How to restrict the user's access to the script for community connector?

Viewed 158

I'm building a Data studio community connector using google apps script. In the script(code), I am accessing the spanner database using service account credentials. But when I share the connector with others to use it, they can access my script and view the secret. What do I have to do so that the script is inaccessible by the users?

If I publish it to the partner connector gallery, will the user's still have access to my script? Is there any setting so that the user should not see the functions executions and also the script?

If this is not possible then how could I store my secret such that it is not visible to the user?

1 Answers
  1. Store the service account credentials in Script properties. Users with view access to the script cannot view the script properties in the UI.

  2. When you share with the users, don't notify them. If they don't know the script url, they can't view the script. They can still use the connector if you provide them with the deployment id/link. Deployment id is always different from script Id.

  3. If you publish to the connector gallery, you won't have to share the script with everyone. See the first requirement here.

Related