googleapis / googleapis/google-api-nodejs-client

gmail.users.watch | error sending test message to Cloud PubSub projects/tms-erp-afourtech-assets/topics/gmail-watcher : User not authorized to perform this action.

Open
#2,843 6 comments 0 reactions 0 assignees View on GitHub
api: gmail type: question
Dominant language
TypeScript
Stars
12.2k
Forks
2k
Avg merge
1d 9h
Merged PRs (30d)
24

Description

I want to implement watch for new mails in INBOX for a Google Workspace email ID.

Already Verified Pointers:
1. I've made sure that `client_id` from `service.json` file has domain wide delegated authorisation for the scope being used.
2. I've also made sure that service account has `Publisher` access.
3. I've also made sure that `client_email` has `Publisher` access from the [`Pub/Sub`](https://console.cloud.google.com/cloudpubsub/topic/list) [Followed this solution](https://stackoverflow.com/questions/68091042/gmailapi-error-sending-test-message-to-cloud-pubsub-projects-project-id-topi)

Still getting
```typescript
{
message: 'Error sending test message to Cloud PubSub projects//topics/gmail-watcher : User not authorized to perform this action.',
domain: 'global',
reason: 'forbidden'
}
```

Code:
```typescript
import { google, Auth } from 'googleapis';
import { resolve } from 'path';

const serviceAccountPath = resolve('./service.json')
const scopes = [
'https://www.googleapis.com/auth/gmail.metadata'
]
const emailToBeDelegated = 'email.id@domain.com'

class GoogleAuth {
public auth;
constructor(serviceAccountPath: string, scopes: string[], emailToBeDelegated: string){
this.auth = this.getAuth(serviceAccountPath, scopes, emailToBeDelegated);
}
public async getAuthorizedJWT () {
await this.auth.authorize();
return this.auth;
};
private getAuth = (serviceAccountPath: string, scopes: string[], emailToBeDelegated: string): Auth.JWT => {
return new Auth.JWT({
keyFile: serviceAccountPath,
scopes,
subject: emailToBeDelegated
});
};
}

class GMailService extends GoogleAuth {
constructor(serviceAccountPath: string, scopes: string[], emailToBeDelegated: string){
super(serviceAccountPath, scopes, emailToBeDelegated);
}

watch = async () => {
const auth = await this.getAuthorizedJWT();
return google.gmail({ version: 'v1' }).users.watch({auth,
userId: 'me',
requestBody: {
topicName: 'projects//topics/gmail-watcher',
labelIds: ['INBOX']
}
})
}
}

(async () => {
const gMailService = new GMailService(serviceAccountPath, scopes, emailToBeDelegated);
console.log(await gMailService.watch());
})();
```

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.