I have read through this guide to figure out how the new Google Drive API security changes will affect our DMS application which integrates with google drive using the Google Drive API v2.
From what I understand, a file in google drive which has been shared via a link with domain/anyone will now need to have a resourceKey to get "files referenced by requests to the Drive API".
Question 1: What is meant by "files referenced by requests"? Our current application uses the /files/{id} endpoint to get details about the file (I assume that will include a resourceKey if one exists) and the application also uses the downloadUrl from the files details to download the file. Does the file download count as one of these "requests"? And will our integration break for downloading these link shared files if the user trying to download it hasn't "viewed" it yet?
Question 2: What is meant by "viewed" in this case? Does the user have to open the file for viewing in a browser for it to be considered viewed? If I called /files endpoint to list files within a folder and that link shared file was in that folder, would that be considered viewing the file?
Question 3: If the resourceKey is required for the download, will the resourceKey now be included in the downloadUrl of the response to /files/{id}? This particular blog post mentions that the resourceKey will be included in "exportLinks, webContentLink, and webViewLink" but I don't see any mention of downloadUrl anywhere.
Question 4: If I can access a resourceKey for a file using the /files/{id} endpoint without providing a resourceKey to the /files/{id} endpoint. Then how is this adding any extra security to the shared file?