#迷上英式英文【男神Cumberbatch的男神聲線】
#蕭叔叔講莎士比亞
演英國電視劇火紅的男神Benedict Cumberbatch擁有一把超重低音的磁性男生,身為聲音控的蕭叔叔,也不禁為之顛倒。這一短片,是Cumberbatch為BBC電視劇拍的廣告,題為A Lifetime of Original British Drama on the BBC。
其中他朗讀的一段文字,來自莎士比亞劇As You Like It的著名獨白All the World’s a Stage,講述人由呱呱墜地到衰老死亡的過程。全文如下。
All the world’s a stage,
And all the men and women merely players;
They have their exits and their entrances,
And one man in his time plays many parts,
His acts being seven ages. At first, the infant,
Mewling and puking in the nurse’s arms.
Then the whining schoolboy, with his satchel
And shining morning face, creeping like snail
Unwillingly to school. And then the lover,
Sighing like furnace, with a woeful ballad
Made to his mistress’ eyebrow. Then a soldier,
Full of strange oaths and bearded like the pard,
Jealous in honor, sudden and quick in quarrel,
Seeking the bubble reputation
Even in the cannon’s mouth. And then the justice,
In fair round belly with good capon lined,
With eyes severe and beard of formal cut,
Full of wise saws and modern instances;
And so he plays his part. The sixth age shifts
Into the lean and slippered pantaloon,
With spectacles on nose and pouch on side;
His youthful hose, well saved, a world too wide
For his shrunk shank, and his big manly voice,
Turning again toward childish treble, pipes
And whistles in his sound. Last scene of all,
That ends this strange eventful history,
Is second childishness and mere oblivion,
Sans teeth, sans eyes, sans taste, sans everything.
蕭叔叔輕輕用廣東話粗略解釋大意:
人生如舞台上七段戲。
第一階段,係又嘈又嘔奶嘅手抱BB。
第二階段,係lur地唔願意返學嘅小學雞。
第三階段,係sighing like furnace,整天唉聲嘆氣,要生要死,對住小事如愛人條眼眉都可以作到首慘情詩嘅超難頂lovers。
第四階段,係滿口古怪誓言,終日打打鬧鬧,為榮譽連砲彈都唔怕嘅軍人。
然後第五階段,開始變成離地中產,成為又肥又貪,滿口道理嘅官。
第六階段,身形漸漸縮水,開始衣不稱身,聲線變弱,由雄厚聲線,變到老人家嗰D好似吹口哨嘅vee vee聲。
第七階段,係second childishness。也就是說,你點嚟,就會點去,變番好似BB仔一樣,冇牙、冇眼、冇味覺、乜9都冇。
同場加映,蕭叔叔上年在明報寫的文章:
【我有特別的學英文技巧-讀莎士比亞】蕭愷一
【明報專訊】讀莎士比亞,不應該是文學學生的專利。蕭叔叔的writing學生,不論長幼,都要讀莎士比亞的詩和劇。「點解要讀這些『英文的文言文』?」不少學生問。莎士比亞的的文字,的確同現代英文好不同,不論句式,詞序,用字,以至串法,都不一樣。假如不是要學寫古文,讀來作甚?主要有兩個原因。
第一,閱讀甚至背誦莎士比亞,有助掌握英文輕重音的節奏。英文這個語言,著重音節的輕重,這種輕重音相隔的節奏,好比中文的平仄,文筆是否流暢,好多時要看這個。不論寫作還是說話,不拿捏好輕重音,英文好難學得好。但這不是本文主旨,未來再跟大家詳談。
第二個原因,也是今天蕭叔叔要跟大家說的:多讀老莎的文字,有助解決寫作軟弱無力,言之無物,含糊不清,累贅不堪等港式英文常見的毛病。莎士比亞的文字有什麼特點?用字靈活多變而精簡,比喻新穎而深刻。今天蕭叔叔找來兩句取自莎士比亞的劇作和情詩的例子,跟大家一同感受他文字的創造力和感染力。
第一句來自戲劇 The Merchant of Venice。劇中反派角色猶太人 Shylock 借錢給男主角,合約訂明假如主角於時限前還不到錢,Shylock 就可割下他一磅重的肉,換句話說,就是要了他的命。後來主角週轉不靈,真的還不到錢,一直對主角恨之入骨的 Shylock 當然不會放過傷害主角的機會,有人問 Shylock 為何要堅持要履行合約,他說:
He hath disgraced me and hindered me half a million, laughed at my losses, mocked at my gains, scorned my nation, thwarted my bargains, cooled my friends, heated mine enemies—and what’s his reason? I am a Jew. […]
蕭叔叔翻譯技巧平平,只道個大意出來:他(男主角)不單累我唔見錢,仲常常羞辱我,冷待我,嘲笑我,只因我是個猶太人。大家留意兩個簡單的字:cooled 和 heated。兩個在此都是動詞,cooled my friends,大意就是破壞我同朋友之間的友誼,使朋友離我而去;heated my enemies 就是煽動我的敵人。這兩個字,都簡潔到極,但意思好出,一看就明。大家不妨想想自己會怎樣表達這兩句的意思。英文平平的人,可能會把前半部寫成:
made me lose my friends,或
caused my friends to leave me,或
undermined the relationship between me and my friends,之類。
後半部可能會變成:
made my enemies hate me even more。
非常長氣,而且表達還不夠簡單一句 cooled my friends,heated my enemies 生動、深刻。這是大師的功力。
第二句來自老莎的情詩(他的情詩是一絕,將來找幾首同大家讀讀)。老莎跟情人的關係若即若離,有時好high,有時 insecure。有次他寫:
To leave poor me thou hast the strength of law, since why to love I can allege no cause.
他說,你要離開我,實在有太多太多的理由,像連法律都會站在你那邊,因為我從來都配不起你:I can think of no reason why you should love me and stay with me.
要離開我,you have the strength of law!假如你要走,像法律明文寫出一樣堂皇的道理,都在你那邊。可看到老莎在這段關係裏的地位是如何卑微。大家請留意,這句的字,都是很淺的,但意義深遠,比喻深刻。也看 allege 一字。因為,你為什麼要愛我,我一個理由都想不到。Allege 這個法庭常用的動詞,跟前句的比喻呼應。你為什麼要愛我?我一個理由都呈不上。幾可憐!
篇幅有限,先講到這裏,只希望大家也感受到老莎文字可愛之處。讀莎士比亞,不是為了要寫這些「文言文」,而是為了學習他運用文字的 spirit。
最後,由於這是蕭叔叔在本欄的第一篇文,在此向大家打個招呼,請大家多多指教。另外,叔叔也要戴個頭盔。蕭叔叔雖是個英文教與學的狂熱份子,但從未受過正式的語言學、文學、翻譯的訓練。假如有何錯漏,歡迎電郵或在 Facebook 指正,指點,討論,感謝萬分。
文:蕭愷一
作者簡介:蕭愷一,AKA蕭叔叔。夢想做男神,現實是大叔的英文教學狂熱份子,law grad,哲學碩士dropout,語言學愛好者。以 speak English like an educated native 為教與學的終極目標。Facebook專頁:蕭叔叔的英式英文學會 facebook.com/unclesiu
同時也有65部Youtube影片,追蹤數超過261萬的網紅Kouki,也在其Youtube影片中提到,一輩子不能錯過的RPG作品,2015年極致好評 Undertale 。每周六日推出。 從今天起開始訂閱吧! ➔ http://bit.ly/Kouki 此影片有繁體中文翻譯,需開啟影片中的CC字幕。 Undertale ★ 播放清單 ★ ➔ https://www.youtube.com/playl...
「side part中文」的推薦目錄:
- 關於side part中文 在 蕭叔叔英式英文學會 Uncle Siu's British English Club Facebook
- 關於side part中文 在 姚惠珍 Facebook
- 關於side part中文 在 林輝:旅遊寫作人 Facebook
- 關於side part中文 在 Kouki Youtube
- 關於side part中文 在 emi wong Youtube
- 關於side part中文 在 Kouki Youtube
- 關於side part中文 在 《英雄傳說黎之軌跡II -緋紅原罪-》中文版- Part.5 - YouTube 的評價
- 關於side part中文 在 Using OAuth 2.0 for Web Server Applications 的評價
side part中文 在 姚惠珍 Facebook 八卦
目前台灣人年齡的中位數是42歲,過半數的台灣人不認識或不熟悉守護台灣40年安全的台灣關係法(TRA)。
太平盛世時,大家不熟悉就算了,現在習大大都抬出了「ㄧ國兩制」,我們不能再溫水煮青蛙,要搞清楚我們迄今能跟中國處於不同世界,都是受到TRA的保護。現在更要在這個基礎上,尋求未來更多的可能。
40年前,因為很多人的努力(包括美國國會議員),才有TRA,40年後的今天,輪到我們這一代,來承擔守護台灣的責任。
#TRA40周年慶
#保羅萊恩很帥
#拒交主權全民作主
美中公報的英文/中文版本,來比較這三個公報的異同點在哪裡。
1972年2月,「上海公報」中明確提出美國的「一個中國」政策,即「The United States acknowledges that all Chinese on either side of the Taiwan Strait maintain there is but one China and that Taiwan is a part of China. The United States Government does not challenge that position. It reaffirms its interest in a peaceful settlement of the Taiwan question by the Chinese them-selves.」中國政府版本:「美國認識到,在臺灣海峽兩邊的所有中國人都認為只有一個中國,臺灣是中國的一部份,美國政府對這一立場不提出異議。它重申它對由中國人自己和平解決臺灣問題的關心。」
在1978年12月美中建交公報裡,美國在「一個中國」有關的立場上作以下說明:「The United States of America recognizes the Government of the People’s Republic of China as the sole legal Government of China…The Government of the United States of America acknowledges the Chinese position that there is but one China and Taiwan is part of China.」中國政府版本:「美利堅合眾國承認中華人民共和國政府是中國的唯一合法政府。...美利堅合眾國政府承認中國的立場,即只有一個中國,臺灣是中國的一部份。」
1982年8月17日的「八.一七公報」,其中美國「一個中國」政策的表述為:「The United States of America recognized the Government of the People’s Republic of China as the sole legal government of China, and it acknowledged the Chinese position that there is but one China and Taiwan is part of China.」中國政府版本:「美利堅合眾國承認中華人民共和國政府為中國的唯一合法政府,並承認中國的立場,即只有一個中國,臺灣是中國的一部份」
比較「上海公報」與「建交公報」及「八.一七公報」的英中版本,可以發現,美國在「一個中國」政策表述上一直採用英文的「acknowledge」一詞。另外,後兩個公報採用「the Chinese position」,而不是「上海公報」中的「all Chinese on either side of the Taiwan Strait 」這一用語,美國人採用這些精確的英文是有法律和政治深意的。
首先,「acknowledge」是「認知和了解」的意思,美國只是認知中國人的立場,也不提出異議,但並不表示「承認和接受」。在「上海公報」簽署前一晚,國務卿羅吉斯和助理國務卿葛林反對季辛吉創造出的用語「all Chinese on either side of the Taiwan Strait」。葛林指出,講「所有的中國人」並沒確切反映事實,因為臺灣的居民只有少數人自認是中國人。如果「所有的中國人」指的是社會上、文化上、種族上的華人,那麼幾乎島上每個人都可歸進這一類,可是這些多數人並不同意他們屬於中國。季辛吉因此緊急約見中國副外長喬冠華,指出羅吉斯要求把「在臺灣海峽兩邊的所有中國人都認為只有一個中國」一句中的「所有中國人改為『中國人』」。喬冠華很不高興,痛罵季辛吉竟然暗示在臺灣有人可能不會認同自己是中國人、或是不覺得臺灣是中國的一部分,季辛吉退讓了,因此「上海公報」沒有按美國國務院的意見做任何修改。但是,「建交公報」及「八.一七公報」卻按國務院的意見把「在臺灣海峽兩邊的所有中國人改為『中國人』」了,這就暗示美國認知臺灣有人可能不認同自己是中國人。
尤其嚴重的是,中國官方在中文版本中,「上海公報」將英文版裡的「acknowledge」翻譯為「認識到」,但到了「建交公報」及「八.一七公報」,「acknowledge」卻翻譯為「承認」,於是,美國政策表述中的英文用詞沒變,但中文翻譯意思大變。
最後,中國官方又把「the Chinese position」從「中國人的立場」改譯為「中國的立場」,漏掉「人」字,這種曲解英文原意的翻譯,造成了中美兩國對什麼是美國的「一個中國」政策長期爭論不休。美國明明只是「認知中國人的立場」(包括在臺灣的中國人),可是中國硬翻譯成美國「承認中國的立場」(即為中華人民共和國的立場),這真是「差之毫釐,謬以千里」。中國官方這麼翻譯,讓中國老百姓以為美國承認了中華人民共和國政府的立場。
side part中文 在 林輝:旅遊寫作人 Facebook 八卦
和一個旅行女孩約會吧!
Date a girl who travels. 和一個旅行女孩約會吧!
Date a girl who travels.
Date a girl who would rather save up for out of town trips or day trips than buy new shoes or clothes. She may not look like a fashion plate, but behind that tanned and freckled face from all the days out in the sun, lies a mind that can take you places and an open heart that will take you for what you are, not for what you can be.
和一個旅行女孩約會吧。這個女孩,寧願把錢存下來當作旅行基金,也不會花在無謂的新衣服。她看起來可能不是個時尚辣妹,但在那張久經日曬的小麥色臉龐後,藏著一顆能帶你去任何地方,並且能欣賞你最真實個性的一顆心。
Date a girl who travels.
You’ll recognize her by the backpack she always carries. She won’t be carrying a dainty handbag; where will she put her travel journal, her pens, and the LED flashlight that’s always attached to her bag’s zipper? In a small purse, how can she bring the small coil of travel string, the wet tissues, the box of cracker, and the bottle of water she’s always ready with, just in case something happens and she can’t go home yet? Yes, a girl who travels knows that anytime, anything can happen and she just has to be prepared with it. Nothing takes her by surprise; she takes everything with equanimity, knowing that such things are always a part of life. She’s reliable and dependable, traits that she’s learned while on the road.
和一個旅行女孩約會吧。你可以一眼就從那永不離身的背包認出她。並非一個無法裝載旅行日誌、筆、手電筒的精緻小提包,一個小包包怎麼能裝下旅行繩、溼毛巾、乾糧、和一瓶緊急備用的水呢?沒錯,一個旅行女孩知道隨時都有可能發生無法預料的事,所以她會永遠保持在準備好的狀態。沒有什麼事能嚇到她,她永遠可以泰然處之從容面對,知道這就是人生。她是值得信賴依靠的,這是她從旅途中學到的事。
You’ll also recognize a girl who travels by the fact that she’s always amazed at the world around her, no matter if she’s in her home town or in a place that’s totally new. She sees beauty all around her, not just the ones featured in travel guides or shown in postcards. A girl who travels has developed a deeper appreciation for life. She won’t judge you, or pressure you to do things you don’t want to do. She knows too much about the importance of identity and self-efficacy, and she will appreciate all the more if you won’t pretend to be who you’re not.
你也可以從旅行女孩那不管是在家鄉或是一個陌生城鎮,卻總能對她周遭事物充滿興趣的特質認出她。她可以發覺各式美麗事物,而不只是旅行指南或明信片上的熱門景點。一個旅行女孩會對生命由衷的欣賞,她不會武斷地評論你,也不會逼你做不情願的事。她清楚的知道自我肯定及認同的重要,如果你不矯揉造作,她對你加倍青睞。你可以對一個旅行女孩說謊,犯錯也沒有關係,你可以做最真實的自己。別擔心,她在旅途中碰過更糟的事,而且對變化莫測的人性也有深刻的認識。
Date a girl who travels, because when you’re with her, you’ll realize that even though she’s napped at a temple in Angkor Wat, went boating down the Mekong Delta, ran by the streets of Saigon, or went skinny-dipping in the caves in the Philippines , she still retains that humility that is the mark of a real traveler. She knows she’s been to a lot of places, but she’s humbled by the fact that the world is still a big place and she’s only seen a small part of it. Seeing this in her can make you feel all right with yourself too; there’s no need for you to do more, to be more. What you are is enough.
和一個旅行女孩約會吧。和她在一起你會發現,無論她在吳哥窟小憩,在湄公河划船,在西貢的街上奔跑,或是在菲律賓的洞穴裸泳,她都謹記著「謙遜」才是旅人最重要的特質。她知道她去過很多地方,但她很謙虛地了解這世界很大,自己走過的地方只是一小部份。這項特質讓你也覺得很自在,你不需要虛假誇大,只需要做你自己。
When you meet a girl who travels, ask her where she’s been and what she’s going to do next. She will appreciate your interest, and if you’re lucky, she may even invite you to join her. When she does, do. Nothing bonds people better than traveling. On your trips, you will both see each other’s best and worst characteristics, and you can then decide whether she’s worth fighting for.
當你認識一個旅行女孩,問問她去過哪裡、下一個旅行地點是哪裡,她會很欣賞你的用心。夠幸運的話,說不定她還會約你結伴同行。如果她開口,就跟她一起去吧。沒有一件事能比旅行更能拉近人與人之間的關係,在旅程中,你們會發現彼此的優點和缺點,你也可以因此決定她是不是個值得的對象。
It’s easy enough to date a girl who travels. She won’t want expensive gifts; you can buy her (or both of you) cheap tickets to Thailand for the weekend, and she’ll be more than happy to take you to the longest wooden bridge in the country. You don’t even have to go overseas; you can take her out on day trips, caving or hiking, or treat her to a full body massage.
You can also buy her the little things that she keeps forgetting to buy for herself; that carabiner that will attach her backpack to her seat so that she will feel easier about sleeping on her bus trip, or a backpack cover, a small alarm clock, a money belt, or maybe another sarong that will replace the one she lost in China.
和一個旅行女孩約會很簡單。她不渴求昂貴的禮物,你可以買張飛往泰國渡週末的廉價機票給她或是來一趟雙人之旅,她會帶你去看世界上最長的木橋;你們甚至不用出國,你可以帶她去個洞穴探險或爬山的一日小旅行,或是讓她享受一套全身按摩。你也可以送她一些她總是忘記買的小東西。那條能綁住她的背包和座椅的鍊條,讓她能在巴士旅途中睡個好覺;一個背包套、小鬧鐘、可以藏錢的腰帶、或是一條新沙龍來代替她在中國遺失那條。
She won’t mind if you get lost on your way to a date. She knows that oftentimes, the journey is more important than the destination. She will help you see the lighter side of things. She’ll walk along with you, not behind you, pointing out the interesting bits of things you’ll see on the way. Before long, you’ll realize that yes, the journey has been more memorable than the destination that you’ve planned to take her to.
一個旅行女孩不介意你約會時迷路,她知道多數時候旅行的過程比結果更重要。她會讓看到事情的光明面,走在你身旁而不是你後方,為你指出一路上將看到的趣事。不用多久你就會真的了解,和她一起尋找的過程其實比你要帶她去的目的地更讓你記憶深刻。
Is a girl who travels worth it? Yes, she is. So when you find her, keep her. Don’t lose her with your insecurities and doubts. Because when she says she loves you, she really does. After all, she’s seen so many things, met so many people, and if she had chosen you, better grab that opportunity and thank the gods that you were lucky enough she’s chosen you and not that bloke she met while watching the sun rise in Angkor Wat, or while whitewater rafting in the Padas Gorge in Sabah. If she says she loves you, she must have seen something in you, something that can always call her back from her travels, something that can anchor her to the world in the way that she wants to after weeks and months of being on the road.
一個旅行女孩值得你追求嗎?是的,她值得。所以當你碰上她時,請好好珍惜她。不要因為你的不安全感或懷疑而放手,因為當她說她愛你,那絕對千真萬確。畢竟她看過那麼多各式事物,認識了那麼多不同的人;如果她選擇了你,請好好把握這個機會,並感謝老天她選擇的是你,而不是那個她在吳哥窟並肩看夕陽的男孩,或她在沙巴巴達士泛舟的同伴。如果她說她愛你,表示她一定有發現你的某些特別之處;一些能讓她回憶起過去旅行的小細節,一個能讓她在四處漂蕩好幾個月後可以停泊的港灣。
Date a girl who travels. Make her feel safe, warm, and secure. Make her believe that no matter where she goes, and however long she’s gone, you’ll always be there for her, the one that she can call home.
和一個旅行女孩約會吧。給她安心和溫暖,讓她相信無論她去到哪裡,或是離開了多久,你都會在那個她能當作「家」的地方等待她。
Find a girl who travels. Date her, love her, and marry her, and your world will never be the same again.
找一個旅行女孩,和她約會,真愛她,讓她成為你的妻子。你的世界,將會因此而不同。
《《中文版譯自 Reddy Ting Ho。原文載自 Date A Girl Who Travels.》》
side part中文 在 Kouki Youtube 的評價
一輩子不能錯過的RPG作品,2015年極致好評 Undertale 。每周六日推出。
從今天起開始訂閱吧! ➔ http://bit.ly/Kouki
此影片有繁體中文翻譯,需開啟影片中的CC字幕。
Undertale ★ 播放清單 ★ ➔ https://www.youtube.com/playlist?list=PLtHA2VxfiZuXl1OkPc7IRvjCz0adMdB4P
To The Moon ★ 播放清單 ★ ➔ https://www.youtube.com/watch?v=EUNoivmtx6A&index=1&list=PLtHA2VxfiZuUcqRLfZAaH7hNA6yEve8Xe
留言禁止爆雷,感謝你對留言版的維護。
♫:Undertale
在Facebook上追蹤我 ➔ https://www.facebook.com/KamiKamiMatsu
在Twitter上追蹤我 ➔ https://twitter.com/Ashan_kouki
在粉絲團上追蹤我 ➔ facebook.com/oeurXstudio
Ending Pic : Jon Davies (SovanJedi) on deviantart
Side Pic : the-mischievous-fox on deviantart
Translation : 白樺
Thumbnail : MirU
Modifications : 阿神、鬼怒川
Transcript : 梅子
Subtitles : 路Rusiru
Microphone ➔ Zoom H2N
Keyboard ➔ Ducky 青軸
Mouse ➔ Razer TransFormers 大黃蜂款
直播頻道 ➔ http://bit.ly/koukilive

side part中文 在 emi wong Youtube 的評價
Finally the last day of my One Month Project Comeback!! Many of you requested a cooking video with my parents of all the yummy meals I eat everyday so here you go! (: Special thanks to my parents for being a part of this video.
♡SUBSCRIBE FOR WEEKLY VIDEOS ► http://bit.ly/SubscribeToEmi
♡ADD ME ON
INSTAGRAM: @EmiWong_ ► https://www.instagram.com/emiwong_
FACEBOOK: Emi Wong ► https://www.facebook.com/StayFitandTravel/
Girl in her 20s. Living in Hong Kong, working a full time office job in Marketing and making YouTube videos on the side. Also a Certified Advanced Personal Trainer.
(: MY FAVOURITE THINGS: Workout To Eat, My Family, Dog & Boyfriend
♡HELP ME TRANSLATE MY VIDEOS
http://www.youtube.com/timedtext_cs_panel?tab=2&c=UCvGEK5_U-kLgO6-AMDPeTUQ
♡INTRO SONG: Aarre - When We Were Young (ft. Reece Lemonius)
Spotify: https://open.spotify.com/track/14B6ipvBQ5pyP49lQ1KCjz?si=4QlubtsSS3SNKSiOFwdrkw
Soundcloud: https://soundcloud.com/aarre
Facebook: https://www.facebook.com/AarreMusic/
♡WATCH MORE VIDEOS (PLAYLISTS)
WHO IS EMI ► http://bit.ly/WhoIsEmi
WORKOUTS ► http://bit.ly/WorkoutWthEmi
BEGINNER WORKOUTS ► http://bit.ly/BeginnerWorkoutsWithEmi
FITNESS & DIET TIPS ► http://bit.ly/FitnessDietTipsWithEmi
EAT (FOOD VLOGS!) ► http://bit.ly/EatWithEmi
TRAVEL ► http://bit.ly/TravelWithEmi
RECIPES ► http://bit.ly/CookWithEmi
FUN CHALLENGES ► http://bit.ly/ChallengesWithEmi
MAKE UP & FASHION ► http://bit.ly/MakeUpFashionWithEmi
廣東話片 Videos in Cantonese ► http://bit.ly/CantoneseVideosEmi
有中文字幕的片 With Chinese Subtitles ► http://bit.ly/ChineseSubtitlesEmi

side part中文 在 Kouki Youtube 的評價
這次Undertale周末番到這裡完結囉!感謝大家這幾個月的支持❤,這集影片底下留言開放所有討論!
從今天起開始訂閱吧! ➔ http://bit.ly/Kouki
此影片有繁體中文翻譯,需開啟影片中的CC字幕。
Undertale ★ 播放清單 ★ ➔ https://www.youtube.com/playlist?list=PLtHA2VxfiZuXl1OkPc7IRvjCz0adMdB4P
To The Moon ★ 播放清單 ★ ➔ https://www.youtube.com/watch?v=EUNoivmtx6A&index=1&list=PLtHA2VxfiZuUcqRLfZAaH7hNA6yEve8Xe
留言禁止爆雷,感謝你對留言版的維護。
♫:Undertale
在Facebook上追蹤我 ➔ https://www.facebook.com/KamiKamiMatsu
在Twitter上追蹤我 ➔ https://twitter.com/Ashan_kouki
在粉絲團上追蹤我 ➔ facebook.com/oeurXstudio
Side Pic : the-mischievous-fox on deviantart
Translation : 鬼怒川
Thumbnail : MirU
Modifications : 阿神、鬼怒川
Transcript : 鬼怒川
Subtitles : 路Rusiru
Microphone ➔ Zoom H2N
Keyboard ➔ Ducky 青軸
Mouse ➔ Razer TransFormers 大黃蜂款
直播頻道 ➔ http://bit.ly/koukilive

side part中文 在 Using OAuth 2.0 for Web Server Applications 的八卦
This document explains how web server applications use Google API Client Libraries or Google
OAuth 2.0 endpoints to implement OAuth 2.0 authorization to access
the YouTube Data API.
OAuth 2.0 allows users to share specific data with an application while keeping their
usernames, passwords, and other information private.
For example, an application can use OAuth 2.0 to obtain permission
to upload videos to a user's YouTube channel.
This OAuth 2.0 flow is specifically for user authorization. It is designed for applications
that can store confidential information and maintain state. A properly authorized web server
application can access an API while the user interacts with the application or after the user
has left the application.
Web server applications frequently also use
service accounts to authorize API requests, particularly when calling Cloud APIs to access
project-based data rather than user-specific data. Web server applications can use service
accounts in conjunction with user authorization.
Note that the YouTube Data API supports the service account flow only for
YouTube content owners that own and manage multiple YouTube channels.
Specifically, content owners can use service accounts to call API methods that
support the onBehalfOfContentOwner
request parameter.
Note: Given the security implications of getting the implementation
correct, we strongly encourage you to use OAuth 2.0 libraries when interacting with Google's
OAuth 2.0 endpoints. It is a best practice to use well-debugged code provided by others, and
it will help you protect yourself and your users. For more information, see
Client libraries.
Client libraries
The language-specific examples on this page use
Google API Client Libraries to implement
OAuth 2.0 authorization. To run the code samples, you must first install the
client library for your language.
When you use a Google API Client Library to handle your application's OAuth 2.0 flow, the client
library performs many actions that the application would otherwise need to handle on its own. For
example, it determines when the application can use or refresh stored access tokens as well as
when the application must reacquire consent. The client library also generates correct redirect
URLs and helps to implement redirect handlers that exchange authorization codes for access tokens.
Google API Client Libraries for server-side applications are available for the following languages:
Go
Java
.NET
Node.js
PHP
Python
Ruby
Important: The Google API client
library for JavaScript and Sign In With Google are
only intended to handle OAuth 2.0 in the user's browser. If you want to use JavaScript on the
server-side to manage OAuth 2.0 interactions with Google, consider using the
Node.js library on your back-end platform.
Prerequisites
Enable APIs for your project
Any application that calls Google APIs needs to enable those APIs in the
API Console.
To enable an API for your project:
Open the API Library in the
Google API Console.
If prompted, select a project, or create a new one. Use the Library page to find and enable the YouTube Data API. Find any other
APIs that your application will use and enable those, too.
Create authorization credentials
Any application that uses OAuth 2.0 to access Google APIs must have authorization credentials
that identify the application to Google's OAuth 2.0 server. The following steps explain how to
create credentials for your project. Your applications can then use the credentials to access APIs
that you have enabled for that project.
Go to the Clients page.
Click Create Client.
Select the Web application application type.
Fill in the form and click Create. Applications that use languages and frameworks
like PHP, Java, Python, Ruby, and .NET must specify authorized redirect URIs. The
redirect URIs are the endpoints to which the OAuth 2.0 server can send responses. These
endpoints must adhere to Google’s validation rules.
For testing, you can specify URIs that refer to the local machine, such as
http://localhost:8080
. With that in mind, please note that all of the
examples in this document use http://localhost:8080
as the redirect URI.
We recommend that you design your app's auth endpoints so
that your application does not expose authorization codes to other resources on the
page.
After creating your credentials, download the client_secret.json file from the
API Console. Securely store the file in a location that only
your application can access.
publicly-accessible location. In addition, if you share the source code to your
application — for example, on GitHub — store the client_secret.json file
outside of your source tree to avoid inadvertently sharing your client credentials.
Identify access scopes
Scopes enable your application to only request access to the resources that it needs while also
enabling users to control the amount of access that they grant to your application. Thus, there
may be an inverse relationship between the number of scopes requested and the likelihood of
obtaining user consent.
Before you start implementing OAuth 2.0 authorization, we recommend that you identify the scopes
that your app will need permission to access.
We also recommend that your application request access to authorization scopes via an
incremental authorization process, in which your application
requests access to user data in context. This best practice helps users to more easily understand
why your application needs the access it is requesting.
The YouTube Data API v3 uses the following scopes:
Scopes
https://www.googleapis.com/auth/youtubeManage your YouTube account
https://www.googleapis.com/auth/youtube.channel-memberships.creatorSee a list of your current active channel members, their current level, and when they became a member
https://www.googleapis.com/auth/youtube.force-sslSee, edit, and permanently delete your YouTube videos, ratings, comments and captions
https://www.googleapis.com/auth/youtube.readonlyView your YouTube account
https://www.googleapis.com/auth/youtube.uploadManage your YouTube videos
https://www.googleapis.com/auth/youtubepartnerView and manage your assets and associated content on YouTube
https://www.googleapis.com/auth/youtubepartner-channel-auditView private information of your YouTube channel relevant during the audit process with a YouTube partner
The OAuth 2.0 API Scopes document contains a full
list of scopes that you might use to access Google APIs.
If your public application uses scopes that permit access to
certain user data, it must complete a verification process. If you see unverified
app on the screen when testing your application, you must submit a
verification request to remove it. Find out more about
unverified apps
and get answers to
frequently asked questions about app verification in the Help Center.
Language-specific requirements
To run any of the code samples in this document, you'll need a Google account, access to the
Internet, and a web browser. If you are using one of the API client libraries, also see the
language-specific requirements below.
To run the PHP code samples in this document, you'll need:
PHP 8.0 or greater with the command-line interface (CLI) and JSON extension installed.
The Composer dependency management tool.
The Google APIs Client Library for PHP:
composer require google/apiclient:^2.15.0
See Google APIs Client Library for
PHP for more information.
To run the Python code samples in this document, you'll need:
Python 3.7 or greater
The pip package management tool.
The Google APIs Client Library for Python 2.0 release:
pip install --upgrade google-api-python-client
The
google-auth
, google-auth-oauthlib
, andgoogle-auth-httplib2
for user authorization.
pip install --upgrade google-auth google-auth-oauthlib google-auth-httplib2
The Flask Python web application framework.
pip install --upgrade flask
The
requests
HTTP library.
pip install --upgrade requests
Review the Google API Python client library
release note
if you aren't able to upgrade python and associated migration guide.
To run the Ruby code samples in this document, you'll need:
Ruby 2.6 or greater
The Google Auth Library for Ruby:
gem install googleauth
The Sinatra Ruby web application framework.
gem install sinatra
Node.js
To run the Node.js code samples in this document, you'll need:
The maintenance LTS, active LTS, or current release of Node.js.
The Google APIs Node.js Client:
npm install googleapis crypto express express-session
HTTP/REST
You do not need to install any libraries to be able to directly call the OAuth 2.0
endpoints.
Obtaining OAuth 2.0 access tokens
The following steps show how your application interacts with Google's OAuth 2.0 server to obtain
a user's consent to perform an API request on the user's behalf. Your application must have that
consent before it can execute a Google API request that requires user authorization.
The list below quickly summarizes these steps:
Your application identifies the permissions it needs.
Your application redirects the user to Google along with the list of requested
permissions.
The user decides whether to grant the permissions to your application.
Your application finds out what the user decided.
If the user granted the requested permissions, your application retrieves tokens needed to
make API requests on the user's behalf.
Step 1: Set authorization parameters
Your first step is to create the authorization request. That request sets parameters that
identify your application and define the permissions that the user will be asked to grant to
your application.
If you use a Google client library for OAuth 2.0 authentication and authorization, you
create and configure an object that defines these parameters.
If you call the Google OAuth 2.0 endpoint directly, you'll generate a URL and set the
parameters on that URL.
The tabs below define the supported authorization parameters for web server applications. The
language-specific examples also show how to use a client library or authorization library to
configure an object that sets those parameters.
The following code snippet creates a Google\Client()
object, which defines the
parameters in the authorization request.
That object uses information from your client_secret.json file to identify your
application. (See creating authorization credentials for more about
that file.) The object also identifies the scopes that your application is requesting permission
to access and the URL to your application's auth endpoint, which will handle the response from
Google's OAuth 2.0 server. Finally, the code sets the optional access_type
and
include_granted_scopes
parameters.
For example, this code requests offline access to manage a user's YouTube
account:
use Google\Client;$client = new Client();// Required, call the setAuthConfig function to load authorization credentials fromPython
// client_secret.json file.
$client->setAuthConfig('client_secret.json');// Required, to set the scope value, call the addScope function
$client->addScope(GOOGLE_SERVICE_YOUTUBE::YOUTUBE_FORCE_SSL);// Required, call the setRedirectUri function to specify a valid redirect URI for the
// provided client_id
$client->setRedirectUri('http://' . $_SERVER['HTTP_HOST'] . '/oauth2callback.php');// Recommended, offline access will give you both an access and refresh token so that
// your app can refresh the access token without user interaction.
$client->setAccessType('offline');// Recommended, call the setState function. Using a state value can increase your assurance that
// an incoming connection is the result of an authentication request.
$client->setState($sample_passthrough_value);// Optional, if your application knows which user is trying to authenticate, it can use this
// parameter to provide a hint to the Google Authentication Server.
$client->setLoginHint('hint@example.com');// Optional, call the setPrompt function to set "consent" will prompt the user for consent
$client->setPrompt('consent');// Optional, call the setIncludeGrantedScopes function with true to enable incremental
// authorization
$client->setIncludeGrantedScopes(true);
The following code snippet uses the google-auth-oauthlib.flow
module to construct
the authorization request.
The code constructs a Flow
object, which identifies your application using
information from the client_secret.json file that you downloaded after
creating authorization credentials. That object also identifies the
scopes that your application is requesting permission to access and the URL to your application's
auth endpoint, which will handle the response from Google's OAuth 2.0 server. Finally, the code
sets the optional access_type
and include_granted_scopes
parameters.
For example, this code requests offline access to manage a user's YouTube
account:
import google.oauth2.credentialsRuby
import google_auth_oauthlib.flow# Required, call the from_client_secrets_file method to retrieve the client ID from a
# client_secret.json file. The client ID (from that file) and access scopes are required. (You can
# also use the from_client_config method, which passes the client configuration as it originally
# appeared in a client secrets file but doesn't access the file itself.)
flow = google_auth_oauthlib.flow.Flow.from_client_secrets_file('client_secret.json',
scopes=['https://www.googleapis.com/auth/youtube.force-ssl'])# Required, indicate where the API server will redirect the user after the user completes
# the authorization flow. The redirect URI is required. The value must exactly
# match one of the authorized redirect URIs for the OAuth 2.0 client, which you
# configured in the API Console. If this value doesn't match an authorized URI,
# you will get a 'redirect_uri_mismatch' error.
flow.redirect_uri = 'https://www.example.com/oauth2callback'# Generate URL for request to Google's OAuth 2.0 server.
# Use kwargs to set optional request parameters.
authorization_url, state = flow.authorization_url(
# Recommended, enable offline access so that you can refresh an access token without
# re-prompting the user for permission. Recommended for web server apps.
access_type='offline',
# Optional, enable incremental authorization. Recommended as a best practice.
include_granted_scopes='true',
# Optional, if your application knows which user is trying to authenticate, it can use this
# parameter to provide a hint to the Google Authentication Server.
login_hint='hint@example.com',
# Optional, set prompt to 'consent' will prompt the user for consent
prompt='consent')
Use the client_secrets.json file that you created to configure a client object in your
application. When you configure a client object, you specify the scopes your application needs to
access, along with the URL to your application's auth endpoint, which will handle the response
from the OAuth 2.0 server.
For example, this code requests offline access to manage a user's YouTube
account:
require 'googleauth'
require 'googleauth/web_user_authorizer'
require 'googleauth/stores/redis_token_store'require 'google/apis/youtube_v3'# Required, call the from_file method to retrieve the client ID from a
# client_secret.json file.
client_id = Google::Auth::ClientId.from_file('/path/to/client_secret.json')# Required, scope value
scope = 'https://www.googleapis.com/auth/youtube.force-ssl'# Required, Authorizers require a storage instance to manage long term persistence of
# access and refresh tokens.
token_store = Google::Auth::Stores::RedisTokenStore.new(redis: Redis.new)# Required, indicate where the API server will redirect the user after the user completes
# the authorization flow. The redirect URI is required. The value must exactly
# match one of the authorized redirect URIs for the OAuth 2.0 client, which you
# configured in the API Console. If this value doesn't match an authorized URI,
# you will get a 'redirect_uri_mismatch' error.
callback_uri = '/oauth2callback'# To use OAuth2 authentication, we need access to a CLIENT_ID, CLIENT_SECRET, AND REDIRECT_URI
# from the client_secret.json file. To get these credentials for your application, visit
# https://console.cloud.google.com/apis/credentials.
authorizer = Google::Auth::WebUserAuthorizer.new(client_id, scope,
token_store, callback_uri)
Your application uses the client object to perform OAuth 2.0 operations, such as generating
authorization request URLs and applying access tokens to HTTP requests.
The following code snippet creates a google.auth.OAuth2
object, which defines the
parameters in the authorization request.
That object uses information from your client_secret.json file to identify your application. To
ask for permissions from a user to retrieve an access token, you redirect them to a consent page.
To create a consent page URL:
const {google} = require('googleapis');
const crypto = require('crypto');
const express = require('express');
const session = require('express-session');/**
* To use OAuth2 authentication, we need access to a CLIENT_ID, CLIENT_SECRET, AND REDIRECT_URI
* from the client_secret.json file. To get these credentials for your application, visit
* https://console.cloud.google.com/apis/credentials.
*/
const oauth2Client = new google.auth.OAuth2(
YOUR_CLIENT_ID,
YOUR_CLIENT_SECRET,
YOUR_REDIRECT_URL
);// Access scopes for YouTube API
const scopes = [
'https://www.googleapis.com/auth/youtube.force-ssl'
];// Generate a secure random state value.
const state = crypto.randomBytes(32).toString('hex');// Store state in the session
req.session.state = state;// Generate a url that asks permissions for the Drive activity and Google Calendar scope
const authorizationUrl = oauth2Client.generateAuthUrl({
// 'online' (default) or 'offline' (gets refresh_token)
access_type: 'offline',
/** Pass in the scopes array defined above.
* Alternatively, if only one scope is needed, you can pass a scope URL as a string */
scope: scopes,
// Enable incremental authorization. Recommended as a best practice.
include_granted_scopes: true,
// Include the state parameter to reduce the risk of CSRF attacks.
state: state
});
Important Note - The refresh_token
is only returned on the first
authorization. More details
here.
Google's OAuth 2.0 endpoint is at https://accounts.google.com/o/oauth2/v2/auth
. This
endpoint is accessible only over HTTPS. Plain HTTP connections are refused.
The Google authorization server supports the following query string parameters for web
server applications:
Parameters
client_id
Required
The client ID for your application. You can find this value in the
Cloud Console
Clients page.
redirect_uri
Required
Determines where the API server redirects the user after the user completes the
authorization flow. The value must exactly match one of the authorized redirect URIs for
the OAuth 2.0 client, which you configured in your client's
Cloud Console
Clients page. If this value doesn't match an
authorized redirect URI for the provided client_id
you will get a
redirect_uri_mismatch
error.
Note that the http
or https
scheme, case, and trailing slash
('/
') must all match.
response_type
Required
Determines whether the Google OAuth 2.0 endpoint returns an authorization code.
Set the parameter value to code
for web server applications.
scope
Required
A
space-delimited
list of scopes that identify the resources that your application could access on the
user's behalf. These values inform the consent screen that Google displays to the
user.
Scopes enable your application to only request access to the resources that it needs
while also enabling users to control the amount of access that they grant to your
application. Thus, there is an inverse relationship between the number of scopes requested
and the likelihood of obtaining user consent.
The YouTube Data API v3 uses the following scopes:
Scopes
https://www.googleapis.com/auth/youtubeManage your YouTube account
https://www.googleapis.com/auth/youtube.channel-memberships.creatorSee a list of your current active channel members, their current level, and when they became a member
https://www.googleapis.com/auth/youtube.force-sslSee, edit, and permanently delete your YouTube videos, ratings, comments and captions
https://www.googleapis.com/auth/youtube.readonlyView your YouTube account
https://www.googleapis.com/auth/youtube.uploadManage your YouTube videos
https://www.googleapis.com/auth/youtubepartnerView and manage your assets and associated content on YouTube
https://www.googleapis.com/auth/youtubepartner-channel-auditView private information of your YouTube channel relevant during the audit process with a YouTube partner
The OAuth 2.0 API Scopes document provides
a full list of scopes that you might use to access Google APIs.
We recommend that your application request access to authorization scopes in context
whenever possible. By requesting access to user data in context, via
incremental authorization, you help users to more easily
understand why your application needs the access it is requesting.
access_type
Recommended
Indicates whether your application can refresh access tokens when the user is not present
at the browser. Valid parameter values are online
, which is the default
value, and offline
.
Set the value to offline
if your application needs to refresh access tokens
when the user is not present at the browser. This is the method of refreshing access
tokens described later in this document. This value instructs the Google authorization
server to return a refresh token and an access token the first time that your
application exchanges an authorization code for tokens.
state
Recommended
Specifies any string value that your application uses to maintain state between your
authorization request and the authorization server's response.
The server returns the exact value that you send as a name=value
pair in the
URL query component (?
) of the
redirect_uri
after the user consents to or denies your application's
access request.
You can use this parameter for several purposes, such as directing the user to the
correct resource in your application, sending nonces, and mitigating cross-site request
forgery. Since your redirect_uri
can be guessed, using a state
value can increase your assurance that an incoming connection is the result of an
authentication request. If you generate a random string or encode the hash of a cookie or
another value that captures the client's state, you can validate the response to
additionally ensure that the request and response originated in the same browser,
providing protection against attacks such as
cross-site request
forgery. See the
OpenID Connect
documentation for an example of how to create and confirm a state
token.
Important: The OAuth client must prevent CSRF as called out in the
OAuth2 Specification
. One way to achieve this is by using the
state
parameter to maintainstate between your authorization request and the authorization server's response.
include_granted_scopes
Optional
Enables applications to use incremental authorization to request access to additional
scopes in context. If you set this parameter's value to true
and the
authorization request is granted, then the new access token will also cover any scopes to
which the user previously granted the application access. See the
incremental authorization section for examples.
enable_granular_consent
Optional
Defaults to true
. If set to false
,
more
granular Google Account permissions
will be disabled for OAuth client IDs created before 2019. No effect for newer
OAuth client IDs, since more granular permissions is always enabled for them.
When Google enables granular permissions for an application, this parameter will no
longer have any effect.
login_hint
Optional
If your application knows which user is trying to authenticate, it can use this parameter
to provide a hint to the Google Authentication Server. The server uses the hint to
simplify the login flow either by prefilling the email field in the sign-in form or by
selecting the appropriate multi-login session.
Set the parameter value to an email address or sub
identifier, which is
equivalent to the user's Google ID.
prompt
Optional
A space-delimited, case-sensitive list of prompts to present the user. If you don't
specify this parameter, the user will be prompted only the first time your project
requests access. See
Prompting re-consent for more information.
Possible values are:
none
Do not display any authentication or consent screens. Must not be specified with
other values.
consent
Prompt the user for consent.
select_account
Prompt the user to select an account.
Step 2: Redirect to Google's OAuth 2.0 server
Redirect the user to Google's OAuth 2.0 server to initiate the authentication and
authorization process. Typically, this occurs when your application first needs to access the
user's data. In the case of incremental authorization, this
step also occurs when your application first needs to access additional resources that it does
not yet have permission to access.
Generate a URL to request access from Google's OAuth 2.0 server:
$auth_url = $client->createAuthUrl();
Redirect the user to
$auth_url
:header('Location: ' . filter_var($auth_url, FILTER_SANITIZE_URL));
Python
This example shows how to redirect the user to the authorization URL using the Flask web
application framework:
return flask.redirect(authorization_url)Ruby
Generate a URL to request access from Google's OAuth 2.0 server:
auth_uri = authorizer.get_authorization_url(request: request)
Redirect the user to
auth_uri
.Node.js
Use the generated URL
authorizationUrl
from Step 1generateAuthUrl
method to request access from Google's OAuth 2.0 server.Redirect the user to
authorizationUrl
.res.redirect(authorizationUrl);
HTTP/REST Sample redirect to Google's authorization server
The sample URL below requests offline access
(access_type=offline
) to a scope that permits access to view
the user's YouTube account. It uses incremental authorization to ensure that
the new access token covers any scopes to which the user previously granted
the application access. The URL also sets values for the required
redirect_uri
, response_type
, and
client_id
parameters as well as for the state
parameter. The URL contains line breaks and spaces for readability.
https://accounts.google.com/o/oauth2/v2/auth?
scope=https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fyoutube.readonly&
access_type=offline&
include_granted_scopes=true&
state=state_parameter_passthrough_value&
redirect_uri=http%3A%2F%2Flocalhost%2Foauth2callback&
response_type=code&
client_id=client_id
After you create the request URL, redirect the user to it.
Google's OAuth 2.0 server authenticates the user and obtains consent from the user for your
application to access the requested scopes. The response is sent back to your application
using the redirect URL you specified.
In this step, the user decides whether to grant your application the requested access. At this
stage, Google displays a consent window that shows the name of your application and the Google API
services that it is requesting permission to access with the user's authorization credentials and
a summary of the scopes of access to be granted. The
user can then consent to grant access to one or more scopes requested by your application or
refuse the request.
Your application doesn't need to do anything at this stage as it waits for the response from
Google's OAuth 2.0 server indicating whether any access was granted. That response is explained in
the following step.
Errors
Requests to Google's OAuth 2.0 authorization endpoint may display user-facing error messages
instead of the expected authentication and authorization flows. Common error codes and suggested
resolutions are listed below.
admin_policy_enforced
The Google Account is unable to authorize one or more scopes requested due to the policies of
their Google Workspace administrator. See the Google Workspace Admin help article
Control which third-party & internal apps access Google Workspace data
for more information about how an administrator may restrict access to all scopes or sensitive and
restricted scopes until access is explicitly granted to your OAuth client ID.
disallowed_useragent
The authorization endpoint is displayed inside an embedded user-agent disallowed by Google's
OAuth 2.0 Policies.
Android
Android developers may encounter this error message when opening authorization requests in
android.webkit.WebView
.
Developers should instead use Android libraries such as
Google Sign-In for Android or OpenID Foundation's
AppAuth for Android.
Web developers may encounter this error when an Android app opens a general web link in an
embedded user-agent and a user navigates to Google's OAuth 2.0 authorization endpoint from
your site. Developers should allow general links to open in the default link handler of the
operating system, which includes both
Android App Links
handlers or the default browser app. The
Android Custom Tabs
library is also a supported option.
iOS
iOS and macOS developers may encounter this error when opening authorization requests in
WKWebView
.
Developers should instead use iOS libraries such as
Google Sign-In for iOS or OpenID Foundation's
AppAuth for iOS.
Web developers may encounter this error when an iOS or macOS app opens a general web link in
an embedded user-agent and a user navigates to Google's OAuth 2.0 authorization endpoint from
your site. Developers should allow general links to open in the default link handler of the
operating system, which includes both
Universal Links
handlers or the default browser app. The
SFSafariViewController
library is also a supported option.
org_internal
The OAuth client ID in the request is part of a project limiting access to Google Accounts in a
specific
Google Cloud Organization.
For more information about this configuration option see the
User type
section in the Setting up your OAuth consent screen help article.
invalid_client
The OAuth client secret is incorrect. Review the
OAuth client
configuration, including the client ID and secret used for this request.
invalid_grant
When refreshing an access token or using
incremental authorization, the token may have expired or has
been invalidated.
Authenticate the user again and ask for user consent to obtain new tokens. If you are continuing
to see this error, ensure that your application has been configured correctly and that you are
using the correct tokens and parameters in your request. Otherwise, the user account may have
been deleted or disabled.
redirect_uri_mismatch
The redirect_uri
passed in the authorization request does not match an authorized
redirect URI for the OAuth client ID. Review authorized redirect URIs in the
Google Cloud Console
Clients page.
The redirect_uri
parameter may refer to the OAuth out-of-band (OOB) flow that has
been deprecated and is no longer supported. Refer to the
migration guide to update your
integration.
invalid_request
There was something wrong with the request you made. This could be due to a number of reasons:
The request was not properly formatted
The request was missing required parameters
The request uses an authorization method that Google doesn't support. Verify your OAuth
integration uses a recommended integration method
Step 4: Handle the OAuth 2.0 server response Important:
Before handling the OAuth 2.0 response on the server, you should confirm that the
state
received from Google matches the state
sent in theauthorization request. This verification helps to ensure that the user, not a malicious
script, is making the request and reduces the risk of
CSRF attacks.
The OAuth 2.0 server responds to your application's access request by using the URL specified
in the request.
If the user approves the access request, then the response contains an authorization code. If
the user does not approve the request, the response contains an error message. The
authorization code or error message that is returned to the web server appears on the query
string, as shown below:
An error response:
https://oauth2.example.com/auth?error=access_denied
An authorization code response:
Important: If your response endpoint renders an
https://oauth2.example.com/auth?code=4/P7q7W91a-oMsCeLvIaQm6bTrgtp7
HTML page, any resources on that page will be able to see the authorization code in the URL.
Scripts can read the URL directly, and the URL in the
Referer
HTTP header may besent to any or all resources on the page.
Carefully consider whether you want to send authorization credentials to all resources on
that page (especially third-party scripts such as social plugins and analytics). To avoid
this issue, we recommend that the server first handle the request, then redirect to another
URL that doesn't include the response parameters.
You can test this flow by clicking on the following sample URL, which requests
read-only access to view metadata for files in your Google Drive and read-only
access to view your Google Calendar events:
https://accounts.google.com/o/oauth2/v2/auth?
scope=https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fyoutube.readonly&
access_type=offline&
include_granted_scopes=true&
state=state_parameter_passthrough_value&
redirect_uri=http%3A%2F%2Flocalhost%2Foauth2callback&
response_type=code&
client_id=client_id
After completing the OAuth 2.0 flow, you should be redirected to
http://localhost/oauth2callback
, which will likely yield a
404 NOT FOUND
error unless your local machine serves a file at that address. The
next step provides more detail about the information returned in the URI when the user is
redirected back to your application.
tokens
After the web server receives the authorization code, it can exchange the authorization code
for an access token.
To exchange an authorization code for an access token, use the
fetchAccessTokenWithAuthCode
method:
$access_token = $client->fetchAccessTokenWithAuthCode($_GET['code']);
Python On your callback page, use the google-auth
library to verify the authorization
server response. Then, use the flow.fetch_token
method to exchange the authorization
code in that response for an access token:
state = flask.session['state']Ruby
flow = google_auth_oauthlib.flow.Flow.from_client_secrets_file(
'client_secret.json',
scopes=['https://www.googleapis.com/auth/youtube.force-ssl'],
state=state)
flow.redirect_uri = flask.url_for('oauth2callback', _external=True)authorization_response = flask.request.url
flow.fetch_token(authorization_response=authorization_response)# Store the credentials in the session.
# ACTION ITEM for developers:
# Store user's access and refresh tokens in your data store if
# incorporating this code into your real app.
credentials = flow.credentials
flask.session['credentials'] = {
'token': credentials.token,
'refresh_token': credentials.refresh_token,
'token_uri': credentials.token_uri,
'client_id': credentials.client_id,
'client_secret': credentials.client_secret,
'granted_scopes': credentials.granted_scopes}
On your callback page, use the googleauth
library to verify the authorization server
response. Use the authorizer.handle_auth_callback_deferred
method to save the
authorization code and redirect back to the URL that originally requested authorization. This
defers the exchange of the code by temporarily stashing the results in the user's session.
target_url = Google::Auth::WebUserAuthorizer.handle_auth_callback_deferred(request)Node.js
redirect target_url
To exchange an authorization code for an access token, use the getToken
method:
const url = require('url');// Receive the callback from Google's OAuth 2.0 server.HTTP/REST
app.get('/oauth2callback', async (req, res) => {
let q = url.parse(req.url, true).query; if (q.error) { // An error response e.g. error=access_denied
console.log('Error:' + q.error);
} else if (q.state !== req.session.state) { //check state value
console.log('State mismatch. Possible CSRF attack');
res.end('State mismatch. Possible CSRF attack');
} else { // Get access and refresh tokens (if access_type is offline) let { tokens } = await oauth2Client.getToken(q.code);
oauth2Client.setCredentials(tokens);
});
To exchange an authorization code for an access token, call the
https://oauth2.googleapis.com/token
endpoint and set the following parameters:
Fields
client_id
The client ID obtained from the Cloud Console
Clients page.
client_secret
The client secret obtained from the Cloud Console
Clients page.
code
The authorization code returned from the initial request.
grant_type
As defined in the OAuth 2.0
specification, this field's value must be set to
authorization_code
.redirect_uri
One of the redirect URIs listed for your project in the
Cloud Console
Clients page for the given
client_id
.The following snippet shows a sample request:
POST /token HTTP/1.1
Host: oauth2.googleapis.com
Content-Type: application/x-www-form-urlencodedcode=4/P7q7W91a-oMsCeLvIaQm6bTrgtp7&
client_id=your_client_id&
client_secret=your_client_secret&
redirect_uri=https%3A//oauth2.example.com/code&
grant_type=authorization_code
Google responds to this request by returning a JSON object that contains a short-lived access
token and a refresh token. Note that the refresh token is only returned if your application set the access_type
parameter to offline
in the initial request to Google's
authorization server.
The response contains the following fields:
Fields
access_token
The token that your application sends to authorize a Google API request.
expires_in
The remaining lifetime of the access token in seconds.
refresh_token
A token that you can use to obtain a new access token. Refresh tokens are valid until the
user revokes access.
Again, this field is only present in this response if you set the
access_type
parameter to
offline
in the initial request to Google's authorization server.scope
The scopes of access granted by the
access_token
expressed as a list ofspace-delimited, case-sensitive strings.
token_type
The type of token returned. At this time, this field's value is always set to
Bearer
.Important: Your application should store both tokens in a secure,
long-lived location that is accessible between different invocations of your application. The
refresh token enables your application to obtain a new access token if the one that you have
expires. As such, if your application loses the refresh token, the user will need to repeat the
OAuth 2.0 consent flow so that your application can obtain a new refresh token.
The following snippet shows a sample response:
{Note: Your application should ignore any unrecognized fields included in
"access_token": "1/fFAGRNJru1FTz70BzhT3Zg",
"expires_in": 3920,
"token_type": "Bearer",
"scope": "https://www.googleapis.com/auth/youtube.force-ssl",
"refresh_token": "1//xEoDL4iW3cxlI7yDbSRFYNG01kVKM2C-259HOF2aQbI"
}
the response.
Errors
When exchanging the authorization code for an access token you may encounter the following
error instead of the expected response. Common error codes and suggested resolutions are
listed below.
invalid_grant
The supplied authorization code is invalid or in the wrong format. Request a new code by
restarting the OAuth process to prompt the user for consent
again.
Step 6: Check which scopes users granted
When requesting multiple permissions (scopes), users may not grant your app access to
all of them. Your app must verify which scopes were actually granted and gracefully handle
situations where some permissions are denied, typically by disabling the features that rely
on those denied scopes.
However, there are exceptions. Google Workspace Enterprise apps with
domain-wide delegation of authority,
or apps marked as
Trusted,
bypass the granular permissions consent screen. For these apps, users won't see the
granular permission consent screen. Instead, your app will either receive all requested
scopes or none.
For more detailed information, see
How to handle granular permissions.
To check which scopes the user has granted, use the getGrantedScope()
method:
// Space-separated string of granted scopes if it exists, otherwise null.Python
$granted_scopes = $client->getOAuth2Service()->getGrantedScope();
The returned credentials
object has a granted_scopes
property,
which is a list of scopes the user has granted to your app.
credentials = flow.credentials
flask.session['credentials'] = {
'token': credentials.token,
'refresh_token': credentials.refresh_token,
'token_uri': credentials.token_uri,
'client_id': credentials.client_id,
'client_secret': credentials.client_secret,
'granted_scopes': credentials.granted_scopes}
Ruby
When requesting multiple scopes at once, check which scopes were granted through
the scope
property of the credentials
object.
# User authorized the request. Now, check which scopes were granted.Node.js
if credentials.scope.include?(Google::Apis::YoutubeV3::AUTH_YOUTUBE_FORCE_SSL)
# User authorized permission to see, edit, and permanently delete the
# YouTube videos, ratings, comments and captions.
# Calling the APIs, etc
else
# User didn't authorize the permission.
# Update UX and application accordingly
end
When requesting multiple scopes at once, check which scopes were granted through
the scope
property of the tokens
object.
// User authorized the request. Now, check which scopes were granted.HTTP/REST
if (tokens.scope.includes('https://www.googleapis.com/auth/youtube.force-ssl'))
{
// User authorized permission to see, edit, and permanently delete the
// YouTube videos, ratings, comments and captions.
// Calling the APIs, etc.
}
else
{
// User didn't authorize read-only Drive activity permission.
// Update UX and application accordingly
}
To check whether the user has granted your application access to a particular scope,
exam the scope
field in the access token response. The scopes of access granted by
the access_token expressed as a list of space-delimited, case-sensitive strings.
For example, the following sample access token response indicates that the user has granted your
application permission to see, edit, and permanently delete user's YouTube videos, ratings,
comments and captions:
{
"access_token": "1/fFAGRNJru1FTz70BzhT3Zg",
"expires_in": 3920,
"token_type": "Bearer",
"scope": "https://www.googleapis.com/auth/youtube.force-ssl",
"refresh_token": "1//xEoDL4iW3cxlI7yDbSRFYNG01kVKM2C-259HOF2aQbI"
}
Call Google APIs
Use the access token to call Google APIs by completing the following steps:
If you need to apply an access token to a new
Google\Client
object — forexample, if you stored the access token in a user session — use the
setAccessToken
method: $client->setAccessToken($access_token);
Build a service object for the API that you want to call. You build a service object by
providing an authorized
Google\Client
object to the constructor for the API youwant to call.
For example, to call the YouTube Data API:
$youtube = new Google_Service_YouTube($client);
Make requests to the API service using the
interface provided by the service object.
For example, to retrieve data about the authorized user's YouTube channel:
$channel = $youtube->channels->listChannels('snippet', array('mine' => $mine));
Python
After obtaining an access token, your application can use that token to authorize API requests on
behalf of a given user account or service account. Use the user-specific authorization credentials
to build a service object for the API that you want to call, and then use that object to make
authorized API requests.
Build a service object for the API that you want to call. You build a service object by
calling the
googleapiclient.discovery
library's build
method with thename and version of the API and the user credentials:
For example, to call version 3 of the YouTube Data API:
from googleapiclient.discovery import buildyoutube = build('youtube', 'v3', credentials=credentials)
Make requests to the API service using the
interface provided by the service object.
For example, to retrieve data about the authorized user's YouTube channel:
channel = youtube.channels().list(mine=True, part='snippet').execute()
Ruby
After obtaining an access token, your application can use that token to make API requests on
behalf of a given user account or service account. Use the user-specific authorization credentials
to build a service object for the API that you want to call, and then use that object to make
authorized API requests.
Build a service object for the API that you want to call.
For example, to call version 3 of the YouTube Data API:
youtube = Google::Apis::YoutubeV3::YouTubeService.new
Set the credentials on the service:
youtube.authorization = credentials
Make requests to the API service using the
interface
provided by the service object.
For example, to retrieve data about the authorized user's YouTube channel:
channel = youtube.list_channels(part, :mine => mine)
Alternately, authorization can be provided on a per-method basis by supplying the
options
parameter to a method:
channel = youtube.list_channels(part, :mine => mine, options: { authorization: auth_client })
Node.js
After obtaining an access token and setting it to the OAuth2
object, use the object
to call Google APIs. Your application can use that token to authorize API requests on behalf of
a given user account or service account. Build a service object for the API that you want to call.
For example, the following code uses the Google Drive API to list filenames in the user's Drive.
const { google } = require('googleapis');// Example of using YouTube API to list channels.HTTP/REST
var service = google.youtube('v3');
service.channels.list({
auth: oauth2Client,
part: 'snippet,contentDetails,statistics',
forUsername: 'GoogleDevelopers'
}, function (err, response) {
if (err) {
console.log('The API returned an error: ' + err);
return;
}
var channels = response.data.items;
if (channels.length == 0) {
console.log('No channel found.');
} else {
console.log('This channel\'s ID is %s. Its title is \'%s\', and ' +
'it has %s views.',
channels[0].id,
channels[0].snippet.title,
channels[0].statistics.viewCount);
}
});
After your application obtains an access token, you can use the token to make calls to a Google
API on behalf of a given
user account if the scope(s) of access required by the API have been granted. To do this, include
the access token in a request to the API by including either an access_token
query
parameter or an Authorization
HTTP header Bearer
value. When possible,
the HTTP header is preferable, because query strings tend to be visible in server logs. In most
cases you can use a client library to set up your calls to Google APIs (for example, when
calling the YouTube Data API).
Note that the YouTube Data API supports service accounts only for YouTube
content owners that own and manage multiple YouTube channels, such as record
labels and movie studios.
You can try out all the Google APIs and view their scopes at the
OAuth 2.0 Playground.
A call to the
youtube.channels
endpoint (the YouTube Data API) using the Authorization: Bearer
HTTP
header might look like the following. Note that you need to specify your own access token:
GET /youtube/v3/channels?part=snippet&mine=true HTTP/1.1
Host: www.googleapis.com
Authorization: Bearer access_token
Here is a call to the same API for the authenticated user using the access_token
query string parameter:
GET https://www.googleapis.com/youtube/v3/channels?access_token=access_token&part=snippet&mine=true
curl
examplesYou can test these commands with the curl
command-line application. Here's an
example that uses the HTTP header option (preferred):
curl -H "Authorization: Bearer access_token" https://www.googleapis.com/youtube/v3/channels?part=snippet&mine=true
Or, alternatively, the query string parameter option:
curl https://www.googleapis.com/youtube/v3/channels?access_token=access_token&part=snippet&mine=true
Complete example
The following example prints a JSON-formatted object showing information
about a user's YouTube channel after the user authenticates and authorizes the
application to manage the user's YouTube account.
To run this example:
In the API Console, add the URL of the local machine to the
list of redirect URLs. For example, add
http://localhost:8080
.Create a new directory and change to it. For example:
mkdir ~/php-oauth2-example
cd ~/php-oauth2-example
Install the Google API Client
Library for PHP using Composer:
composer require google/apiclient:^2.15.0
Create the files
index.php
and oauth2callback.php
with thefollowing content.
Run the example with the PHP's built-in test web server:
php -S localhost:8080 ~/php-oauth2-example
index.php
<?phpoauth2callback.php
require_once __DIR__.'/vendor/autoload.php';session_start();$client = new Google\Client();
$client->setAuthConfig('client_secret.json');// User granted permission as an access token is in the session.
if (isset($_SESSION['access_token']) && $_SESSION['access_token'])
{
$client->setAccessToken($_SESSION['access_token']);
$youtube = new Google_Service_YouTube($client);
$channel = $youtube->channels->listChannels('snippet', array('mine' => $mine));
echo json_encode($channel);
}
else
{
// Redirect users to outh2call.php which redirects users to Google OAuth 2.0
$redirect_uri = 'http://' . $_SERVER['HTTP_HOST'] . '/oauth2callback.php';
header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL));
}
?>
<?phpPython
require_once __DIR__.'/vendor/autoload.php';session_start();$client = new Google\Client();// Required, call the setAuthConfig function to load authorization credentials from
// client_secret.json file.
$client->setAuthConfigFile('client_secret.json');
$client->setRedirectUri('http://' . $_SERVER['HTTP_HOST']. $_SERVER['PHP_SELF']);// Required, to set the scope value, call the addScope function.
$client->addScope(GOOGLE_SERVICE_YOUTUBE::YOUTUBE_FORCE_SSL);// Enable incremental authorization. Recommended as a best practice.
$client->setIncludeGrantedScopes(true);// Recommended, offline access will give you both an access and refresh token so that
// your app can refresh the access token without user interaction.
$client->setAccessType("offline");// Generate a URL for authorization as it doesn't contain code and error
if (!isset($_GET['code']) && !isset($_GET['error']))
{
// Generate and set state value
$state = bin2hex(random_bytes(16));
$client->setState($state);
$_SESSION['state'] = $state; // Generate a url that asks permissions.
$auth_url = $client->createAuthUrl();
header('Location: ' . filter_var($auth_url, FILTER_SANITIZE_URL));
}// User authorized the request and authorization code is returned to exchange access and
// refresh tokens.
if (isset($_GET['code']))
{
// Check the state value
if (!isset($_GET['state']) || $_GET['state'] !== $_SESSION['state']) {
die('State mismatch. Possible CSRF attack.');
} // Get access and refresh tokens (if access_type is offline)
$token = $client->fetchAccessTokenWithAuthCode($_GET['code']); /** Save access and refresh token to the session variables.
* ACTION ITEM: In a production app, you likely want to save the
* refresh token in a secure persistent storage instead. */
$_SESSION['access_token'] = $token;
$_SESSION['refresh_token'] = $client->getRefreshToken();
$redirect_uri = 'http://' . $_SERVER['HTTP_HOST'] . '/';
header('Location: ' . filter_var($redirect_uri, FILTER_SANITIZE_URL));
}// An error response e.g. error=access_denied
if (isset($_GET['error']))
{
echo "Error: ". $_GET['error'];
}
?>
This example uses the Flask framework. It
runs a web application at http://localhost:8080
that lets you test the OAuth 2.0
flow. If you go to that URL, you should see five links:
Test an API request: This link points to a page that tries to execute a sample API
request. If necessary, it starts the authorization flow. If successful, the page displays the
API response.
Test the auth flow directly: This link points to a page that tries to send the user
through the authorization flow. The app requests permission to
submit authorized API requests on the user's behalf.
Revoke current credentials: This link points to a page that
revokes permissions that the user has already granted to the application.
Clear Flask session credentials: This link clears authorization credentials that are
stored in the Flask session. This lets you see what would happen if a user who had already
granted permission to your app tried to execute an API request in a new session. It also lets
you see the API response your app would get if a user had revoked permissions granted to your
app, and your app still tried to authorize a request with a revoked access token.
Note: To run this code locally, you must have followed the directions in
the prerequisites section, including setting
http://localhost:8080
as a valid redirect URI for your credentials and downloadingthe client_secret.json file for those credentials to your working directory.
# -*- coding: utf-8 -*-import osRuby
import flask
import requestsimport google.oauth2.credentials
import google_auth_oauthlib.flow
import googleapiclient.discovery# This variable specifies the name of a file that contains the OAuth 2.0
# information for this application, including its client_id and client_secret.
CLIENT_SECRETS_FILE = "client_secret.json"# The OAuth 2.0 access scope allows for access to the
# authenticated user's account and requires requests to use an SSL connection.
SCOPES = ['https://www.googleapis.com/auth/youtube.force-ssl']
API_SERVICE_NAME = 'youtube'
API_VERSION = 'v3'app = flask.Flask(__name__)
# Note: A secret key is included in the sample so that it works.
# If you use this code in your application, replace this with a truly secret
# key. See https://flask.palletsprojects.com/quickstart/#sessions.
app.secret_key = 'REPLACE ME - this value is here as a placeholder.'@app.route('/')
def index():
return print_index_table()@app.route('/test')
def test_api_request():
if 'credentials' not in flask.session:
return flask.redirect('authorize') # Load credentials from the session.
credentials = google.oauth2.credentials.Credentials(
**flask.session['credentials']) youtube = googleapiclient.discovery.build(
API_SERVICE_NAME, API_VERSION, credentials=credentials) channel = youtube.channels().list(mine=True, part='snippet').execute() # Save credentials back to session in case access token was refreshed.
# ACTION ITEM: In a production app, you likely want to save these
# credentials in a persistent database instead.
flask.session['credentials'] = credentials_to_dict(credentials) return flask.jsonify(**channel)
@app.route('/authorize')
def authorize():
# Create flow instance to manage the OAuth 2.0 Authorization Grant Flow steps.
flow = google_auth_oauthlib.flow.Flow.from_client_secrets_file(
CLIENT_SECRETS_FILE, scopes=SCOPES) # The URI created here must exactly match one of the authorized redirect URIs
# for the OAuth 2.0 client, which you configured in the API Console. If this
# value doesn't match an authorized URI, you will get a 'redirect_uri_mismatch'
# error.
flow.redirect_uri = flask.url_for('oauth2callback', _external=True) authorization_url, state = flow.authorization_url(
# Enable offline access so that you can refresh an access token without
# re-prompting the user for permission. Recommended for web server apps.
access_type='offline',
# Enable incremental authorization. Recommended as a best practice.
include_granted_scopes='true') # Store the state so the callback can verify the auth server response.
flask.session['state'] = state return flask.redirect(authorization_url)@app.route('/oauth2callback')
def oauth2callback():
# Specify the state when creating the flow in the callback so that it can
# verified in the authorization server response.
state = flask.session['state'] flow = google_auth_oauthlib.flow.Flow.from_client_secrets_file(
CLIENT_SECRETS_FILE, scopes=SCOPES, state=state)
flow.redirect_uri = flask.url_for('oauth2callback', _external=True) # Use the authorization server's response to fetch the OAuth 2.0 tokens.
authorization_response = flask.request.url
flow.fetch_token(authorization_response=authorization_response) # Store credentials in the session.
# ACTION ITEM: In a production app, you likely want to save these
# credentials in a persistent database instead.
credentials = flow.credentials
flask.session['credentials'] = credentials_to_dict(credentials) return flask.redirect(flask.url_for('test_api_request'))
@app.route('/revoke')
def revoke():
if 'credentials' not in flask.session:
return ('You need to <a href="/authorize">authorize</a> before ' +
'testing the code to revoke credentials.') credentials = google.oauth2.credentials.Credentials(
**flask.session['credentials']) revoke = requests.post('https://oauth2.googleapis.com/revoke',
params={'token': credentials.token},
headers = {'content-type': 'application/x-www-form-urlencoded'}) status_code = getattr(revoke, 'status_code')
if status_code == 200:
return('Credentials successfully revoked.' + print_index_table())
else:
return('An error occurred.' + print_index_table())@app.route('/clear')
def clear_credentials():
if 'credentials' in flask.session:
del flask.session['credentials']
return ('Credentials have been cleared.<br><br>' +
print_index_table())def credentials_to_dict(credentials):
return {'token': credentials.token,
'refresh_token': credentials.refresh_token,
'token_uri': credentials.token_uri,
'client_id': credentials.client_id,
'client_secret': credentials.client_secret,
'granted_scopes': credentials.granted_scopes}def print_index_table():
return ('<table>' +
'<tr><td><a href="/test">Test an API request</a></td>' +
'<td>Submit an API request and see a formatted JSON response. ' +
' Go through the authorization flow if there are no stored ' +
' credentials for the user.</td></tr>' +
'<tr><td><a href="/authorize">Test the auth flow directly</a></td>' +
'<td>Go directly to the authorization flow. If there are stored ' +
' credentials, you still might not be prompted to reauthorize ' +
' the application.</td></tr>' +
'<tr><td><a href="/revoke">Revoke current credentials</a></td>' +
'<td>Revoke the access token associated with the current user ' +
' session. After revoking credentials, if you go to the test ' +
' page, you should see an <code>invalid_grant</code> error.' +
'</td></tr>' +
'<tr><td><a href="/clear">Clear Flask session credentials</a></td>' +
'<td>Clear the access token currently stored in the user session. ' +
' After clearing the token, if you <a href="/test">test the ' +
' API request</a> again, you should go back to the auth flow.' +
'</td></tr></table>')if __name__ == '__main__':
# When running locally, disable OAuthlib's HTTPs verification.
# ACTION ITEM for developers:
# When running in production *do not* leave this option enabled.
os.environ['OAUTHLIB_INSECURE_TRANSPORT'] = '1' # This disables the requested scopes and granted scopes check.
# If users only grant partial request, the warning would not be thrown.
os.environ['OAUTHLIB_RELAX_TOKEN_SCOPE'] = '1' # Specify a hostname and port that are set as a valid redirect URI
# for your API project in the Google API Console.
app.run('localhost', 8080, debug=True)
This example uses the Sinatra framework.
require 'googleauth'Node.js
require 'googleauth/web_user_authorizer'
require 'googleauth/stores/redis_token_store'require 'google/apis/youtube_v3'require 'sinatra'configure do
enable :sessions # Required, call the from_file method to retrieve the client ID from a
# client_secret.json file.
set :client_id, Google::Auth::ClientId.from_file('/path/to/client_secret.json') # Required, scope value
# Access scopes for retrieving data about the user's YouTube channel.
scope = 'Google::Apis::YoutubeV3::AUTH_YOUTUBE_FORCE_SSL' # Required, Authorizers require a storage instance to manage long term persistence of
# access and refresh tokens.
set :token_store, Google::Auth::Stores::RedisTokenStore.new(redis: Redis.new) # Required, indicate where the API server will redirect the user after the user completes
# the authorization flow. The redirect URI is required. The value must exactly
# match one of the authorized redirect URIs for the OAuth 2.0 client, which you
# configured in the API Console. If this value doesn't match an authorized URI,
# you will get a 'redirect_uri_mismatch' error.
set :callback_uri, '/oauth2callback' # To use OAuth2 authentication, we need access to a CLIENT_ID, CLIENT_SECRET, AND REDIRECT_URI
# from the client_secret.json file. To get these credentials for your application, visit
# https://console.cloud.google.com/apis/credentials.
set :authorizer, Google::Auth::WebUserAuthorizer.new(settings.client_id, settings.scope,
settings.token_store, callback_uri: settings.callback_uri)
endget '/' do
# NOTE: Assumes the user is already authenticated to the app
user_id = request.session['user_id'] # Fetch stored credentials for the user from the given request session.
# nil if none present
credentials = settings.authorizer.get_credentials(user_id, request) if credentials.nil?
# Generate a url that asks the user to authorize requested scope(s).
# Then, redirect user to the url.
redirect settings.authorizer.get_authorization_url(request: request)
end
# User authorized read-only YouTube Data API permission.
# Example of using YouTube Data API to list user's YouTube channel
youtube = Google::Apis::YoutubeV3::YouTubeService.new
channel = youtube.list_channels(part, :mine => mine, options: { authorization: auth_client })
"<pre>#{JSON.pretty_generate(channel.to_h)}</pre>"
end# Receive the callback from Google's OAuth 2.0 server.
get '/oauth2callback' do
# Handle the result of the oauth callback. Defers the exchange of the code by
# temporarily stashing the results in the user's session.
target_url = Google::Auth::WebUserAuthorizer.handle_auth_callback_deferred(request)
redirect target_url
end
To run this example:
In the API Console, add the URL of the
local machine to the list of redirect URLs. For example, add
http://localhost
.Make sure you have maintenance LTS, active LTS, or current release of
Node.js installed.
Create a new directory and change to it. For example:
mkdir ~/nodejs-oauth2-example
cd ~/nodejs-oauth2-example
Install the
Google API Client
Library
for Node.js using npm:
npm install googleapis
Create the files
main.js
with the following content.Run the example:
node .\main.js
main.js
const http = require('http');HTTP/REST
const https = require('https');
const url = require('url');
const { google } = require('googleapis');
const crypto = require('crypto');
const express = require('express');
const session = require('express-session');/**
* To use OAuth2 authentication, we need access to a CLIENT_ID, CLIENT_SECRET, AND REDIRECT_URI.
* To get these credentials for your application, visit
* https://console.cloud.google.com/apis/credentials.
*/
const oauth2Client = new google.auth.OAuth2(
YOUR_CLIENT_ID,
YOUR_CLIENT_SECRET,
YOUR_REDIRECT_URL
);// Access scopes for YouTube API
const scopes = [
'https://www.googleapis.com/auth/youtube.force-ssl'
];/* Global variable that stores user credential in this code example.
* ACTION ITEM for developers:
* Store user's refresh token in your data store if
* incorporating this code into your real app.
* For more information on handling refresh tokens,
* see https://github.com/googleapis/google-api-nodejs-client#handling-refresh-tokens
*/
let userCredential = null;async function main() {
const app = express(); app.use(session({
secret: 'your_secure_secret_key', // Replace with a strong secret
resave: false,
saveUninitialized: false,
})); // Example on redirecting user to Google's OAuth 2.0 server.
app.get('/', async (req, res) => {
// Generate a secure random state value.
const state = crypto.randomBytes(32).toString('hex');
// Store state in the session
req.session.state = state; // Generate a url that asks permissions for the Drive activity and Google Calendar scope
const authorizationUrl = oauth2Client.generateAuthUrl({
// 'online' (default) or 'offline' (gets refresh_token)
access_type: 'offline',
/** Pass in the scopes array defined above.
* Alternatively, if only one scope is needed, you can pass a scope URL as a string */
scope: scopes,
// Enable incremental authorization. Recommended as a best practice.
include_granted_scopes: true,
// Include the state parameter to reduce the risk of CSRF attacks.
state: state
}); res.redirect(authorizationUrl);
}); // Receive the callback from Google's OAuth 2.0 server.
app.get('/oauth2callback', async (req, res) => {
// Handle the OAuth 2.0 server response
let q = url.parse(req.url, true).query; if (q.error) { // An error response e.g. error=access_denied
console.log('Error:' + q.error);
} else if (q.state !== req.session.state) { //check state value
console.log('State mismatch. Possible CSRF attack');
res.end('State mismatch. Possible CSRF attack');
} else { // Get access and refresh tokens (if access_type is offline)
let { tokens } = await oauth2Client.getToken(q.code);
oauth2Client.setCredentials(tokens); /** Save credential to the global variable in case access token was refreshed.
* ACTION ITEM: In a production app, you likely want to save the refresh token
* in a secure persistent database instead. */
userCredential = tokens;
// Example of using YouTube API to list channels.
var service = google.youtube('v3');
service.channels.list({
auth: oauth2Client,
part: 'snippet,contentDetails,statistics',
forUsername: 'GoogleDevelopers'
}, function (err, response) {
if (err) {
console.log('The API returned an error: ' + err);
return;
}
var channels = response.data.items;
if (channels.length == 0) {
console.log('No channel found.');
} else {
console.log('This channel\'s ID is %s. Its title is \'%s\', and ' +
'it has %s views.',
channels[0].id,
channels[0].snippet.title,
channels[0].statistics.viewCount);
}
});
}
}); // Example on revoking a token
app.get('/revoke', async (req, res) => {
// Build the string for the POST request
let postData = "token=" + userCredential.access_token; // Options for POST request to Google's OAuth 2.0 server to revoke a token
let postOptions = {
host: 'oauth2.googleapis.com',
port: '443',
path: '/revoke',
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': Buffer.byteLength(postData)
}
}; // Set up the request
const postReq = https.request(postOptions, function (res) {
res.setEncoding('utf8');
res.on('data', d => {
console.log('Response: ' + d);
});
}); postReq.on('error', error => {
console.log(error)
}); // Post the request with data
postReq.write(postData);
postReq.end();
});
const server = http.createServer(app);
server.listen(8080);
}
main().catch(console.error);
This Python example uses the Flask framework
and the Requests library to demonstrate the OAuth
2.0 web flow. We recommend using the Google API Client Library for Python for this flow. (The
example in the Python tab does use the client library.)
import json
import flask
import requestsapp = flask.Flask(__name__)# To get these credentials (CLIENT_ID CLIENT_SECRET) and for your application, visit
# https://console.cloud.google.com/apis/credentials.
CLIENT_ID = '123456789.apps.googleusercontent.com'
CLIENT_SECRET = 'abc123' # Read from a file or environmental variable in a real app# Access scopes for YouTube API
SCOPE = 'https://www.googleapis.com/auth/youtube.force-ssl'# Indicate where the API server will redirect the user after the user completes
# the authorization flow. The redirect URI is required. The value must exactly
# match one of the authorized redirect URIs for the OAuth 2.0 client, which you
# configured in the API Console. If this value doesn't match an authorized URI,
# you will get a 'redirect_uri_mismatch' error.
REDIRECT_URI = 'http://example.com/oauth2callback'@app.route('/')
def index():
if 'credentials' not in flask.session:
return flask.redirect(flask.url_for('oauth2callback')) credentials = json.loads(flask.session['credentials']) if credentials['expires_in'] <= 0:
return flask.redirect(flask.url_for('oauth2callback'))
else:
headers = {'Authorization': 'Bearer {}'.format(credentials['access_token'])}
req_uri = 'https://www.googleapis.com/youtube/v3/channels/list'
r = requests.get(req_uri, headers=headers)
return r.text @app.route('/oauth2callback')
def oauth2callback():
if 'code' not in flask.request.args:
state = str(uuid.uuid4())
flask.session['state'] = state
# Generate a url that asks permissions for the Drive activity
# and Google Calendar scope. Then, redirect user to the url.
auth_uri = ('https://accounts.google.com/o/oauth2/v2/auth?response_type=code'
'&client_id={}&redirect_uri={}&scope={}&state={}').format(CLIENT_ID, REDIRECT_URI,
SCOPE, state)
return flask.redirect(auth_uri)
else:
if 'state' not in flask.request.args or flask.request.args['state'] != flask.session['state']:
return 'State mismatch. Possible CSRF attack.', 400 auth_code = flask.request.args.get('code')
data = {'code': auth_code,
'client_id': CLIENT_ID,
'client_secret': CLIENT_SECRET,
'redirect_uri': REDIRECT_URI,
'grant_type': 'authorization_code'} # Exchange authorization code for access and refresh tokens (if access_type is offline)
r = requests.post('https://oauth2.googleapis.com/token', data=data)
flask.session['credentials'] = r.text
return flask.redirect(flask.url_for('index'))if __name__ == '__main__':
import uuid
app.secret_key = str(uuid.uuid4())
app.debug = False
app.run()
Redirect URI validation rules
Google applies the following validation rules to redirect URIs in order to help developers
keep their applications secure. Your redirect URIs must adhere to these rules. See
RFC 3986 section 3 for the
definition of domain, host, path, query, scheme and userinfo, mentioned below.
Validation rules
Scheme
Redirect URIs must use the HTTPS scheme, not plain HTTP. Localhost URIs (including
localhost IP address URIs) are exempt from this rule.
Host
Hosts cannot be raw IP addresses. Localhost IP addresses are exempted from this rule.
Domain
Host TLDs
(Top Level Domains)
must belong to the public suffix list.
Host domains cannot be
“googleusercontent.com”
.Redirect URIs cannot contain URL shortener domains (e.g.
goo.gl
) unlessthe app owns the domain. Furthermore, if an app that owns a shortener domain chooses to
redirect to that domain, that redirect URI must either contain
“/google-callback/”
in its path or end with“/google-callback”
.Userinfo
Redirect URIs cannot contain the userinfo subcomponent.
Path
Redirect URIs cannot contain a path traversal (also called directory backtracking),
which is represented by an “/..”
or “\..”
or their URL
encoding.
Query
Redirect URIs cannot contain
open redirects.
Fragment
Redirect URIs cannot contain the fragment component.
Characters
Redirect URIs cannot contain certain characters including:
Wildcard characters (
'*'
)Non-printable ASCII characters
Invalid percent encodings (any percent encoding that does not follow URL-encoding
form of a percent sign followed by two hexadecimal digits)
Null characters (an encoded NULL character, e.g.,
%00
,%C0%80
)Incremental authorization
In the OAuth 2.0 protocol, your app requests authorization to access resources, which are
identified by scopes. It is considered a best user-experience practice to request authorization
for resources at the time you need them. To enable that practice, Google's authorization server
supports incremental authorization. This feature lets you request scopes as they are needed and,
if the user grants permission for the new scope, returns an authorization code that may be
exchanged for a token containing all scopes the user has granted the project.
For example, suppose an app helps users identify interesting local events.
The app lets users view videos about the events, rate the videos, and add the
videos to playlists. Users can also use the app to add events to their Google
Calendars.
In this case, at sign-in time, the app might not need or request access to
any scopes. However, if the user tried to rate a video, add a video to a
playlist, or perform another YouTube action, the app could request access to
the https://www.googleapis.com/auth/youtube.force-ssl
scope.
Similarly, the app could request access to the
https://www.googleapis.com/auth/calendar
scope if the user tried
to add a calendar event.
To implement incremental authorization, you complete the normal flow for requesting an access
token but make sure that the authorization request includes previously granted scopes. This
approach allows your app to avoid having to manage multiple access tokens.
The following rules apply to an access token obtained from an incremental authorization:
The token can be used to access resources corresponding to any of the scopes rolled into the
new, combined authorization.
When you use the refresh token for the combined authorization to obtain an access token, the
access token represents the combined authorization and can be used for any of the
scope
values included in the response.The combined authorization includes all scopes that the user granted to the API project even
if the grants were requested from different clients. For example, if a user granted access to
one scope using an application's desktop client and then granted another scope to the same
application via a mobile client, the combined authorization would include both scopes.
If you revoke a token that represents a combined authorization, access to all of that
authorization's scopes on behalf of the associated user are revoked simultaneously.
Caution: choosing to include granted scopes will automatically add
scopes previously granted by the user to your authorization request. A warning or error page may
be displayed if your app is not currently approved to request all scopes that may be returned in
the response. See
Unverified apps for
more information.
The language-specific code samples in Step 1: Set authorization
parameters and the sample HTTP/REST redirect URL in Step 2:
Redirect to Google's OAuth 2.0 server all use incremental authorization. The code samples
below also show the code that you need to add to use incremental authorization.
$client->setIncludeGrantedScopes(true);
Python In Python, set the include_granted_scopes
keyword argument to true
to
ensure that an authorization request includes previously granted scopes. It is very possible that
include_granted_scopes
will not be the only keyword argument that you set, as
shown in the example below.
authorization_url, state = flow.authorization_url(Ruby
# Enable offline access so that you can refresh an access token without
# re-prompting the user for permission. Recommended for web server apps.
access_type='offline',
# Enable incremental authorization. Recommended as a best practice.
include_granted_scopes='true')
auth_client.update!(Node.js
:additional_parameters => {"include_granted_scopes" => "true"}
)
const authorizationUrl = oauth2Client.generateAuthUrl({HTTP/REST
// 'online' (default) or 'offline' (gets refresh_token)
access_type: 'offline',
/** Pass in the scopes array defined above.
* Alternatively, if only one scope is needed, you can pass a scope URL as a string */
scope: scopes,
// Enable incremental authorization. Recommended as a best practice.
include_granted_scopes: true
});
In this example, the calling application requests access to retrieve the
user's YouTube Analytics data in addition to any other access that the user
has already granted to the application.
GET https://accounts.google.com/o/oauth2/v2/auth?
scope=https%3A%2F%2Fwww.googleapis.com%2Fauth%2Fyt-analytics.readonly&
access_type=offline&
state=security_token%3D138rk%3Btarget_url%3Dhttp...index&
redirect_uri=http%3A%2F%2Flocalhost%2Foauth2callback&
response_type=code&
client_id=client_id&
include_granted_scopes=true
Refreshing an access token (offline access)
Access tokens periodically expire and become invalid credentials for a related API request. You
can refresh an access token without prompting the user for permission (including when the user is
not present) if you requested offline access to the scopes associated with the token.
If you use a Google API Client Library, the client object refreshes
the access token as needed as long as you configure that object for offline access.
If you are not using a client library, you need to set the
access_type
HTTPquery parameter to
offline
when redirecting the user toGoogle's OAuth 2.0 server. In that case, Google's authorization server returns a
refresh token when you exchange an authorization
code for an access token. Then, if the access token expires (or at any other time), you
can use a refresh token to obtain a new access token.
Requesting offline access is a requirement for any application that needs to access a Google
API when the user is not present. For example, an app that performs backup services or
executes actions at predetermined times needs to be able to refresh its access token when the
user is not present. The default style of access is called online
.
Server-side web applications, installed applications, and devices all obtain refresh tokens
during the authorization process. Refresh tokens are not typically used in client-side
(JavaScript) web applications.
If your application needs offline access to a Google API, set the API client's access type to
offline
:
$client->setAccessType("offline");
After a user grants offline access to the requested scopes, you can continue to use the API
client to access Google APIs on the user's behalf when the user is offline. The client object
will refresh the access token as needed.
In Python, set the access_type
keyword argument to offline
to ensure
that you will be able to refresh the access token without having to re-prompt the user for
permission. It is very possible that access_type
will not be the only keyword
argument that you set, as shown in the example below.
authorization_url, state = flow.authorization_url(
# Enable offline access so that you can refresh an access token without
# re-prompting the user for permission. Recommended for web server apps.
access_type='offline',
# Enable incremental authorization. Recommended as a best practice.
include_granted_scopes='true')
After a user grants offline access to the requested scopes, you can continue to use the API
client to access Google APIs on the user's behalf when the user is offline. The client object
will refresh the access token as needed.
If your application needs offline access to a Google API, set the API client's access type to
offline
:
auth_client.update!(
:additional_parameters => {"access_type" => "offline"}
)
After a user grants offline access to the requested scopes, you can continue to use the API
client to access Google APIs on the user's behalf when the user is offline. The client object
will refresh the access token as needed.
If your application needs offline access to a Google API, set the API client's access type to
offline
:
const authorizationUrl = oauth2Client.generateAuthUrl({
// 'online' (default) or 'offline' (gets refresh_token)
access_type: 'offline',
/** Pass in the scopes array defined above.
* Alternatively, if only one scope is needed, you can pass a scope URL as a string */
scope: scopes,
// Enable incremental authorization. Recommended as a best practice.
include_granted_scopes: true
});
After a user grants offline access to the requested scopes, you can continue to use the API
client to access Google APIs on the user's behalf when the user is offline. The client object
will refresh the access token as needed.
Access tokens expire. This library will automatically use a refresh token to obtain a new access
token if it is about to expire. An easy way to make sure you always store the most recent tokens
is to use the tokens event:
oauth2Client.on('tokens', (tokens) => {
if (tokens.refresh_token) {
// store the refresh_token in your secure persistent database
console.log(tokens.refresh_token);
}
console.log(tokens.access_token);
});
This tokens event only occurs in the first authorization, and you need to have set your
access_type
to offline
when calling the generateAuthUrl
method to receive the refresh token. If you have already given your app the requisiste permissions
without setting the appropriate constraints for receiving a refresh token, you will need to
re-authorize the application to receive a fresh refresh token.
To set the refresh_token
at a later time, you can use the setCredentials
method:
oauth2Client.setCredentials({
refresh_token: `STORED_REFRESH_TOKEN`
});
Once the client has a refresh token, access tokens will be acquired and refreshed automatically
in the next call to the API.
To refresh an access token, your application sends an HTTPS POST
request to Google's authorization server (https://oauth2.googleapis.com/token
) that
includes the following parameters:
Fields
client_id
The client ID obtained from the API Console.
client_secret
The client secret obtained from the API Console.
grant_type
As
defined in the
OAuth 2.0 specification,
this field's value must be set to refresh_token
.
refresh_token
The refresh token returned from the authorization code exchange.
The following snippet shows a sample request:
POST /token HTTP/1.1
Host: oauth2.googleapis.com
Content-Type: application/x-www-form-urlencodedclient_id=your_client_id&
client_secret=your_client_secret&
refresh_token=refresh_token&
grant_type=refresh_token
As long as the user has not revoked the access granted to the application, the token server
returns a JSON object that contains a new access token. The following snippet shows a sample
response:
{
"access_token": "1/fFAGRNJru1FTz70BzhT3Zg",
"expires_in": 3920,
"scope": "https://www.googleapis.com/auth/drive.metadata.readonly",
"token_type": "Bearer"
}
Note that there are limits on the number of refresh tokens that will be issued; one limit per
client/user combination, and another per user across all clients. You should save refresh tokens
in long-term storage and continue to use them as long as they remain valid. If your application
requests too many refresh tokens, it may run into these limits, in which case older refresh tokens
will stop working.
In some cases a user may wish to revoke access given to an application. A user can revoke access
by visiting
Account Settings. See the
Remove
site or app access section of the Third-party sites & apps with access to your account
support document for more information.
It is also possible for an application to programmatically revoke the access given to it.
Programmatic revocation is important in instances where a user unsubscribes, removes an
application, or the API resources required by an app have significantly changed. In other words,
part of the removal process can include an API request to ensure the permissions previously
granted to the application are removed.
To programmatically revoke a token, call revokeToken()
:
$client->revokeToken();
Python To programmatically revoke a token, make a request to
https://oauth2.googleapis.com/revoke
that includes the token as a parameter and sets the
Content-Type
header:
requests.post('https://oauth2.googleapis.com/revoke',Ruby
params={'token': credentials.token},
headers = {'content-type': 'application/x-www-form-urlencoded'})
To programmatically revoke a token, make an HTTP request to the oauth2.revoke
endpoint:
uri = URI('https://oauth2.googleapis.com/revoke')
response = Net::HTTP.post_form(uri, 'token' => auth_client.access_token)
The token can be an access token or a refresh token. If the token is an access token and it has
a corresponding refresh token, the refresh token will also be revoked.
If the revocation is successfully processed, then the status code of the response is
200
. For error conditions, a status code 400
is returned along with an
error code.
To programmatically revoke a token, make an HTTPS POST request to /revoke
endpoint:
const https = require('https');// Build the string for the POST request
let postData = "token=" + userCredential.access_token;// Options for POST request to Google's OAuth 2.0 server to revoke a token
let postOptions = {
host: 'oauth2.googleapis.com',
port: '443',
path: '/revoke',
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded',
'Content-Length': Buffer.byteLength(postData)
}
};// Set up the request
const postReq = https.request(postOptions, function (res) {
res.setEncoding('utf8');
res.on('data', d => {
console.log('Response: ' + d);
});
});postReq.on('error', error => {
console.log(error)
});// Post the request with data
postReq.write(postData);
postReq.end();
The token parameter can be an access token or a refresh token. If the token is an access token and it has
a corresponding refresh token, the refresh token will also be revoked.
If the revocation is successfully processed, then the status code of the response is
200
. For error conditions, a status code 400
is returned along with an
error code.
To programmatically revoke a token, your application makes a request to
https://oauth2.googleapis.com/revoke
and includes the token as a parameter:
curl -d -X -POST --header "Content-type:application/x-www-form-urlencoded" \
https://oauth2.googleapis.com/revoke?token={token}
The token can be an access token or a refresh token. If the token is an access token and it has a
corresponding refresh token, the refresh token will also be revoked.
If the revocation is successfully processed, then the HTTP status code of the response is
200
. For error conditions, an HTTP status code 400
is returned along
with an error code.
time before the revocation has full effect.
Implementing Cross-Account Protection
An additional step you should take to protect your users' accounts is implementing Cross-Account
Protection by utilizing Google's Cross-Account Protection Service. This service lets you
subscribe to security event notifications which provide information to your application about
major changes to the user account. You can then use the information to take action depending on
how you decide to respond to events.
Some examples of the event types sent to your app by Google's Cross-Account Protection Service are:
https://schemas.openid.net/secevent/risc/event-type/sessions-revoked
https://schemas.openid.net/secevent/oauth/event-type/token-revoked
https://schemas.openid.net/secevent/risc/event-type/account-disabled
See the
Protect user accounts with Cross-Account Protection page
for more information on how to implement Cross Account Protection and for the full list of available events.
... <看更多>
side part中文 在 《英雄傳說黎之軌跡II -緋紅原罪-》中文版- Part.5 - YouTube 的八卦
英雄傳說黎之軌跡II -緋紅原罪-》 中文 版- 二周目Nightmare===0:15 - 『 side B』開場7:38 - 『第Ⅰ部 side B』- 代理地下萬事屋16:28 - 4SPG (1)22:37 ... ... <看更多>