Skip to content

Document Workspace add-on deployment takeover - #380

Open
carlospolop wants to merge 1 commit into
mainfrom
codex/gcp-workspace-addon-takeover-20260908
Open

Document Workspace add-on deployment takeover#380
carlospolop wants to merge 1 commit into
mainfrom
codex/gcp-workspace-addon-takeover-20260908

Conversation

@carlospolop

Copy link
Copy Markdown
Collaborator

Summary

  • document the live-tested gsuiteaddons.deployments.update HTTP endpoint takeover boundary
  • explain the conditional per-user Workspace OAuth-token impact without claiming an OAuth-consent or tenant-wide bypass
  • add permission-denied enumeration fallbacks, detection, and hardening guidance
  • correct the previous universal claim that Workspace groups are freely joinable

Validation

  • exact-permission custom role: deployment GET/LIST returned 403, full replacement PUT returned 200
  • project testIamPermissions returned only gsuiteaddons.deployments.update
  • cross-organization development installation failed as documented
  • all referenced official URLs return HTTP 200
  • git diff --check passes

No production resources or user content were accessed; all disposable GCP/Workspace lab resources were removed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant