{"id":987517321,"date":"2025-01-09T00:11:21","date_gmt":"2025-01-09T00:11:21","guid":{"rendered":"https:\/\/workspace.trace.pt\/granular-oauth-consent-in-google-apps-script-ide-executions\/"},"modified":"2025-01-09T00:11:21","modified_gmt":"2025-01-09T00:11:21","slug":"granular-oauth-consent-in-google-apps-script-ide-executions","status":"publish","type":"post","link":"https:\/\/workspace.trace.pt\/es\/granular-oauth-consent-in-google-apps-script-ide-executions\/","title":{"rendered":"Granular OAuth consent in Google Apps Script IDE executions"},"content":{"rendered":"<h3>Qu\u00e9 est\u00e1 cambiando<\/h3>\n<div>Google offers a wide variety of APIs that Google Apps Script developers can use to build features for Google users. The data access that these APIs can reference is governed by the <a href=\"https:\/\/developers.google.com\/apps-script\/concepts\/scopes\">OAuth scopes<\/a> of each Workspace application, which users are required to authorize before a script can run. Historically, the OAuth consent screen has asked the user to authorize all of the necessary OAuth scopes to run a given script.\u00a0<\/div>\n<div><\/div>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguq-J8xbeYGZOcjUcqBOPAyRoeUcTLrzrl-xwRYGdYwFtKOv7LMO9ipgJF9_9MQXDWW0YTrb3hjdLTtP6L1BhN63M6iUnsN0shFpLaB_ICq-83sGnyi4oePtCfF5NigGpOVcAytuAYM07ISvXCiHkft07n625g9b-9D8hXAyUpF9-XJdg8mX8EQGmO8N4\/s1284\/This%20screenshot%20shows%20the%20current%20OAuth%20consent%20screen,%20which%20requires%20the%20user%20to%20authenticate%20all%20or%20none%20of%20the%20requested%20OAuth%20scopes.png\"><img loading=\"lazy\" decoding=\"async\" alt=\"This screenshot shows the current OAuth consent screen, which requires the user to authenticate all or none of the requested OAuth scopes.\" border=\"0\" data-original-height=\"1284\" data-original-width=\"964\" height=\"400\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEguq-J8xbeYGZOcjUcqBOPAyRoeUcTLrzrl-xwRYGdYwFtKOv7LMO9ipgJF9_9MQXDWW0YTrb3hjdLTtP6L1BhN63M6iUnsN0shFpLaB_ICq-83sGnyi4oePtCfF5NigGpOVcAytuAYM07ISvXCiHkft07n625g9b-9D8hXAyUpF9-XJdg8mX8EQGmO8N4\/w300-h400\/This%20screenshot%20shows%20the%20current%20OAuth%20consent%20screen,%20which%20requires%20the%20user%20to%20authenticate%20all%20or%20none%20of%20the%20requested%20OAuth%20scopes.png\" width=\"300\"><\/a><\/div>\n<div><i><span>This screenshot shows the <u>old\u00a0<\/u>OAuth consent screen, which requires the user to authenticate all or none of the requested OAuth scopes.<\/span><\/i><\/div>\n<div><span><i><br \/><\/i><\/span><\/div>\n<div><\/div>\n<div>Starting today, the OAuth consent screen will now let users specify which individual OAuth scopes they would like to authorize. For example, if a script requests access to a user\u2019s Sheets and Forms files, and the users only intends to use the script with Sheets files, they can decide to only allow access to their spreadsheets and not their forms. This affords users the benefit of more granular control over what data their 3P applications are allowed to access.<\/div>\n<div><\/div>\n<div class=\"separator\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6PtAOBzHxLZTeaYTFY4G-DLf180eMY2qVeQxiy0RmjSFQ-AoFMCINPZ_d6LHSjKVZrXFWgFJ0MtYdbg3k-JD_YnBCikhOzW8czfEtn1vtwpCtgVv8tZvUkcEpJxFqV0Nrxh1nGiN2xTewufXhNqCdcf_dHUcjDsTt6FjEXWnjtpEt_prgRCBJ0mAzGy0\/s1546\/This%20screenshot%20shows%20the%20new%20OAuth%20consent%20screen,%20which%20lets%20the%20user%20provide%20consent%20for%20a%20subset%20of%20the%20requested%20OAuth%20scopes.png\"><img loading=\"lazy\" decoding=\"async\" alt=\"This screenshot shows the new OAuth consent screen, which lets the user provide consent for a subset of the requested OAuth scopes.\" border=\"0\" data-original-height=\"1546\" data-original-width=\"960\" height=\"400\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj6PtAOBzHxLZTeaYTFY4G-DLf180eMY2qVeQxiy0RmjSFQ-AoFMCINPZ_d6LHSjKVZrXFWgFJ0MtYdbg3k-JD_YnBCikhOzW8czfEtn1vtwpCtgVv8tZvUkcEpJxFqV0Nrxh1nGiN2xTewufXhNqCdcf_dHUcjDsTt6FjEXWnjtpEt_prgRCBJ0mAzGy0\/w249-h400\/This%20screenshot%20shows%20the%20new%20OAuth%20consent%20screen,%20which%20lets%20the%20user%20provide%20consent%20for%20a%20subset%20of%20the%20requested%20OAuth%20scopes.png\" width=\"249\"><\/a><\/div>\n<div><span>This screenshot shows the <u>new<\/u> OAuth consent screen, which lets the user provide consent for a subset of the requested OAuth scopes.<\/span><\/div>\n<div><\/div>\n<div><\/div>\n<h3>M\u00e1s informaci\u00f3n<\/h3>\n<div>To complement the release of this new consent flow, we\u2019re also adding methods to the <a href=\"https:\/\/developers.google.com\/apps-script\/reference\/script\/script-app\">ScriptApp<\/a> y <a href=\"https:\/\/developers.google.com\/apps-script\/reference\/script\/authorization-info\">AuthorizationInfo<\/a> classes that let Apps Script developers programmatically interact with the scopes granted for a script. <a href=\"https:\/\/developers.google.com\/apps-script\/reference\/script\/script-app\">Refer to the developer documentation<\/a>\u00a0para m\u00e1s informaci\u00f3n.<\/div>\n<div><\/div>\n<div>After a user grants permission to a script, Apps Script might request OAuth consent again in the following cases:\u00a0<\/div>\n<div>\n<ul>\n<li>The user, who has granted consent to a subset of the requested OAuth scopes, tries to run a part of the script that was not previously authorized.\u00a0<\/li>\n<li>The script is updated in such a way that it requires permission for additional scopes.\u00a0<\/li>\n<li>The user revoked access to the script from their <a href=\"https:\/\/myaccount.google.com\/connections\">Google Account settings.<\/a><\/li>\n<\/ul>\n<p>All past execution failures will be logged in the execution history. Each OAuth failure will contain a hyperlink that users can use to provide the permissions that were missing.\u00a0<\/p><\/div>\n<div><\/div>\n<div><\/div>\n<h3>Getting Started\u00a0<\/h3>\n<div>\n<ul>\n<li><b>Admins:<\/b> There is no admin control for this feature.\u00a0<\/li>\n<li><b>Developers and end users:\u00a0<\/b><\/li>\n<ul>\n<li>Granular OAuth consent is only available for scripts that have finished migrating to the V8 runtime. If you would like to utilize granular consent on one of the few remaining Rhino scripts, you can manually migrate to V8 by following <a href=\"https:\/\/developers.google.com\/apps-script\/guides\/v8-runtime\/migration\">these instructions.<\/a><\/li>\n<li>This new consent screen will only be used for new OAuth scope grants. Pre-existing scope grants <u>will not be affected<\/u>, so no action is required by users on scripts they\u2019ve already authorized.\u00a0<\/li>\n<li>The new consent screen will be launched first to the Apps Script IDE (i.e. executing a script directly from Apps Script). The consent screen will launch to the remaining surfaces in the future:\u00a0<\/li>\n<ul>\n<li>Google Ads Script<\/li>\n<li>Macro executions\u00a0<\/li>\n<li>Trigger executions\u00a0<\/li>\n<li>Web app executions\u00a0<\/li>\n<li>API Executions\u00a0<\/li>\n<li>Chat apps<\/li>\n<li>Add-ons\u00a0<\/li>\n<\/ul>\n<\/ul>\n<\/ul>\n<\/div>\n<h3>Ritmo de implantaci\u00f3n\u00a0<\/h3>\n<div>\n<ul>\n<li><a href=\"https:\/\/support.google.com\/a\/answer\/172177\">Dominios de Liberaci\u00f3n R\u00e1pida y Liberaci\u00f3n Programada:<\/a> Extended rollout (potentially longer than 15 days for feature visibility) starting on January 8, 2025, with expected completion by January 24, 2025\u00a0<\/li>\n<\/ul>\n<\/div>\n<div><\/div>\n<h3>Disponibilidad\u00a0<\/h3>\n<div>\n<ul>\n<li>Disponible para todos los clientes de Google Workspace y suscriptores individuales de Workspace\n<\/li>\n<\/ul>\n<h3>Recursos<\/h3>\n<\/div>\n<ul>\n<li><a href=\"https:\/\/developers.google.com\/apps-script\/guides\/v8-runtime\/migration\">Developer Documentation: Migrating scripts to the V8 runtime<\/a><\/li>\n<li><a href=\"https:\/\/developers.google.com\/apps-script\/reference\/script\/script-app\">Developer Documentation:\u00a0Class ScriptApp\u00a0<\/a><\/li>\n<\/ul>\n<div><\/div>","protected":false},"excerpt":{"rendered":"<p>What\u2019s changing Google offers a wide variety of APIs that Google Apps Script developers can use to build features for Google users. The data access that these APIs can reference is governed by the OAuth scopes of each Workspace application, which users are required to authorize before a script can run. Historically, the OAuth consent [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[1],"tags":[],"class_list":["post-987517321","post","type-post","status-publish","format-standard","hentry","category-noticias"],"acf":[],"_links":{"self":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts\/987517321","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/comments?post=987517321"}],"version-history":[{"count":0,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/posts\/987517321\/revisions"}],"wp:attachment":[{"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/media?parent=987517321"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/categories?post=987517321"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/workspace.trace.pt\/es\/wp-json\/wp\/v2\/tags?post=987517321"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}