Jump to content

GSuite - 3rd party apps - API controls - Apps access control


Recommended Posts

Posted
You may be right...

 

So forget my answer above!

 

Disappointingly, I have also just managed to sign-up to something called 'Lumin PDF' (didn't want to try OnlyFans) which requires 'Drive' access.

 

It is already on the list of 3rd Party apps, but I've set it to 'Limited' and the 'Google Service' for 'Drive' is set to 'Restricted - High-Risk Access'.

 

Created a document and uploaded it to my Google Drive...

 

Audit log for Token:

 

*USER* authorized access to Lumin PDF for

openid, ht tps://www.googleapis.com/auth/userinfo

profile, ht tps://www.googleapis.com/auth/userinfo

email, ht tps://www.googleapis.com/auth/drive.appdata

ht tps://www.googleapis.com/auth/drive.file scopes

 

In the Google Services tab it also still says 15 allowed apps for Drive.

It may be that apps can create files but only access what they create.

That may fall outside high risk since it isnt sticking its nose in anything else

 

[color=#3C4043][font=Roboto]For Gmail, high-risk OAuth scopes are:[/font][/color]
[list]
[*]https://mail.google.com/
[*]https://www.googleapis.com/auth/gmail.compose
[*]https://www.googleapis.com/auth/gmail.insert
[*]https://www.googleapis.com/auth/gmail.metadata
[*]https://www.googleapis.com/auth/gmail.modify
[*]https://www.googleapis.com/auth/gmail.readonly
[*]https://www.googleapis.com/auth/gmail.send
[*]https://www.googleapis.com/auth/gmail.settings.basic
[*]https://www.googleapis.com/auth/gmail.settings.sharingFor details about Gmail scopes, see [url="https://developers.google.com/gmail/api/auth/scopes"]Choose Auth Scopes[/url].
[/list]
[color=#3C4043][font=Roboto]For Drive, high-risk OAuth scopes are:[/font][/color]

[list]
[*][url]https://www.googleapis.com/auth/drive[/url]
[*][url]https://www.googleapis.com/auth/drive.apps.readonly[/url]
[*][url]https://www.googleapis.com/auth/drive.metadata[/url]
[*][url]https://www.googleapis.com/auth/drive.metadata.readonly[/url]
[*][url]https://www.googleapis.com/auth/drive.readonly[/url]
[*][url]https://www.googleapis.com/auth/drive.scripts[/url]
[*][url]https://www.googleapis.com/auth/documents[/url]
[/list]

Posted (edited)
Checked my sites and nothing beyond some EDU apps (phew!). If the bold apps are "worrisome", I'd argue that many legit artists use Patreon (Professor Elemental and Abney Park often push it).

 

Yes, of course there are probably legitimate users on both of those platforms and I did explain that to our Safeguarding team. It's just that you know... 'school'... 'responsibilty'... 'media outcry'... ''student uses account to sign up to p0rn'... I can see it now!

 

It may be that apps can create files but only access what they create.

That may fall outside high risk since it isnt sticking its nose in anything else

 

Actually, I think I do remember that there was a tick box to agree to only do that, wonder what would happen if I untick it?!

 

Upshot is... we can't stop them signing up to anything they like with their school Google account or stop the apps accessing GSuite Services as long as they promise not to do anything naughty?

Edited by Koldov
Posted
Yes, of course there are probably legitimate users on both of those platforms and I did explain that to our Safeguarding team. It's just that you know... 'school'... 'responsibilty'... 'media outcry'... ''student uses account to sign up to p0rn'... I can see it now!

 

 

 

Actually, I think I do remember that there was a tick box to agree to only do that, wonder what would happen if I untick it?!

 

Upshot is... we can't stop them signing up to anything they like with their school Google account?

 

I haven't searched Patreon (and only learnt of OnlyFans in this thread!) but I thought it was mainly legit.

 

Anyway, as we're KS1/2 we don't let them receive mail from outside the domain, so I guess signups are stopped that way.

Posted

i was under the impression restricted without high risk scopes ticked would block everything - been so long since i had the war of locking down all the things to remember!

 

if youre in a position to try it make a test account and try to sign up with lumen

Posted
i just installed Clicker Writer onto our Chromebooks and as far as I can tell it was completely blocked from doing anything until I gave it access in the app API security page. I dont think they could even sign-in, at least that was the messaage from the teacher.
Posted (edited)

Well, looks like I'm going down this rabbit hole, too!

 

We've got OnlyFans, many phone games, social networks (mostly TikTok, but also Facebook, Instagram and Reddit).

 

Going to be doing some more digging into the services I don't recognise, and writing an email to our DSL, methinks.

Edited by Garacesh
Posted (edited)

@fiza It does, just not on that screen you have to go into the reporting section: Reports > Audit > Token > Search by Application Name

 

I think if the app is already listed as limited after you set the restriction to the services you'll need to block them if you want to deny usage. Any new app that requests API access will hit the restrictive blockade though. So it's a case of setting restrictions, trusting/blocking existing apps in the list, and then adding apps to the trust in the future that you want to give access too.

Edited by Tones
how on earth do you do a mention? :(
  • Thanks 1
Posted
@fiza It does, just not on that screen you have to go into the reporting section: Reports > Audit > Token > Search by Application Name

 

I think if the app is already listed as limited after you set the restriction to the services you'll need to block them if you want to deny usage. Any new app that requests API access will hit the restrictive blockade though. So it's a case of setting restrictions, trusting/blocking existing apps in the list, and then adding apps to the trust in the future that you want to give access too.

 

Thank you!!

  • 2 weeks later...
Posted

Could be what some of us are looking for...

 

Unfortunately we do use 3rd party apps such as SMART and ADOBE.

 

Does this single tick box disable ALL 3rd party app API access as in DENY > ALLOW.

 

It would be worthwhile using if specifically allowed apps were still able to work as since the original post I went through and blocked all the other apps and I've just checked now and the following have been added to the list (as 'limited') since:

 

Picture This

Nimses

MaraPets

ZEE5

azar

Brilliant.org

Project-451217118864

Likee

Reddit

Uber

Urban Dictionary

 

I just want to completely block all API access (especially sign-in) to apps unless I specifically allow them, not have to check everyday and block randoms.

 

I thought I'd got a handle on it and had my settings to block it (restricted without low-risk scopes ticked), but this new setting seems to be the only way to block 'sign-in scopes' unless I'm missing something (which is entirely possible). Seems like they know it's a problem for us but have fixed it with a sledge hammer to crack a nut... something slightly more nuanced would be better.

Posted

Here's another one... in Apps > Google Workspace > Settings for Classroom > Data access

 

Does anybody know if this setting overrides anything set in the 3rd Party API setting?

 

classroom_api.jpg

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...