Repository navigation
Conversation
The overview said little beyond a file-type list, the OAuth page still followed the old console layout and pointed readers at a founders email, and nothing explained the connector form, permission sync, or the connector's own errors. Rewrite all three pages in the shape of the Salesforce and Teams pages: what is and is not indexed, the four scopes, the General and Specific options and how they differ by credential type, run behavior, an Auto Sync Permissions section with the mapping of each Drive sharing type, and a troubleshooting table keyed to error strings. The auth pages follow the current Google Cloud console (Google Auth Platform) and Admin console paths. They list three APIs instead of four, since the connector exports Sheets through the Drive API and never calls the Sheets API, and they drop the JavaScript origins, since the sign-in is a server-side code exchange that only needs the redirect URI. The connectors overview no longer implies that admin OAuth is equivalent to a service account for permission sync: with OAuth the user list is the signed-in account alone, so group sync sees far less.
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
justin-tahara
approved these changes
Sep 23, 2026
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Rewrites the three Google Drive pages in the shape of the Salesforce (#474), Teams (#470), and Gong (#479) pages, plus one line on the connectors overview. Grounded in the connector code (
backend/onyx/connectors/google_drive/,google_utils/) and the permission sync package (backend/ee/onyx/external_permissions/google_drive/), and in Google's current console docs.google_drive/overview.mdx: cards for the two auth methods; what gets indexed per file type and what is not; the four scopes; the connector form, with a table of how each General option differs between a service account and OAuth; run behavior; an Auto Sync Permissions section with a table of what each Drive sharing type maps to and the limits; a troubleshooting table keyed to the connector's error strings.google_drive/service_account.mdx: current console labels, the service account key org policy note, domain-wide delegation via Security → API controls, the primary admin requirements as their own section, and the Onyx dialog's actual labels (Option 2: Service account, Primary Admin Email).google_drive/oauth.mdx: rewritten for the Google Auth Platform layout (Branding, Data Access, Audience, Clients), Internal vs External audiences, the seven-day test-user expiry, and the exact redirect URI fromgoogle_kv.py. States plainly that OAuth only mirrors what the signed-in account can see.connectors/overview.mdx: the permission sync list no longer implies admin OAuth is equivalent to a service account.Deliberate changes to what the pages ask for:
doc_conversion.py:234-238, 405-412). Drive, Admin SDK, and Docs remain; Docs is what heading-aware splitting uses (section_extraction.py:88-117)./admin/connectors/google-drive/auth/callback, so only the redirect URI matters.Three code-derived facts a reviewer may want to sanity check:
group_sync.py:393, 418), so a nested group's members inherit nothing.doc_sync.py:258), but a link-only "anyone" share on a folder does not (doc_sync.py:358). The page documents the file behavior; the folder asymmetry looks unintended and may be worth an engineering look.doc_sync.py:195-207).Not done: the instance-default OAuth app env vars (
OAUTH_GOOGLE_DRIVE_CLIENT_ID/_SECRET) back a separate enterprise sign-in flow with its own callback path (ee/onyx/server/oauth/google_drive.py) that I did not trace, so they are not documented here. The two Onyx credential dialog screenshots still carry the July TODO to be re-shot, and the OAuth client screenshots predate the Google Auth Platform layout. No image was renamed, since three are shared with the Gmail pages.Test plan
scripts/format_docs.py --checkpasses.mint broken-linksreports no broken links.git diff --checkis clean.🤖 Generated with Claude Code