Skip to content

docs(google-drive): rewrite the Google Drive connector pages - #482

Open
raunakab wants to merge 1 commit into
mainfrom
docs/google-drive-connector
Open

raunakab wants to merge 1 commit into
mainfrom
docs/google-drive-connector

Conversation

@raunakab

Copy link
Copy Markdown
Contributor

Summary

Rewrites the three Google Drive pages in the shape of the Salesforce (#474), Teams (#470), and Gong (#479) pages, plus one line on the connectors overview. Grounded in the connector code (backend/onyx/connectors/google_drive/, google_utils/) and the permission sync package (backend/ee/onyx/external_permissions/google_drive/), and in Google's current console docs.

  • google_drive/overview.mdx: cards for the two auth methods; what gets indexed per file type and what is not; the four scopes; the connector form, with a table of how each General option differs between a service account and OAuth; run behavior; an Auto Sync Permissions section with a table of what each Drive sharing type maps to and the limits; a troubleshooting table keyed to the connector's error strings.
  • google_drive/service_account.mdx: current console labels, the service account key org policy note, domain-wide delegation via Security → API controls, the primary admin requirements as their own section, and the Onyx dialog's actual labels (Option 2: Service account, Primary Admin Email).
  • google_drive/oauth.mdx: rewritten for the Google Auth Platform layout (Branding, Data Access, Audience, Clients), Internal vs External audiences, the seven-day test-user expiry, and the exact redirect URI from google_kv.py. States plainly that OAuth only mirrors what the signed-in account can see.
  • connectors/overview.mdx: the permission sync list no longer implies admin OAuth is equivalent to a service account.

Deliberate changes to what the pages ask for:

  • Three APIs, not four. The connector exports Sheets as CSV through the Drive API and never calls the Sheets API (doc_conversion.py:234-238, 405-412). Drive, Admin SDK, and Docs remain; Docs is what heading-aware splitting uses (section_extraction.py:88-117).
  • No JavaScript origins. The sign-in is a server-side code exchange against /admin/connectors/google-drive/auth/callback, so only the redirect URI matters.
  • Dropped the founders email, the named Slack contacts, and the suggestion to put a founders address on the consent screen.

Three code-derived facts a reviewer may want to sanity check:

  • Nested Google Groups are not expanded during group sync; members are fetched as emails only (group_sync.py:393, 418), so a nested group's members inherit nothing.
  • An "anyone with the link" share makes a file public unconditionally (doc_sync.py:258), but a link-only "anyone" share on a folder does not (doc_sync.py:358). The page documents the file behavior; the folder asymmetry looks unintended and may be worth an engineering look.
  • When Google refuses to list a file's sharing settings, usually for a file owned outside the Workspace, only the user Onyx found it through can see it (doc_sync.py:195-207).

Not done: the instance-default OAuth app env vars (OAUTH_GOOGLE_DRIVE_CLIENT_ID/_SECRET) back a separate enterprise sign-in flow with its own callback path (ee/onyx/server/oauth/google_drive.py) that I did not trace, so they are not documented here. The two Onyx credential dialog screenshots still carry the July TODO to be re-shot, and the OAuth client screenshots predate the Google Auth Platform layout. No image was renamed, since three are shared with the Gmail pages.

Test plan

  • scripts/format_docs.py --check passes.
  • mint broken-links reports no broken links.
  • git diff --check is clean.
  • All three pages render in the local Mintlify preview.

🤖 Generated with Claude Code

The overview said little beyond a file-type list, the OAuth page still
followed the old console layout and pointed readers at a founders email,
and nothing explained the connector form, permission sync, or the
connector's own errors. Rewrite all three pages in the shape of the
Salesforce and Teams pages: what is and is not indexed, the four scopes,
the General and Specific options and how they differ by credential type,
run behavior, an Auto Sync Permissions section with the mapping of each
Drive sharing type, and a troubleshooting table keyed to error strings.

The auth pages follow the current Google Cloud console (Google Auth
Platform) and Admin console paths. They list three APIs instead of four,
since the connector exports Sheets through the Drive API and never calls
the Sheets API, and they drop the JavaScript origins, since the sign-in is
a server-side code exchange that only needs the redirect URI.

The connectors overview no longer implies that admin OAuth is equivalent
to a service account for permission sync: with OAuth the user list is the
signed-in account alone, so group sync sees far less.
@mintlify

mintlify Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

Preview deployment for your docs. Learn more about Mintlify Previews.

Project Status Preview Updated
onyx 🟢 Ready View Preview Sep 23, 2026, 4:59 AM

💡 Tip: Enable Automations to automatically generate PRs for you.

This branch was successfully deployed

1 active deployment
staging — be1e1387 Deployed Sep 23, 2026 by mintlify[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants