You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过App Script函数撤销第三方应用对Google表格的访问权限?

如何通过Google Apps Script撤销第三方应用对Google表格的访问权限?

可以实现,但你尝试的ScriptApp.getAuthorization()方法已废弃,且该方法仅用于获取脚本自身的授权信息,无法操作第三方应用的权限。以下是两种可行方案,分别适用于普通个人账户和Google Workspace管理员:

普通个人账户方案:借助OAuth2库调用Google Identity API

普通用户需要通过OAuth2授权来调用Google的权限撤销接口,步骤如下:

  1. 安装OAuth2库
    在脚本编辑器中,点击「资源」>「库」,输入库ID 1B7FSrk5Zi6L1rSxxTDgDEUsPzlukDsi4KGuTMorsTQHhGBzBkMun4iDF,选择最新版本后添加。

  2. 创建Google Cloud OAuth客户端ID
    在Google Cloud控制台中创建一个OAuth客户端ID,类型选择「桌面应用」或「Web应用」,记录下生成的clientId和clientSecret。

  3. 编写撤销权限脚本

    function revokeThirdPartyAccess() {
      // 替换为你的OAuth客户端ID和密钥
      var clientId = 'YOUR_CLIENT_ID';
      var clientSecret = 'YOUR_CLIENT_SECRET';
      
      // 配置OAuth2服务
      var service = OAuth2.createService('RevokeAccess')
        .setAuthorizationBaseUrl('https://accounts.google.com/o/oauth2/auth')
        .setTokenUrl('https://oauth2.googleapis.com/token')
        .setClientId(clientId)
        .setClientSecret(clientSecret)
        .setCallbackFunction('authCallback')
        .setPropertyStore(PropertiesService.getUserProperties())
        .setScope('https://www.googleapis.com/auth/auth.revoke');
    
      if (!service.hasAccess()) {
        var authorizationUrl = service.getAuthorizationUrl();
        SpreadsheetApp.getUi().alert('请复制以下链接到浏览器授权:\n' + authorizationUrl);
        return;
      }
    
      // 替换为要撤销权限的第三方应用客户端ID
      // 该ID可从Google账户「数据与隐私>第三方应用和服务」的应用详情中获取
      var targetClientId = 'TARGET_APP_CLIENT_ID';
      
      // 调用撤销API(撤销当前授权令牌对应的所有权限)
      var response = UrlFetchApp.fetch('https://oauth2.googleapis.com/revoke?token=' + service.getAccessToken(), {
        method: 'POST'
      });
    
      // 若需精准撤销特定应用权限,可使用以下端点:
      // var response = UrlFetchApp.fetch('https://accounts.google.com/o/oauth2/revoke?client_id=' + targetClientId, {
      //   method: 'POST',
      //   headers: { 'Authorization': 'Bearer ' + service.getAccessToken() }
      // });
    
      if (response.getResponseCode() === 200) {
        SpreadsheetApp.getUi().alert('权限已成功撤销');
      } else {
        SpreadsheetApp.getUi().alert('撤销失败:' + response.getContentText());
      }
    }
    
    function authCallback(request) {
      var service = OAuth2.createService('RevokeAccess');
      var isAuthorized = service.handleCallback(request);
      return HtmlService.createHtmlOutput(isAuthorized ? '授权成功,请关闭此页面返回表格' : '授权失败');
    }
    
  4. 运行脚本
    首次运行会提示授权,按指引完成后即可执行撤销操作。

Google Workspace管理员方案:使用Admin SDK Directory API

如果你是Workspace管理员,可直接通过Admin SDK批量或精准撤销用户的第三方应用权限:

  1. 启用Admin SDK高级服务
    在脚本编辑器中,点击「资源」>「高级Google服务」,找到「Admin SDK Directory API」并开启,同时确保对应Google Cloud项目中的API已启用。

  2. 编写管理员权限撤销脚本

    function revokeAppAccessForUser() {
      // 替换为目标用户的邮箱和第三方应用客户端ID
      var userEmail = 'user@yourdomain.com';
      var targetClientId = 'TARGET_APP_CLIENT_ID';
      
      try {
        AdminDirectory.Oauth2client.revoke(userEmail, targetClientId);
        SpreadsheetApp.getUi().alert('已成功撤销该用户对目标应用的权限');
      } catch (e) {
        SpreadsheetApp.getUi().alert('撤销失败:' + e.message);
      }
    }
    

关键说明

  • 你之前使用的ScriptApp.getAuthorization()已被废弃,且仅用于管理脚本自身的授权,无法操作第三方应用权限。
  • 普通用户必须手动获取第三方应用的客户端ID,无法通过脚本自动枚举(Google未提供相关接口)。

内容的提问来源于stack exchange,提问作者Bruno Carvalho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.15 06:02:21