I decided to implement a service account and use that to allow everyone using this app to "work" out of one person's inbox, in the background, therefore keeping the IDs always consistent.
I have the normal oauth2 up and running with the required scope without a problem, but am now having trouble also getting the service account to authenticate.
I have enabled delegation of the service accounts rights within our g suite account.
I keep getting error messages regarding "not allowed to get tokens using that method.." which makes me think the service account and individual user logins are getting crossed up somewhere along the line. I've made sure to use different variables for the service and client objects and everything, however.
I'm in the train now, but I will copy some code examples into here as soon as I get home. But in general, is this even possible? I haven't seen any documentation about it.
I want my users to be able to authenticate themselves with their work G suite accounts to get into the application in general ( and to grab a few other things from their accounts within the app) - but need this service account functionality to manage the email fetching / saving system on the backend.
php oauth-2.0 gmail-api service-accounts
php oauth-2.0 gmail-api service-accounts
asked Nov 22 at 18:25
ndom91
136
136
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27
add a comment |
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27
add a comment |
active
oldest
votes
Your Answer
StackExchange.ifUsing("editor", function () {
StackExchange.using("externalEditor", function () {
StackExchange.using("snippets", function () {
StackExchange.snippets.init();
});
});
}, "code-snippets");
StackExchange.ready(function() {
var channelOptions = {
tags: "".split(" "),
id: "1"
};
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function() {
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled) {
StackExchange.using("snippets", function() {
createEditor();
});
}
else {
createEditor();
}
});
function createEditor() {
StackExchange.prepareEditor({
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader: {
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
},
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
});
}
});
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53436442%2fgoogle-api-php-login-as-user-with-oauth2-and-service-account-in-the-same-appli%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
active
oldest
votes
active
oldest
votes
active
oldest
votes
active
oldest
votes
Thanks for contributing an answer to Stack Overflow!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Some of your past answers have not been well-received, and you're in danger of being blocked from answering.
Please pay close attention to the following guidance:
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function () {
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f53436442%2fgoogle-api-php-login-as-user-with-oauth2-and-service-account-in-the-same-appli%23new-answer', 'question_page');
}
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function () {
StackExchange.helpers.onClickDraftSave('#login-link');
});
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Your error means that your service account haven't authorized properly, have you checked Delegating domain-wide authority to the service account? As well as this SO post?
– MαπμQμαπkγVπ.0
Nov 23 at 8:15
I have seen that, thanks though. I have enabled the service account DWD and added the client id + scopes to the admin console's api access security page. I cant find anyhting else im missing based on their documentation. Am I overlooking something?
– ndom91
Nov 23 at 8:27