Repository navigation
File Acl permissions #804
Description
Activity
- addedapi: storageIssues related to the Cloud Storage API.Issues related to the Cloud Storage API.type: questionRequest for information or clarification. Not an issue.Request for information or clarification. Not an issue.
on Aug 17, 2015 There is, though it's a little more wordy than our API is usually:
file.createWriteStream({ metadata: { acl: [ { entity: 'allUsers', role: gcloud.storage.acl.READER_ROLE } ] } });
I'm struggling to think of a clean way to make that easier, but if you have any ideas, we will gladly try to accommodate!
I have tried that, but the file gets uploaded and no permissions are set. Here is my modified code
fs.createReadStream('test.png') .pipe(file.createWriteStream({ metadata:{ acl:[ { entity:'allUsers', role:gcs.acl.READER_ROLE } ] } } )) .on('error', function(err) { done(); }) .on('complete', function(metadata) { done(); });am i missing something
I don't think so, that looks right to me. Can you paste what
metadatareturns in the complete callback?Also, what version of gcloud are you running?
{ kind: 'storage#object', id: 'xxxx/temp/test.png/1439816836081000', selfLink: 'https://www.googleapis.com/storage/v1/b/xxxx/o/temp%2Ftest.png', name: 'temp/test.png', bucket: 'xxxx', generation: '1439816836081000', metageneration: '1', contentType: 'image/png', updated: '2015-08-17T13:07:16.080Z', storageClass: 'STANDARD', size: '53844', md5Hash: 'zAp5LEFzw2l', mediaLink: 'https://www.googleapis.com/download/storage/v1/b/xxx/o/temp%2Ftest.png?generation=1439816836081000&alt=media', acl: [ { kind: 'storage#objectAccessControl', id: 'xxx/temp/test.png/1439816836081000/allUsers', selfLink: 'https://www.googleapis.com/storage/v1/b/xxxx/o/temp%2Ftest.png/acl/allUsers', bucket: 'xxxx', object: 'temp/test.png', generation: '1439816836081000', entity: 'allUsers', role: 'READER', etag: 'COjKEAE=' }, { kind: 'storage#objectAccessControl', id: 'xxx/temp/test.png/1439816836081000/user-00b4903770f8e313045586eab55', selfLink: 'https://www.googleapis.com/storage/v1/b/xxxx/o/temp%2Ftest.png/acl/user-00b4903770f8e313045586eab55', bucket: 'xxx', object: 'temp/test.png', generation: '1439816836081000', entity: 'user-00b4903770f8e313045586eab55', role: 'OWNER', entityId: '00b4903770f8e313045586eab55', etag: 'COjKudiXsMcCEAE=' } ], owner: { entity: 'user-00b4903770f8e313045586eab55', entityId: '00b4903770f8e313045586eab55' }, crc32c: 'LOOQ==', etag: 'COjcCEAE=' }Am using version 0.18.0
It looks like the right permissions were added:
metadata.acl[0] = { // ... entity: 'allUsers', role: 'READER' }
How are you verifying the file is not being given the right permissions?
I was accessing it using the console.developers.google.com UI, and i cant set any permissions using it
am gettingPlease include at least one owner's permissionHowever i have tested the actual url and its accessible to the public.
@jgeewax I think you're the resident expert at ACLs. Is there any reason a file would say it uploaded would have this metadata, but then list nothing (see above screenshot)?
Anyone with leads on this issue?
Hmm weird. Is it possible that somehow we're overriding the owner (which should be the service account that uploaded the object) which leads to a weird situation in the UI?
How can I test this case
18 remaining items
- added a commit that references this issue
on Jan 28, 2026 - added a commit that references this issue
on Jan 28, 2026 - added a commit that references this issue
on Feb 17, 2026 - added a commit that references this issue
on Feb 25, 2026 - added a commit that references this issue
on Mar 18, 2026 - added a commit that references this issue
on Mar 27, 2026 - added a commit that references this issue
on May 5, 2026




Is it possible to add permissions (allUsers:readers) to a file during uploading