将OAuth2令牌存储在UserProperties中是否存在安全风险?
Service Account Token Storage in UserProperties: Security Risks Explained
Great question—let’s break down your concerns about storing Bearer tokens in PropertiesService.getUserProperties() when using OAuth2 service account impersonation.
Can Users Access the Stored Token?
You’re right that there’s no built-in G Suite UI for users to directly view UserProperties values. However, there are a couple of edge cases to consider:
- Regular users (no script access): They can’t access the token at all. Without permission to edit the underlying Apps Script project, they have no way to run code that reads from
UserProperties. - Users with script edit permissions: If someone is a collaborator on your Apps Script project, they can write a simple snippet to fetch the token. For example:
This would let them retrieve the active Bearer token for the impersonated user.const props = PropertiesService.getUserProperties(); const token = props.getProperty('GoogleDrive:' + USER_EMAIL + '_access_token'); Logger.log(token);
What Can Someone Do With the Token, and How Long Is It Valid?
- Validity period: Google’s service account-generated Bearer tokens are indeed short-lived—they expire after 1 hour by default. Once expired, the token can’t be used to authenticate API requests anymore.
- Permissions granted: The token’s capabilities are strictly limited to the scope you defined:
https://www.googleapis.com/auth/drive. Anyone with the token can act as the impersonatedUSER_EMAILand perform any action allowed by that scope, including:- Viewing, editing, deleting, or sharing any files the user has access to
- Creating new files or folders in the user’s Drive
- Accessing team drives the user is part of (if applicable)
- Modifying Drive settings or preferences for that user
Quick Security Recommendations
To mitigate risks:
- Restrict script edit permissions to only trusted team members—avoid granting edit access to anyone who doesn’t need it.
- If possible, use narrower scopes instead of the full Drive scope (e.g.,
https://www.googleapis.com/auth/drive.readonlyif you only need read access) to limit potential damage if a token is exposed.
内容的提问来源于stack exchange,提问作者zlZimon
相关产品推荐
相关产品推荐

