Google Apps Script无法正确统计Team Drive文件的查看权限用户数
Let's walk through the most likely reasons your script is returning 0 viewers when you know they exist, along with actionable fixes:
1. You're checking the wrong permission role name
Google Drive's API uses specific role identifiers for Shared Drives, and it's easy to mix them up. For view-only access, the role is reader, not viewer (that's a super common gotcha!). If your script is filtering for role == "viewer", it'll never match actual view-only users.
Fix:
Update your role check to target reader instead. Here's a Python snippet example using the Google Drive API:
from googleapiclient.discovery import build # Initialize your Drive service with valid credentials service = build('drive', 'v3', credentials=creds) # Fetch permissions for the file (critical flags for Shared Drives included) permissions = service.permissions().list( fileId='YOUR_TARGET_FILE_ID', supportsAllDrives=True ).execute() viewer_count = 0 for perm in permissions.get('permissions', []): # Check for the correct reader role and user type if perm['role'] == 'reader' and perm['type'] == 'user': viewer_count += 1 print(f"Total view-only users: {viewer_count}")
2. You're missing inherited permissions
By default, the permissions.list call only returns direct permissions assigned directly to the file. But in Shared Drives, many users get access via inherited permissions (from the parent folder or the entire Shared Drive itself). These inherited permissions won't show up in the default response.
Fix:
Add the includeInheritedPermissions=True parameter to your API call to capture these indirect access rights:
permissions = service.permissions().list( fileId='YOUR_TARGET_FILE_ID', supportsAllDrives=True, includeInheritedPermissions=True # Pull in access from parent folders/Drive ).execute()
Now you'll count users who got view access through the Drive structure, not just direct file assignments.
3. You're ignoring group/domain permissions
If some view-only access is granted to a Google Group or an entire domain, your script might be only checking type == 'user' and missing these. Members of those groups/domains with view access won't be counted unless you resolve the group membership.
Fix:
- First, flag group/domain permissions with the
readerrole - If you have G Suite/Workspace admin access, use the Admin SDK to fetch group members and add them to your count. For domain-wide access, you may need additional checks based on your organization's setup.
Example snippet to detect group permissions:
for perm in permissions.get('permissions', []): if perm['role'] == 'reader': if perm['type'] == 'user': viewer_count += 1 elif perm['type'] == 'group': # Uncomment below if you have Admin SDK access to fetch group members # group_members = admin_service.members().list(groupKey=perm['email']).execute() # viewer_count += len(group_members.get('members', [])) print(f"Found view-only group (members not counted yet): {perm['email']}")
4. Your API request is missing critical Shared Drive flags
Shared Drives require specific parameters in API calls to function correctly. If you don't include supportsAllDrives=True, the API might silently fail to return permissions for Shared Drive files, leading to an empty results list.
Fix:
Double-check that every permissions.list call includes supportsAllDrives=True (as shown in earlier examples). Also, confirm your OAuth credentials have the correct scopes—you'll need at minimum https://www.googleapis.com/auth/drive.readonly to access permission data.
Final Debugging Tip
If you're still stuck, print out all unfiltered permissions returned by the API. This will let you see exactly what roles and types are being returned, helping you spot any gaps in your filtering logic.
内容的提问来源于stack exchange,提问作者Manuel

