Google service account: Delegate Domain-Wide Delegation of Authority to impersonate only ONE user

Viewed 159

We need to access Google Calendar API with server application to create the events and invite the attendees. Google recommends to use service account for the applications.

The main problem here with the attendees inviting to the event, because the service account can't do it without the Domain-Wide Delegation of Authority (see img).

Organization do not want to give the service account an access to ALL user's data. So, I'm trying to find out can we delegate the Domain-Wide Delegation of Authority to the ONE user of the domain ? (restrict access to use another user's data).

p.s. it's only about google calendar api.

Many thanks for the help.

screenshot from the google doc

1 Answers

I am still not sure that this question is programming related, however if you just want to see "in code" how to delegate to a user here is an example using C# where the gsuiteUser is added to the code where the ServiceAccountCredential is initialized.

When run this code will run as if the code is being run by the gsuiteuser. there for any access that that user has on the gsuite domain the service account will have. There is no way to limit that access anymore then that. Service accounts are dummy users who can be preauthorized to have access of a user.

string ApplicationName = "Calendar API .NET Quickstart";
            const string serviceAccount = "xxx@xxxxx-api.iam.gserviceaccount.com";

            var certificate = new X509Certificate2("cred.p12", "notasecret", X509KeyStorageFlags.Exportable);

            var gsuiteUser = "user@mygsuitedomain.com";

            var serviceAccountCredentialInitializer = new ServiceAccountCredential.Initializer(serviceAccount)
            {
                User = gsuiteUser,   // Service account will run as this user
                Scopes = new[] { CalendarService.Scope.read }

            }.FromCertificate(certificate);

            var credential = new ServiceAccountCredential(serviceAccountCredentialInitializer);
            if (!credential.RequestAccessTokenAsync(CancellationToken.None).Result)
                throw new InvalidOperationException("Access token failed.");

            var service = new CalendarService(new BaseClientService.Initializer()
            {
                HttpClientInitializer = credential,
                ApplicationName = ApplicationName,
            });
Related