设置列入许可名单的网域 API

本页面介绍了如何在添加、列出和获取或删除许可名单网域之前设置许可名单网域 API。

准备工作

在使用任何 Cloud Identity API 之前,您必须设置 Cloud Identity。如需查看相关说明,请参阅设置 Cloud Identity。

安装 Python 客户端库

如需安装 Python 客户端库,请运行以下命令:

  pip install --upgrade google-api-python-client google-auth \
    google-auth-oauthlib google-auth-httplib2

如需详细了解如何设置 Python 开发环境,请参阅 Python 开发环境设置指南。

启用 API 并设置凭据

  1. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  2. Verify that billing is enabled for your Google Cloud project.

  3. Enable the Cloud Identity API, if it is not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

  4. 创建服务账号:
    • 确保您拥有 Create Service Accounts IAM 角色 (roles/iam.serviceAccountCreator) 和 Project IAM Admin 角色 (roles/resourcemanager.projectIamAdmin)。了解如何授予角色。
    • 在 Google Cloud 控制台中,前往创建服务账号页面。
    • 选择您的项目。
    • 在服务账号名称字段中,输入一个名称。 Google Cloud 控制台会根据此名称填充服务账号 ID 字段。
    • 在服务账号说明字段中,输入说明。例如 Service account for quickstart。
    • 点击创建并继续。
    • 向服务账号授予项目 > 所有者角色。如需授予该角色,请找到选择角色列表,然后选择项目 > 所有者。
    • 点击继续。
    • 点击完成以完成服务账号的创建过程。不要关闭浏览器窗口。您将在下一步骤中用到它。
  5. 创建服务账号密钥:
    • 在 Google Cloud 控制台中,点击您创建的服务账号的电子邮件地址。
    • 点击密钥。
    • 点击添加密钥,然后点击创建新密钥。
    • 点击创建。JSON 密钥文件将下��到您的计算机���。
    • 点击���闭。

创建 API 密钥

  1. 在 Google Cloud 控制台中,前往凭证页面。
  2. 点击创建凭证,然后选择 API 密钥。
  3. API 密钥已创建对话框会显示您新创建的 API 密钥。复制此密钥,以便在脚本中用作 API_KEY 常量。

以服务账号身份进行身份验证并进行全网域授权

如果您是管理许可列入名单的网域的管理员,或者您希望向账号提供全网域权限,以便其可以代表管理员管理许可列入名单的网域,则应以服务账号的身份进行身份验证,然后向该服务账号授予全网域权限。

如需详细了解如何设置全网域授权,请参阅使用全网域授权功能控制 API 访问权限。查看最佳实践,以降低与使用全网域授权相关的安全风险。

提供以下范围以授权服务账号:

  • 对于读取和写入操作(create、delete、list、get): https://www.googleapis.com/auth/cloud-identity.allowlisteddomains

  • 对于只读操作(list、get): https://www.googleapis.com/auth/cloud-identity.allowlisteddomains.readonly

初始化凭据并实例化客户端

在代码中初始化凭据时,通过对凭据调用 with_subject() 来指定服务账号要操作的电子邮件地址。

以下示例展示了如何使用服务账号凭据实例化客户端,以与 Allowlisted Domains API 进行交互:

Python

from google.oauth2 import service_account
import googleapiclient.discovery

SCOPES = [
    'https://www.googleapis.com/auth/cloud-identity.allowlisteddomains.readonly',
    'https://www.googleapis.com/auth/cloud-identity.allowlisteddomains',
]
SERVICE_ACCOUNT_FILE = 'SERVICE_ACCOUNT_CREDENTIAL_FILE'
PROD_DISCOVERY_URL_BASE = (
    'https://cloudidentity.googleapis.com/$discovery/rest'
)
API_KEY = 'YOUR_API_KEY'

def create_service(version, delegated_email):
  """Instantiates a client using service account credentials."""
  credentials = service_account.Credentials.from_service_account_file(
      SERVICE_ACCOUNT_FILE, scopes=SCOPES
  )
  delegated_credentials = credentials.with_subject(delegated_email)
  url = f'{PROD_DISCOVERY_URL_BASE}?version={version}&key={API_KEY}'

  service = googleapiclient.discovery.build(
      serviceName=None,
      version=None,
      credentials=delegated_credentials,
      discoveryServiceUrl=url,
      static_discovery=False,
  )
  return service

替换以下内容:

  • SERVICE_ACCOUNT_CREDENTIAL_FILE:您在本文档前面部分创建的服务账号密钥文件
  • YOUR_API_KEY:从 Google Cloud 控制台的“凭据”页面复制的 API 密钥

如需查看用于调用“已列入许可名单的网域”API 操作的详细示例代码,请参阅列出和获取已列入许可名单的网域。