top | item 23132289

(no title)

slouch | 5 years ago

Hi, I'm not OP, but have built a similar thing. Are you suggesting to use https://www.googleapis.com/auth/drive.file instead of https://www.googleapis.com/auth/spreadsheets?

discuss

order

benatkin|5 years ago

Yeah. It gives read/write access to one file. The ideal for this use case would be read only access for one file. I think read/write access for one file follows the principle of least privilege better than read access for all files. https://developers.google.com/drive/api/v2/about-auth https://en.wikipedia.org/wiki/Principle_of_least_privilege