Jump to content

Recommended Posts

Posted

Always worries me a little agreeing to 'this app can see and download all your 'data & contacts', see and delete all the files in your drive, view and manage all your information, find out where you live and throw a brick through your window if you uninstall it'... 

 

I mean I think understanding that it means the app needs to be able to create and delete files so it can function is still something I'm not getting... it always makes me pause before I hit the save button. Do you have to work out each time what will cripple the apps usability if you don't allow it access?

 

Take Canva for example, does anyone limit those scopes, or have a 'it will work with these scopes' cheat sheet I can use? Or just go 'yeah I let it see everything'?

Posted

Theres not much you can do really you either accept it's play store reuirements or you don't use it.

 

We've had a few I've said no to as they've literally been asking for everything under the sun.

Posted

Play Store...? This is for the Canva app (or an 'education' targeted version of) in Google Workspace. Thing is, we haven't really used apps and I certainly don't use these apps, so I'm not really sure what impact denying a scope will have. I mean for anyone that uses Canva, would denying any of the following affect any of the apps functions, or is it just losing an 'enhanced' experience? You know like in a Wonde approval request, there is the data that the app requires to function and then there are choices of sharing 'optional' data to enable extra functionality.... 

 

So, in Google Workspace OAuth Scopes:

 

image.png.42bb35ad0e5f6edbff20ce99a1f1db07.png

 

Unhelpfully, the flyout doesn't expand for the full description...

 

image.thumb.png.0771f98098f671b4833b9d577890c42f.png

image.png.b74a3bb010a30002a51a24e2b4fca487.png

Posted
1 minute ago, Koldov said:

Play Store...? This is for the Canva app (or an 'education' targeted version of) in Google Workspace. Thing is, we haven't really used apps and I certainly don't use these apps, so I'm not really sure what impact denying a scope will have. I mean for anyone that uses Canva, would denying any of the following affect any of the apps functions, or is it just losing an 'enhanced' experience? You know like in a Wonde approval request, there is the data that the app requires to function and then there are choices of sharing 'optional' data to enable extra functionality.... 

 

So, in Google Workspace OAuth Scopes:

 

image.png.42bb35ad0e5f6edbff20ce99a1f1db07.png

 

Unhelpfully, the flyout doesn't expand for the full description...

 

image.thumb.png.0771f98098f671b4833b9d577890c42f.png

image.png.b74a3bb010a30002a51a24e2b4fca487.png

Denying a scope will simply not allow the user to integrate their Google account with said application. I don't allow access to any 3rd party apps regardless of OU and user age. I only whitelist them when requested, and a DPIA has been filled in to ensure it's safe to use. I have seen horror stories before of users integrating/signing into inappropriate websites with work/school accounts, so this is just an added layer of protection.

 

Students don't have access to their email accounts here anyway, so they couldn't manually sign up either. Staff could "technically" however, emails can be caught in the spam filter or searched if needed to.

Posted
12 minutes ago, HyperTech said:

Denying a scope will simply not allow the user to integrate their Google account with said application.

 

I thought there was multiple parts as to whether an app can be used or not though. 

 

14 minutes ago, HyperTech said:

 I don't allow access to any 3rd party apps regardless of OU and user age. I only whitelist them when requested, and a DPIA has been filled in to ensure it's safe to use. I have seen horror stories before of users integrating/signing into inappropriate websites with work/school accounts, so this is just an added layer of protection.

 

I don't allow 3rd Party apps here either in general. This is the first app I've whitelisted, so initially they need to be allowlisted for the specific OUs...

 

Apps > Google Workspace Marketplace apps > Allowlisted Apps

 

Then...

 

Security > API controls > App access control

 

You can choose from Trusted or Limited which are blanket scopes

 

Or you can choose a more fine grained/detailed approach by choosing 'Specific Google data'...

 

It's these other scopes which detail what data the app can see, or what it can do with that data (integrate with) and it's these individual scopes I'm interested in and how they interact with the functionality of the app.

 

The following scope is the one to allow Sign-In with Google...

 

Note, you must include the Google Sign-In scope below to allow users to sign in with their Google Account.

 

The scope needed to allow Google Sign-In to the app...

 

This is the first app I've allowed, so I want to get it right.

 

23 minutes ago, HyperTech said:

Students don't have access to their email accounts here anyway, so they couldn't manually sign up either. Staff could "technically" however, emails can be caught in the spam filter or searched if needed to.

 

Students don't have email here, but when they are signed in to Google, the primary barrier to them is that access to 3rd Party apps is blocked unless allowlisted and then it would have to be allowed in their specific OU.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...