Manage API Client Access for internal applications - scope not restricted?

73 views
Skip to first unread message

Charles Cooke

unread,
Sep 1, 2011, 8:12:58 AM9/1/11
to google-app...@googlegroups.com
We are using 3-legged OAuth for our internal application.  We would like to manage the scope as discussed here (http://www.google.com/support/a/bin/answer.py?answer=162106).  However, it seems that no matter what scope we use in the 'One or More API Scopes' section, the authenticating application always has full access to all APIs and scopes.

I understand that the section is titled 'Manage third party OAuth Client access'.  Does this mean that internal applications authenticating with OAuth will always have full access?

Shraddha Gupta

unread,
Sep 1, 2011, 1:20:37 PM9/1/11
to google-app...@googlegroups.com
It seems that you have 'Two-legged oauth access control' enabled for all APIs in the section "Manage Oauth Domain Key". That is overriding the limited scopes specified  in the section  titled 'Manage third party OAuth Client access'.
Uncheck the 'Two-legged oauth access control', to limit the access to APIs.
Reply all
Reply to author
Forward
0 new messages