Google Calendar api permissions - Service account

Viewed 124

I have a script which modifies my work supplied GCal. For authentication I use an access/refresh token (like this: https://developers.google.com/people/quickstart/python).

I want to run the script in Docker now. For authentication I have decided to use a service account.

I have created the service account, shared my calendar with it and accepted the calendar. In the Google Console where you create the service account, I set the permission to "owner".

When I try to run the script using the service account (not in Docker yet) it returns only a subset of attributes for each calendar event. I can see that accessRole = freeBusyReader.

How do I grant write access to this service account? I have tried:

rule = service.acl().get(calendarId="myId", ruleId='user:service@myApp-351310.iam.gserviceaccount.com').execute()  # Get this from acl_items
rule["role"] = "owner"
service.acl().update(calendarId="myId", ruleId="user:service@myApp-351310.iam.gserviceaccount.com", body=rule).execute()

I have read about firmwide delegation and impersonation of users. I'm not sure if this is requred or not. Does anyone know how to do this?

1 Answers

The code to authenticate a service account is slightly different then the sample you were using for an installed application it is as follows.

credentials = ServiceAccountCredentials.from_json_keyfile_name(
            key_file_location, scopes=scopes)
credentials = credentials.create_delegated(user_email)

This video shows How to create Google Oauth2 Service account credentials. just make sure to enable the google calendar api.

Remember service accounts are only supported via domain wide delegation to users on your google workspace domain. You cant use a standard google gmail user.

I recommend following the Delegate domain-wide authority to your service account sample it shows how to set up the delegation to a service account from your workspace domain. Just change out the section about admin sdk to that of google calendar as this is the api you are trying to connect to.

You add the user_Email being the user on your domain you want the service account to impersonate.

Related