我想让整个Google驱动器从我的应用程序访问用户。
并且我使用以下代码从Google和oauth2.0进行授权。

function OpenGoogleLogin()
              {
                    var url = "https://accounts.google.com/o/oauth2/auth?scope=https://www.googleapis.com/auth/drive&redirect_uri=http://localhost:8080/Abc/Oauth2callback&response_type=code&client_id=xxxxxxxxxxxxxxxxxxxxxxxxxx&access_type=offline&approval_prompt=force";
                    window.location = url;
             }


从上面的代码中,我得到了授权代码。
在重定向页面上,我将以下servlet代码放入

public class Oauth2callback extends HttpServlet {
    private static final long serialVersionUID = 1L;

    public Oauth2callback() {
        super();

    }

    /**
     * @see HttpServlet#doGet(HttpServletRequest request, HttpServletResponse
     *      response)
     */
    protected void doGet(HttpServletRequest request,
            HttpServletResponse response) throws ServletException, IOException {

        System.out.println("entering doGet");
        try {
            // get code
            String code = request.getParameter("code");
            // format parameters to post
            String urlParameters = "code="
                    + code
                    + "&client_id=xxxxxxxxxxxxxxxxxxxxx"
                    + "&client_secret=xxxxxxxxxxxxxxxxxx"
                    + "&redirect_uri=http://localhost:8080/Abc/Oauth2callback"
                    + "&grant_type=authorization_code";

            //post parameters
            URL url = new URL("https://accounts.google.com/o/oauth2/token");
            URLConnection urlConn = url.openConnection();
            urlConn.setDoOutput(true);
            OutputStreamWriter writer = new OutputStreamWriter(
                    urlConn.getOutputStream());
            writer.write(urlParameters);
            writer.flush();

            //get output in outputString
            String line, outputString = "";
            BufferedReader reader = new BufferedReader(new InputStreamReader(
                    urlConn.getInputStream()));
            while ((line = reader.readLine()) != null) {
                outputString += line;
            }
            System.out.println(outputString);

            //get Access Token
            JsonObject json = (JsonObject)new JsonParser().parse(outputString);
            String access_token = json.get("access_token").getAsString();
            System.out.println(access_token);

            //get User Info
            url = new URL(
                    "https://www.googleapis.com/oauth2/v1/userinfo?access_token="
                            + access_token);
            urlConn = url.openConnection();
            outputString = "";
            reader = new BufferedReader(new InputStreamReader(
                    urlConn.getInputStream()));
            while ((line = reader.readLine()) != null) {
                outputString += line;
            }
            System.out.println(outputString);

            // Convert JSON response into Pojo class
            GooglePojo data = new Gson().fromJson(outputString, GooglePojo.class);
            System.out.println(data);
            writer.close();
            reader.close();

        } catch (MalformedURLException e) {
            System.out.println( e);
        } catch (ProtocolException e) {
            System.out.println( e);
        } catch (IOException e) {
            System.out.println( e);
        }
        System.out.println("leaving doGet");
    }

}


在上面的代码中,google pojo只是一个pojo类,但是我不知道何时运行该servlet,它使我可以访问并刷新。
但这给了我错误

java.io.IOException:服务器返回URL的HTTP响应代码:403:https://www.googleapis.com/oauth2/v1/userinfo?access_token=xxxxxxxxxxxxx

最佳答案

您正在使用范围https://www.googleapis.com/auth/drive发出初始授权请求,并使用其代码来调用https://www.googleapis.com/oauth2/v1/userinfo

如果要获取用户个人资料信息,则必须在初始请求中使用以下范围之一,


https://www.googleapis.com/auth/userinfo.email:查看电子邮件地址
https://www.googleapis.com/auth/userinfo.profile:查看基本个人资料信息


因此,将您的第一个网址更改为

var url = "https://accounts.google.com/o/oauth2/auth?scope=https://www.googleapis.com/auth/userinfo.profile&redirect_uri=http://localhost:8080/Abc/Oauth2callback&response_type=code&client_id=xxxxxxxxxxxxxxxxxxxxxxxxxx&access_type=offline&approval_prompt=force";

10-08 01:54