2017-03-02 388 views
0

我正在玩Java Script Google Drive API,並能夠通過API成功獲取我的谷歌驅動器內容。如何將訪問我的Google雲端硬盤中的某些文件夾的權限授予通過Google Drive API登錄的用戶

現在讓我們說我在某些文件夾中有某些文件,並且由其他用戶登錄到我的應用程序,他們可以在我的驅動器中訪問這些文件。目前的Google Drive API可以讓用戶登錄我的APP並在我的谷歌驅動器中訪問我的文件。

這裏是從谷歌驅動讀取文件中的代碼:從這個documentation,當你的應用程序需要訪問用戶數據基於

<!DOCTYPE html> 
<html> 
    <head> 
    <title>Drive API Quickstart</title> 
    <meta charset='utf-8' /> 
    </head> 
    <body> 
    <p>Drive API Quickstart</p> 

    <!--Add buttons to initiate auth sequence and sign out--> 
    <button id="authorize-button" style="display: none;">Authorize</button> 
    <button id="signout-button" style="display: none;">Sign Out</button> 

    <pre id="content"></pre> 

    <script type="text/javascript"> 
     // Client ID and API key from the Developer Console 
     var CLIENT_ID = 'CLIENT_ID_GOES_HERE'; 

     // Array of API discovery doc URLs for APIs used by the quickstart 
     var DISCOVERY_DOCS = ["https://www.googleapis.com/discovery/v1/apis/drive/v3/rest"]; 

     // Authorization scopes required by the API; multiple scopes can be 
     // included, separated by spaces. 
     var SCOPES = 'https://www.googleapis.com/auth/drive.metadata.readonly'; 

     var authorizeButton = document.getElementById('authorize-button'); 
     var signoutButton = document.getElementById('signout-button'); 

     /** 
     * On load, called to load the auth2 library and API client library. 
     */ 
     function handleClientLoad() { 
     gapi.load('client:auth2', initClient); 
     } 

     /** 
     * Initializes the API client library and sets up sign-in state 
     * listeners. 
     */ 
     function initClient() { 
     gapi.client.init({ 
      discoveryDocs: DISCOVERY_DOCS, 
      clientId: CLIENT_ID, 
      scope: SCOPES 
     }).then(function() { 
      // Listen for sign-in state changes. 
      gapi.auth2.getAuthInstance().isSignedIn.listen(updateSigninStatus); 

      // Handle the initial sign-in state. 
      updateSigninStatus(gapi.auth2.getAuthInstance().isSignedIn.get()); 
      authorizeButton.onclick = handleAuthClick; 
      signoutButton.onclick = handleSignoutClick; 
     }); 
     } 

     /** 
     * Called when the signed in status changes, to update the UI 
     * appropriately. After a sign-in, the API is called. 
     */ 
     function updateSigninStatus(isSignedIn) { 
     if (isSignedIn) { 
      authorizeButton.style.display = 'none'; 
      signoutButton.style.display = 'block'; 
      listFiles(); 
     } else { 
      authorizeButton.style.display = 'block'; 
      signoutButton.style.display = 'none'; 
     } 
     } 

     /** 
     * Sign in the user upon button click. 
     */ 
     function handleAuthClick(event) { 
     gapi.auth2.getAuthInstance().signIn(); 
     } 

     /** 
     * Sign out the user upon button click. 
     */ 
     function handleSignoutClick(event) { 
     alert('out'); 
     auth2.disconnect(); 
     gapi.auth2.getAuthInstance().signOut(); 
     } 

     /** 
     * Append a pre element to the body containing the given message 
     * as its text node. Used to display the results of the API call. 
     * 
     * @param {string} message Text to be placed in pre element. 
     */ 
     function appendPre(message) { 
     var pre = document.getElementById('content'); 
     var textContent = document.createTextNode(message + '\n'); 
     pre.appendChild(textContent); 
     } 

     /** 
     * Print files. 
     */ 
     function listFiles() { 
     gapi.client.drive.files.list({ 
      'pageSize': 10, 
      'fields': "nextPageToken, files(id, name)" 
     }).then(function(response) { 
      appendPre('Files:'); 
      var files = response.result.files; 
      if (files && files.length > 0) { 
      for (var i = 0; i < files.length; i++) { 
       var file = files[i]; 
       appendPre(file.name + ' (' + file.id + ')'); 
      } 
      } else { 
      appendPre('No files found.'); 
      } 
     }); 
     } 

    </script> 

    <script async defer src="https://apis.google.com/js/api.js" 
     onload="this.onload=function(){};handleClientLoad()" 
     onreadystatechange="if (this.readyState === 'complete') this.onload()"> 
    </script> 
    </body> 
</html> 
+0

任何有此API使用經驗的人? – Wolverine

回答

0

,它要求谷歌對接入的特定scope

範圍https://www.googleapis.com/auth/drive.file以實用的方式達到了這個平衡。據推測,用戶只能打開或創建一個他們信任的應用程序的文件,理由是他們理解的。

如上所述,here,文件夾的訪問由訪問控制列表(ACL)確定。 ACL是確定用戶是否可以對文件執行操作(例如讀取或寫入)的權限列表。您可以檢查permissions guide以瞭解關於權限和角色的更多詳細信息。

相關問題