Repository navigation
options.public to storage/File.createWriteStream doesn't make uploaded files public #1566
Description
Activity
Setting
public: truewill set the object'spredefinedAcltopublicRead. Callingfile.makePublic()will grant theREADERrole toallUsers. Do you have any existing rules that might be trumping thepredefinedAcl?To test, I created a new bucket and new file, so that no existing configuration could get in the way.
- addedapi: storageIssues related to the Cloud Storage API.Issues related to the Cloud Storage API.
on Sep 6, 2016 @stephenplusplus So, the only issue here should be an existing rule trumping
predefinedAcl? Am not aware of having any such rule, but I'll look.@stephenplusplus How did you add the
allusers: Readerbit? Does this correspond topredefinedAcl: publicRead?Reacted by Michael PrenticeYes, that came from setting
predefinedAcl: publicRead.@jgeewax, am I giving out correct information?
@stephenplusplus OK, so that should mean that
predefinedAcl: publicReadis equivalent to callingfile.makePublic()does it not? I end up with the same in my file permissions, by callingfile.makePublic().Reacted by Michael PrenticeWe saw this same issue lately as well. We used the CLI (since the UI didn't have this feature) to change the
predefinedAclon the whole bucket since we didn't want to callfile.makePublic()on every file.It would be ideal if the option worked as expected and make the file public.
@stephenplusplus Come to think of it, how would you write a test for this issue? Apparently it's not solved, so seems as if you lack a test for this functionality.
We do: https://github.com/GoogleCloudPlatform/google-cloud-node/blob/35573c31e834c841b99ae73f6cf5e647b76ae7cc/packages/storage/system-test/storage.js#L424 -- but if we're not doing it the right way, we'll need to rewrite the test.
Reacted by Arve Knudsen@stephenplusplus I guess there's some sort of false positive there, looks that way at least.
Indeed, looking forward to fixing this :)
@stephenplusplus When you upload an object, you can specify either a predefined ACL or a fully-enumerated ACL, and you get errors if you have both. If you don't want to bother writing client logic, you could just always turn
public: trueto the predefined ACL but then also use whatever client-provided ACL and let the service return the error that you cannot cross the streams. Seems like a bad idea to have the client specify one ACL that doesn't set it to public read and another in the same request that does. Or perhaps I'm misunderstanding and there's no additional user-provided ACL?We're not really running into conflicting ACL specifications during the upload here. In the simplest case, a user might want to upload a file and make it public in one line, and it would look like this:
bucket.upload('./localfile.txt', { public: true }, function(err) {})
That would send
POST https://.../o?name=localfile.txt&predefinedAcl=publicRead.Is this what our library should do, or is there more to it?
I presume there's no body to the
POSTifresumableand it also contains anuploadTypeURL parameter that's eithermediaorresumable? If so, then, that's exactly what it should do. Does the ACL you get back from such an object not listallUsers: READER?1 remaining item
It seems like we're doing this right as far as the API is concerned. If I'm missing something, we'll re-open and get back to work. Thanks!
Sorry, I ran out of bandwidth to debug this and then Hurricane Matthew hit. We were able to work around it for now. Thanks.
- added a commit that references this issue
on Feb 3, 2026 - added a commit that references this issue
on Feb 25, 2026 - added a commit that references this issue
on Mar 17, 2026 - added a commit that references this issue
on Mar 18, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on Mar 27, 2026




According to API docs,
storage/File.createWriteStreamshould take a boolean optionpublicthat makes the uploaded file publicly readable. However, in my experience this isn't the case.I create the stream like this:
And still, I have to call
cloudFile.makePublicafter the upload has finished, because otherwise the file is only accessible to the owner:Environment details