Googledrive API: Shared Drive access control

Viewed 70
  1. I was able to create a shared drive under my profile.

  2. I created Service Account (E.g: test@svc.company.net)

  3. I created G-Suite Account (E.g: test@integration-24524514.iam.gserviceaccount.com) from Service Account (E.g: test@svc.company.net)

  4. For the shareddrive created, I assigned below access for each of the profile

  • My profile (Manager)
  • Service Account (E.g: test@svc.company.net) (Manager)
  • G-Suite Account (E.g: test@integration-24524514.iam.gserviceaccount.com) (Manager)
  1. I created a sub folder under the shared drive

  2. I tried to grant access manually from the API Explorer (https://developers.google.com/drive/api/v3/reference/permissions/create) with below details

Request parameters fileId = Ix6yw5La5iTg-n*********

Request body { "role": "reader", "type": "user", "emailAddress": "test@email.com" }

  • It works fine when I grant access as My profile (Manager) and Service Account (E.g: test@svc.company.net) (Manager)
  1. When I try the same through API as G-Suite Account (E.g: test@integration-24524514.iam.gserviceaccount.com) (Manager), it returns below error
com.google.api.client.googleapis.json.GoogleJsonResponseException: 404 Not Found
{
  "code" : 404,
  "errors" : [ {
    "domain" : "global",
    "location" : "fileId",
    "locationType" : "parameter",
    "message" : "File not found: Ix6yw5La5iTg-n*********",
    "reason" : "notFound"
  } ],
  "message" : "File not found: Ix6yw5La5iTg-n*********"
}
1 Answers

The service account doesn't directly have access to anything dont look at test@integration-24524514.iam.gserviceaccount.com as a user account its not.

For a service account to access files on Google workspace it needs to have impersonation set up.

Think of impersonation as a singer pending to be Mikael Jackson at a concert. The singer has been granted permission to pretend or impersonate Mickael jackson. They are allowed to preform as him.

For the service account to be able to access a file owned by test@email.com it must have permission to impersonate test@email.com other wise it doesn't have access.

So if you want the service account to preform actions on behalf of a user and access files owned by that user then you need to set up impersonation.

GoogleCredential credential = GoogleCredential.fromStream(new FileInputStream("MyProject-1234.json"))
.createScoped(Collections.singleton(SQLAdminScopes.SQLSERVICE_ADMIN))
.createDelegated("test@email.com");
Related