Resumable_Upload_For_WebApps icon indicating copy to clipboard operation
Resumable_Upload_For_WebApps copied to clipboard

Concern

Open manujindal77 opened this issue 7 years ago • 7 comments

Is it ok to send the token to the client? Anyone can access your Drive with that token.

manujindal77 avatar May 20 '18 05:05 manujindal77

At the condition of Web Apps in this sample, only owner can use this script. So other users cannot see the access token. You can see the detail information of the condition for Web Apps at here.

tanaikech avatar May 20 '18 06:05 tanaikech

Perfect!

manujindal77 avatar May 20 '18 08:05 manujindal77

When Web Apps is deployed, if "Execute the app as:" and "Who has access to the app:" are "Me" and "Only myself", respectively, other users cannot access to the deployed Web Apps. If they are deployed as "Anyone, even anonymous" and "Anyone", other users can access to the deployed Web Apps. Please be careful the setting condition, when you use this.

tanaikech avatar May 20 '18 08:05 tanaikech

I do not understand. So is it safe to deploy with "who can access" to anyone? In that case other can get the OAuthToken?

cimenta avatar Aug 25 '22 16:08 cimenta

Thank you for your comment. And, I have to apologize for my poor English skill. Unfortunately, I cannot understand So is it safe to deploy with "who can access" to anyone? In that case other can get the OAuthToken?. Can I ask you about the detail of your question?

tanaikech avatar Aug 26 '22 00:08 tanaikech

in the comment from May 2018 you said that we have to be careful. I want to have a GAS web application that anybody can upload files for me. So I have to deploy as "anyone". So I guess someone with good javascript knowledge could get the OAuth token. Can they the OAuth token somehow misuse?

cimenta avatar Aug 26 '22 17:08 cimenta

Thank you for replying. From your replying, in your situation, is this post useful? https://github.com/tanaikech/Safe-Uploading-for-Google-Drive-by-HTML-in-External-Server-using-Google-Apps-Script

tanaikech avatar Aug 27 '22 00:08 tanaikech