Repository navigation
Expand file tree
/
Copy pathsetup_gmail_oauth_gcloud.sh
More file actions
executable file
·153 lines (133 loc) · 5.23 KB
/
Copy pathsetup_gmail_oauth_gcloud.sh
File metadata and controls
executable file
·153 lines (133 loc) · 5.23 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
#!/bin/bash
# Gmail OAuth Setup Script using gcloud CLI
# This script creates OAuth credentials for Gmail API access
set -e # Exit on error
echo "🚀 Setting up Gmail OAuth using gcloud CLI"
echo "=========================================="
# Configuration
PROJECT_ID="brain-gmail-integration-$(date +%s)"
PROJECT_NAME="Brain Gmail Integration"
CREDENTIALS_PATH="/Users/tarive/brain-poc/mcp-gmail/credentials.json"
# Step 1: Create or select project
echo ""
echo "📁 Step 1: Creating Google Cloud Project..."
if gcloud projects create "$PROJECT_ID" --name="$PROJECT_NAME" 2>/dev/null; then
echo "✅ Project created: $PROJECT_ID"
else
echo "⚠️ Project creation failed (might already exist). Using existing project."
# Try to use existing project
EXISTING_PROJECT=$(gcloud projects list --filter="name:Brain Gmail Integration" --format="value(projectId)" | head -1)
if [ -n "$EXISTING_PROJECT" ]; then
PROJECT_ID="$EXISTING_PROJECT"
echo "✅ Using existing project: $PROJECT_ID"
fi
fi
# Set the project as active
gcloud config set project "$PROJECT_ID"
echo "✅ Set active project to: $PROJECT_ID"
# Step 2: Enable Gmail API
echo ""
echo "📧 Step 2: Enabling Gmail API..."
if gcloud services enable gmail.googleapis.com --project="$PROJECT_ID"; then
echo "✅ Gmail API enabled"
else
echo "⚠️ Gmail API might already be enabled"
fi
# Step 3: Create OAuth consent screen configuration
echo ""
echo "🔐 Step 3: Configuring OAuth consent screen..."
# First check if OAuth brand already exists
EXISTING_BRAND=$(gcloud iap oauth-brands list --project="$PROJECT_ID" --format="value(name)" 2>/dev/null | head -1)
if [ -z "$EXISTING_BRAND" ]; then
# Create OAuth brand (consent screen)
gcloud iap oauth-brands create \
--application_title="Brain Gmail Integration" \
--support_email="tarive22@gmail.com" \
--project="$PROJECT_ID" 2>/dev/null || echo "⚠️ OAuth brand might already exist"
else
echo "✅ OAuth brand already exists"
fi
# Step 4: Create OAuth 2.0 Client ID
echo ""
echo "🔑 Step 4: Creating OAuth 2.0 Client ID..."
# Create OAuth client for desktop application
echo "Creating desktop OAuth client..."
# We need to use the API directly for desktop clients since gcloud doesn't support it directly
# First, get an access token
ACCESS_TOKEN=$(gcloud auth print-access-token)
# Create the OAuth client using the API
OAUTH_RESPONSE=$(curl -s -X POST \
"https://iam.googleapis.com/v1/projects/${PROJECT_ID}/locations/global/oauthClients" \
-H "Authorization: Bearer ${ACCESS_TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"displayName": "Brain Gmail Desktop Client",
"allowedGrantTypes": ["authorization_code", "refresh_token"],
"allowedRedirectUris": ["urn:ietf:wg:oauth:2.0:oob", "http://localhost"],
"allowedScopes": [
"https://www.googleapis.com/auth/gmail.modify"
]
}' 2>/dev/null)
# Alternative approach: Use the older API
if [ -z "$OAUTH_RESPONSE" ] || [[ "$OAUTH_RESPONSE" == *"error"* ]]; then
echo "⚠️ Desktop client creation via API failed. Trying alternative method..."
# Create credentials using the console API
OAUTH_RESPONSE=$(curl -s -X POST \
"https://console.cloud.google.com/apis/credentials/oauthclient" \
-H "Authorization: Bearer ${ACCESS_TOKEN}" \
-H "Content-Type: application/json" \
-d "{
\"project_id\": \"${PROJECT_ID}\",
\"client_type\": \"installed\",
\"client_name\": \"Brain Gmail Desktop Client\"
}" 2>/dev/null)
fi
# Step 5: Download and save credentials
echo ""
echo "📥 Step 5: Setting up credentials file..."
# Since gcloud doesn't directly support desktop OAuth clients, we'll create the credentials JSON manually
# This is the format needed for desktop applications
cat > "$CREDENTIALS_PATH" <<EOF
{
"installed": {
"client_id": "YOUR_CLIENT_ID.apps.googleusercontent.com",
"project_id": "${PROJECT_ID}",
"auth_uri": "https://accounts.google.com/o/oauth2/auth",
"token_uri": "https://oauth2.googleapis.com/token",
"auth_provider_x509_cert_url": "https://www.googleapis.com/oauth2/v1/certs",
"client_secret": "YOUR_CLIENT_SECRET",
"redirect_uris": ["urn:ietf:wg:oauth:2.0:oob", "http://localhost"]
}
}
EOF
echo ""
echo "⚠️ IMPORTANT: Manual step required!"
echo "====================================="
echo ""
echo "Since gcloud CLI doesn't directly support creating desktop OAuth clients,"
echo "you need to complete this step manually:"
echo ""
echo "1. Open this URL in your browser:"
echo " https://console.cloud.google.com/apis/credentials?project=${PROJECT_ID}"
echo ""
echo "2. Click '+ CREATE CREDENTIALS' → 'OAuth client ID'"
echo ""
echo "3. Select:"
echo " - Application type: Desktop app"
echo " - Name: Brain Gmail Desktop Client"
echo ""
echo "4. Click 'CREATE'"
echo ""
echo "5. Click 'DOWNLOAD JSON'"
echo ""
echo "6. Save the file as:"
echo " ${CREDENTIALS_PATH}"
echo ""
echo "📝 Project ID: ${PROJECT_ID}"
echo ""
echo "Once you've downloaded the credentials, test with:"
echo " cd /Users/tarive/brain-poc/mcp-gmail"
echo " uv run python scripts/test_gmail_setup.py"
echo ""
echo "✅ Gmail API is enabled and project is configured!"
echo " Just need to download the OAuth credentials manually."