Has anyone successfully used Google Admin SDK with Google Cloud Functions?

Viewed 265

My org is new to Google Auth and we have poured countless hours into documentation readings. The mission was simple: view members in our google groups through the Directory API.

Our setup: The cloud function deploys and runs with a service account that has been granted domain-wide access with the proper scopes, and impersonates an admin user detailed here:

https://developers.google.com/admin-sdk/directory/v1/guides/delegation

When I run the function locally and pull the service account key from a file path I get the error: "Error 403: Not Authorized to access this resource/api, forbidden"

I noticed that when deploying the Cloud Function via inline text or an uploaded zip it was unable to read a .json or .text file type when I included it in the package. I know this is bad practice but just to see I put in marshaled the JSON key in the main file.

And still got a "Error 403: Not Authorized to access this resource/api, forbidden"

Where am I going wrong?

import (
    "encoding/json"
    "fmt"
    _"io/ioutil"
    "log"
    "net/http"
    _ "os"
    "time"

    "golang.org/x/net/context"
    "golang.org/x/oauth2/google"

    admin "google.golang.org/api/admin/directory/v1"
    "google.golang.org/api/option"
)


var User_email = <user>


func createAdminDirectoryService(serviceAccountFilePath, gsuiteAdminUserEmail string) *admin.Service {
    jsonCredentials,_ := json.Marshal(map[string]string{<SERVICE KEY FILE>})

    log.Println("Json creds: ", jsonCredentials)

    config, err := google.JWTConfigFromJSON(
        jsonCredentials,
        "https://www.googleapis.com/auth/admin.directory.group.member.readonly",
    )
    if err != nil {
        log.Printf("Json Config error:%v", err.Error())
    }
    config.Subject = gsuiteAdminUserEmail

    fmt.Println(serviceAccountFilePath)//vestigial of previous version reading key from file
    fmt.Println(gsuiteAdminUserEmail)

    ctx, _ := context.WithDeadline(context.Background(), time.Now().Add(20*time.Second))
    ts := config.TokenSource(ctx)

    srv, err := admin.NewService(ctx, option.WithTokenSource(ts))
    if err != nil {
        log.Println("Admin Service error:", err.Error())
    }
    return srv
}

func listUsersInGroup(srv *admin.Service, groupEmail string) ([]string, error) {
    membersEmails := make([]string, 1)
    members, err := srv.Members.List(groupEmail).Do()
    if err != nil {
        log.Fatal("fatalerror list users: ", err)

        membersEmails[0] = "Nope"

    } else {
        membersEmails := make([]string, len(members.Members))
        for i, member := range members.Members {
            membersEmails[i] = member.Email
        }
    }

    return membersEmails, err
}

func Main(w http.ResponseWriter, r *http.Request) {

    groupEmail := <groupemail>
    path := "./key.json" //vestigial of previous version reading key from file
    fmt.Println("Path:", path)

    srv := createAdminDirectoryService(
        path,
        User_email,
    )

    members, err := listUsersInGroup(srv, groupEmail)

    if err != nil {
        log.Println(members)
    } else {
        log.Println("sorry bud")
    }
}
   
0 Answers
Related