Skip to content

Not access data from Google Play #651

Description

@beshkenadze

When requesting files from the bucket "pubsite_prod_rev_ххххх" answer is always "Forbidden" (status code 403).
Example code:

var gcloud = require('gcloud');
var storage = gcloud.storage({
    projectId: '1xxxxxxxx',
    keyFilename: './json_api_key.json'
});

var bucket = storage.bucket("pubsite_prod_rev_1xxxxxxxxx");

bucket.getFiles({
    prefix: "reviews"
}, function (err, files, nextQuery, apiResponse) {
    if (nextQuery) {
        // nextQuery will be non-null if there are more results.
        bucket.getFiles(nextQuery, function (err, files, nextQ, apiResponse) {
        });
    }
    if(files == null) { // always Forbidden
        console.log(err.message); 
    }else{
        console.log(files);
    }
});

Activity

  1. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    Is that bucket owned by you? If so, are you sure that particular service account (specified in keyFilename) has access to the bucket?

  2. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    Yep, the bucket and the app owned by one account.
    Using gsutil everything works as expected.

  3. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    Hmm. Are you able to list buckets ?

    var gcloud = require('gcloud');
    var storage = gcloud.storage({
        projectId: '1xxxxxxxx',
        keyFilename: './json_api_key.json'
    });
    
    storage.getBuckets(function(err, buckets, next) {
      console.log('Buckets were: ', buckets);
    });
  4. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    The list is empty, the response status of 200.

    {
      response: {
        debugId: 1,
        headers: {
          expires: 'Wed, 10 Jun 2015 13:28:33 GMT',
          date: 'Wed, 10 Jun 2015 13:28:33 GMT',
          'cache-control': 'private, max-age=0, must-revalidate, no-transform',
          vary: 'Origin, X-Origin',
          'content-type': 'application/json; charset=UTF-8',
          'x-content-type-options': 'nosniff',
          'x-frame-options': 'SAMEORIGIN',
          'x-xss-protection': '1; mode=block',
          'content-length': '31',
          server: 'GSE',
          'alternate-protocol': '443:quic,p=1',
          connection: 'close'
        },
        statusCode: 200,
        body: '{\n "kind": "storage#buckets"\n}\n'
      }
    }

    btw, APIs Explorer (https://cloud.google.com/storage/docs/json_api/v1/buckets/list) shows the same response, the request (https://cloud.google.com/storage/docs/json_api/v1/objects/list) generates a list of files.

  5. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    This really seems like an access problem for that specific service account... You're 100% certain that the project ID is correct (and owns that bucket)? And that the service account is in that project?

    What happens if you run gcloud auth login locally and comment out the keyFilename property? (This tells gcloud-node to pull credentials from whatever the cloud SDK is using.)

  6. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    After using the command "gcloud auth login" and comment out the keyFilename property, request responded with 200 status and brought the list of files.

    It turns out that is not authenticated through a "service_account".

    I doubled checked and even created another json key, but still won't work.

  7. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    Gotcha. Do you see the service account in the list on the permissions page? (https://console.developers.google.com/project/_/permissions)

  8. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    Of course.
    2015-06-10 at 17 30 2x

  9. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    Err, that should probably look more like:

    perms

  10. jgeewax commented on Jun 10, 2015

    @jgeewax
    Contributor

    I just ran a quick test to double check this:

    1. Create a bucket
    2. Upload a file to that bucket
    3. Create a new set of credentials (service account, with JSON keyfile)
    4. Check whether the new credentials could see the bucket listing

    The hope was to see if there was some bug on Google's side where maybe they weren't granting access to the bucket if you created the credentials after the fact.

    It looks like this did exactly what it was supposed to do: I was able to see the bucket listing using the service account.

    Any other info you can provide to help us track down whether this was a bug or not would be super useful... but I'm out of ideas (outside of simple mistakes like using the wrong .json file).

  11. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    Oh, I have a new version of the console.
    Here is the correct screenshot:
    2015-06-10 at 18 19 2x

  12. beshkenadze commented on Jun 10, 2015

    @beshkenadze
    Author

    We don't have account in Google Cloud Storage and we can't create a bucket :(
    We have another account for a android application.

  13. ryanseys commented on Jun 10, 2015

    @ryanseys
    Contributor

    This is weird. Just throwing out a couple ideas:

    1. The project id is different than the project number. Typically it starts with a letter, so it's strange yours starts with a number unless you changed it. For example purple-spaceman-123 is a good example of what a default project id looks like.
    2. Try going to https://console.developers.google.com/project/{{projectID}}/apiui/credential

    You should see a screen like:

    image

    Click the "Generate new JSON key" button and set keyFilename to point to that file. The file should contain the line: "type": "service_account".

    We don't have account in Google Cloud Storage and we can't create a bucket :(

    What do you mean you don't have an account in Google Cloud Storage? There is no such thing as a Google Cloud Storage account. There are Google accounts and Google Service Accounts. With those two things, and the right credentials, you should be all set to use this library.

  14. ryanseys commented on Jun 10, 2015

    @ryanseys
    Contributor

    FWIW Cloud Storage did see a blip of 500's yesterday on https://status.cloud.google.com/ but, despite the overall vague-ness of the status report, it seems unrelated to the issue presented here.

  15. 57 remaining items

  16. added a commit that references this issue on Feb 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

api: storageIssues related to the Cloud Storage API.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions