googleapis / googleapis/google-api-nodejs-client
gmail.users.watch | error sending test message to Cloud PubSub projects/tms-erp-afourtech-assets/topics/gmail-watcher : User not authorized to perform this action.
- Dominant language
- TypeScript
- Stars
- 12.2k
- Forks
- 2k
- Avg merge
- 1d 9h
- Merged PRs (30d)
- 24
Description
I want to implement watch for new mails in INBOX for a Google Workspace email ID.
Already Verified Pointers:
1. I've made sure that `client_id` from `service.json` file has domain wide delegated authorisation for the scope being used.
2. I've also made sure that service account has `Publisher` access.
3. I've also made sure that `client_email` has `Publisher` access from the [`Pub/Sub`](https://console.cloud.google.com/cloudpubsub/topic/list) [Followed this solution](https://stackoverflow.com/questions/68091042/gmailapi-error-sending-test-message-to-cloud-pubsub-projects-project-id-topi)
Still getting
```typescript
{
message: 'Error sending test message to Cloud PubSub projects//topics/gmail-watcher : User not authorized to perform this action.',
domain: 'global',
reason: 'forbidden'
}
```
Code:
```typescript
import { google, Auth } from 'googleapis';
import { resolve } from 'path';
const serviceAccountPath = resolve('./service.json')
const scopes = [
'https://www.googleapis.com/auth/gmail.metadata'
]
const emailToBeDelegated = 'email.id@domain.com'
class GoogleAuth {
public auth;
constructor(serviceAccountPath: string, scopes: string[], emailToBeDelegated: string){
this.auth = this.getAuth(serviceAccountPath, scopes, emailToBeDelegated);
}
public async getAuthorizedJWT () {
await this.auth.authorize();
return this.auth;
};
private getAuth = (serviceAccountPath: string, scopes: string[], emailToBeDelegated: string): Auth.JWT => {
return new Auth.JWT({
keyFile: serviceAccountPath,
scopes,
subject: emailToBeDelegated
});
};
}
class GMailService extends GoogleAuth {
constructor(serviceAccountPath: string, scopes: string[], emailToBeDelegated: string){
super(serviceAccountPath, scopes, emailToBeDelegated);
}
watch = async () => {
const auth = await this.getAuthorizedJWT();
return google.gmail({ version: 'v1' }).users.watch({auth,
userId: 'me',
requestBody: {
topicName: 'projects//topics/gmail-watcher',
labelIds: ['INBOX']
}
})
}
}
(async () => {
const gMailService = new GMailService(serviceAccountPath, scopes, emailToBeDelegated);
console.log(await gMailService.watch());
})();
```
Contributor guide
Assessment
This issue has not been assessed yet.