Data Studio双API密钥认证连接器开发安全性问询
Data Studio双密钥连接器:安全风险与凭据存储问题解答
Hey there! Let's break down your questions about building a Data Studio connector that requires both an API_KEY and API_SECRET—since the platform doesn't natively support dual-key authentication, your approach makes sense, but let's dig into the details.
1. 这种实现方式的安全风险分析
First off, using the NONE auth type and collecting keys via getConfig() is generally safe, but there are a few key precautions to take to minimize risk:
- Storage security: Any values saved to PropertiesService (whether from
getConfig()orsetCredentials()) are encrypted at rest by Google, and only your connector's script can access them. So from a storage standpoint, there's no inherent security difference between the two methods. - Input privacy: Make sure to set the
API_SECRETfield as a password input type in your config. UsesetInputType(InputType.PASSWORD)so users don't see plaintext while typing—this prevents shoulder-surfing risks and keeps the secret hidden in the UI. - Avoid accidental exposure: Never log the API_KEY or API_SECRET in your script's logs (even for debugging). Logs in Google Apps Script are accessible to anyone with access to the script, so this is a critical leak point to avoid.
- Transmission safety: Data Studio handles the transfer of user input from the UI to your script over HTTPS, so you don't have to worry about interception during that step.
2. getConfig() vs setCredentials(): Are they really interchangeable?
You're correct that both methods end up storing data in PropertiesService, but there are subtle differences in how Data Studio treats them:
- Workflow purpose:
setCredentials()is built specifically for official authentication flows (like OAuth2 or username/password). Since you're usingNONEauth, this method won't even be triggered—so you have no choice but to usegetConfig()to collect the keys. - User experience: Config fields from
getConfig()are part of the connector's initial setup flow, while credentials fromsetCredentials()get a dedicated "Manage Credentials" section. For your use case, keeping both keys in the setup flow makes sense, as users will expect to input them together. - Validation flexibility: In
getConfig(), you can add a validation function to check if the provided keys work before saving. For example, make a test API call with the keys and return an error if authentication fails—this gives users immediate feedback instead of letting them hit errors later when fetching data.
Recommended Best Practices
To make your implementation as robust and secure as possible:
- Mark both fields as required with
setIsRequired(true)to ensure users can't skip them. - Use
InputType.PASSWORDfor the API_SECRET to hide input text. - Add validation in
getConfig()to verify the keys are valid (e.g., call a lightweight API endpoint that checks authentication). - Store the keys in
UserProperties(notScriptProperties) so each user's credentials are isolated from others. - When making API requests, retrieve the keys from
UserPropertiesand inject them into your request headers/parameters securely—never hardcode or log them.
内容的提问来源于stack exchange,提问作者przemoo83
相关产品推荐
相关产品推荐

