Похожие чаты

Hey Currently using googles cloud vision api in an electron app. The

docs tell me to create a service account, and that this service account needs appropriate permissions to access the api. Then tells you to give it the owner role (wtf?!!)
It also recommends to then limit the permissions later. But doesn't tell you how and just links to the general IAM docs (thanks)

But when i create a service account with no permissions at all, it can access the cloud vision api just fine. In fact, there is no role at all that related to cloud vision api. So despite the docs saying you have to set permissions, this is totally untrue.

Because of that I don't know if it would be save to ship the key file with the application. All i want that service account to be able to access is the cloud vision api ,which is literally the only thing this gcp project has enabled. But I'm not sure what resources such a service account can access by default, because the docs are clearly lying. Is it safe to embed the key file? Or do I actually have to build a fuckin proxy just So this key can stay safe. Oauth is not an Option and an api key is definitely insecure so not doing that

2 ответов

24 просмотра

Oh man it's one of the great mysteries of humanity. I've never seen anyone who managed to use the official Google API. That is, without the help of a third-party lib because it's just too bureaucratic and the authentication process is badly documented in my option. I wonder if that's a way they found to push for Google Apps Scripts.

palone- Автор вопроса
Pedro Aguiar
Oh man it's one of the great mysteries of humanity...

The wrappers I've seen wanted me to use either oauth (which i can't due to business requirements) or an service account keyfile

Похожие вопросы

Обсуждают сегодня

а через ESC-код ?
Alexey Kulakov
29
30500 за редактор? )
Владимир
47
Чёт не понял, я ж правильной функцией воспользовался чтобы вывести отладочную информацию? но что-то она не ловится
notme
18
У меня есть функция где происходит это: write_bit(buffer, 1); write_bit(buffer, 0); write_bit(buffer, 1); write_bit(buffer, 1); write_bit(buffer, 1); w...
~
13
any reference of this implementation?
BitBuddha
29
Ⓐrtto, [4/23/24 7:02 PM] Please explain more fully how it is not working exactly, and what are the steps you are taking, and what error messages come or what happens. Ⓐrtto, ...
Ezza Kezza
2
sounds like people have lost their kaspa on tradeogre... does this mean tradeogre not trustworthy?
Ezza Kezza
15
Страшнейшая правда про списки ЦБ. С первых дней жизни P2P сферы, молодые человеки, начитавшись законодательной базы и "внутренних" документов, решили, что им противостоит сер...
Foxcool
3
Недавно Google Project Zero нашёл багу в SQLite с помощью LLM, о чём достаточно было шумно в определённых интернетах, которые сопровождались рассказами, что скоро всех "ибешни...
Alex Sherbakov
5
So much speculation in the last week. So much volatility in price. This is because Hedera has a GC that isn't using the network it's governing. Why aren't people asking why a...
Summit Seeker R
9
Карта сайта