导出Google Drive Workspace文件时触发insufficientFilePermissions错误
解决Google Drive Workspace文件导出时的insufficientFilePermissions错误
问题现象
导出Google Drive Workspace文件时触发403权限错误,错误详情如下:
googleapiclient.http:Encountered 403 Forbidden with reason "insufficientFilePermissions" <HttpError 403 when requesting https://www.googleapis.com/drive/v3/files/{File_ID}/export?mimeType=application%2Fvnd.oasis.opendocument.presentation&alt=media returned " The user does not have sufficient permissions for this file.". Details: "[{ 'message': 'The user does not have sufficient permissions for this file.', 'domain': 'global', 'reason': 'insufficientFilePermissions' }]">
使用官方导出代码,自身环境配置服务账号后可正常下载,但客户环境下相同代码仅对Workspace文件报错,其他类型文件下载正常。目标文件的结构信息如下:
{ 'kind': 'drive#file', 'copyRequiresWriterPermission': False, 'writersCanShare': True, 'viewedByMe': True, 'mimeType': 'application/vnd.google-apps.presentation', 'exportLinks': { 'application/vnd.oasis.opendocument.presentation': 'https://docs.google.com/feeds/download/presentations/Export?id={file_id}&exportFormat=odp', 'application/pdf': 'https://docs.google.com/feeds/download/presentations/Export?id={file_id}&exportFormat=pdf', 'application/vnd.openxmlformats-officedocument.presentationml.presentation': 'https://docs.google.com/feeds/download/presentations/Export?id={file_id}&exportFormat=pptx', 'text/plain': 'https://docs.google.com/feeds/download/presentations/Export?id={file_id}&exportFormat=txt' }, 'parents': ['root'], 'thumbnailLink': 'https://docs.google.com/feeds/vt?gd=true&id={file_id}&v=2&s=AMedNnoAAAAAZH2QVm6sssfJMwvO4_wZtTxvWk9-VGZP&sz=s220', 'iconLink': 'https://drive-thirdparty.googleusercontent.com/16/type/application/vnd.google-apps.presentation', 'shared': False, 'lastModifyingUser': { 'displayName': '{user_name}', 'kind': 'drive#user', 'me': True, 'permissionId': '{permissionId}', 'emailAddress': '{email_id}' }, 'owners': [{ 'displayName': '{user_name}', 'kind': 'drive#user', 'me': True, 'permissionId': '{permissionId}', 'emailAddress': '{email_id}' }], 'webViewLink': 'https://docs.google.com/presentation/d/{file_id}/edit?usp=drivesdk', 'viewersCanCopyContent': True, 'permissions': [{ 'id': '{permissionId}', 'displayName': '{user_name}', 'type': 'user', 'kind': 'drive#permission', 'emailAddress': '{email_id}', 'role': 'owner', 'deleted': False, 'pendingOwner': False }], 'hasThumbnail': True, 'spaces': ['drive'], 'id': '{file_id}', 'name': '{file name}', 'starred': False, 'trashed': False, 'explicitlyTrashed': False, 'createdTime': '2022-02-22T04:05:47.677Z', 'modifiedTime': '2022-02-22T04:05:51.475Z', 'modifiedByMeTime': '2022-02-22T04:05:51.475Z', 'viewedByMeTime': '2022-02-22T04:05:51.475Z', 'quotaBytesUsed': '0', 'version': '275', 'ownedByMe': True, 'isAppAuthorized': False, 'capabilities': { 'canChangeViewersCanCopyContent': True, 'canEdit': True, 'canCopy': True, 'canComment': True, 'canAddChildren': False, 'canDelete': True, 'canDownload': True, 'canListChildren': False, 'canRemoveChildren': False, 'canRename': True, 'canTrash': True, 'canReadRevisions': True, 'canChangeCopyRequiresWriterPermission': True, 'canMoveItemIntoTeamDrive': True, 'canUntrash': True, 'canModifyContent': True, 'canMoveItemOutOfDrive': True, 'canAddMyDriveParent': False, 'canRemoveMyDriveParent': True, 'canMoveItemWithinDrive': True, 'canShare': True, 'canMoveChildrenWithinDrive': False, 'canModifyContentRestriction': True, 'canChangeSecurityUpdateEnabled': False, 'canAcceptOwnership': False, 'canReadLabels': True, 'canModifyLabels': True }, 'thumbnailVersion': '2', 'modifiedByMe': True, 'permissionIds': ['{permissionId}'], 'linkShareMetadata': { 'securityUpdateEligible': False, 'securityUpdateEnabled': True } }
排查与解决步骤
- 确认服务账号文件权限:将服务账号邮箱添加为目标Workspace文件的协作者,分配编辑权限——仅查看权限无法触发导出操作,这是Workspace文件和普通文件的权限差异点。
- 检查全域委派配置:若客户使用Google Workspace域名,需在Admin控制台为服务账号启用全域委派,并确保授予的OAuth2范围包含
https://www.googleapis.com/auth/drive(或验证drive.readonly是否支持导出)。 - 修正文件共享状态:目标文件
'shared': False,未公开共享,需确保服务账号被明确添加到文件权限列表,而非依赖域内默认权限。 - 验证接口权限范围:
files.export接口需要特定权限范围,确认服务账号的授权范围包含该接口的访问权限,避免范围限制导致报错。 - 临时替代方案:若上述配置无法快速调整,可先调用
files.copy接口复制目标文件到服务账号有权限的目录,再导出复制后的文件。
内容的提问来源于stack exchange,提问作者Deepak Saini
相关产品推荐
相关产品推荐

