We Want to Hear From You! What Do You Want to See on the Community? Tell us here!

Forum Discussion

EpeeFencer's avatar
EpeeFencer
New member | Level 2
5 years ago

Restrict a Connected App to Just One Folder

I have several connected apps to my Dropbox account.  Several of them are restricted to view/edit specific folders that are related to them.  Others are allowed to view all of my Dropbox folders. 

 

When I connected the apps, I just clicked "allow access to Dropbox".

 

How can I restrict those connected apps with full access to my folders to the only folder to which they need access?  I don't want the apps to see/edit/delete files that are not any of their business.

8 Replies

  • Mark's avatar
    Mark
    Icon for Super User II rankSuper User II
    5 years ago

    I'm afraid you cant - its the developers of the app who set which restrictions they want to use and then you have to simply agree or disagree with it.

  • Rich's avatar
    Rich
    Icon for Super User II rankSuper User II
    5 years ago

    EpeeFencer wrote:

    How can I restrict those connected apps with full access to my folders to the only folder to which they need access?


    You can't. This is a choice made by the developer when they create their app. The developer chooses either App Folder access or Full Dropbox access, depending on what their app needs. You as a user can either agree to that access when connecting the app to your account, or choose not to use the app.

  • EpeeFencer's avatar
    EpeeFencer
    New member | Level 2
    5 years ago

    I understand that the amount of Dropbox access is determined by the connected app developer.  For many connected apps it is an all-or-nothing access decision.

     

    However, for security, it would be great if Dropbox could allow its users to modify which folders a connected app can access, from full access to specific folder(s)/subfolder(s) access.

     

    Are there any Dropbox developers online?  Should I contact support to suggest this important security modification?

  • EpeeFencer's avatar
    EpeeFencer
    New member | Level 2
    5 years ago

    Thank you, Mark.  I've voted for restricting connected apps to a specific folder.

     

    However, with only 798 votes, it is unlikely to be addressed.  And I think it is an important security issue that should be brought to the top of the list.  It should not be the prerogative of the connected app developer whether they can access all files in someone's Dropbox.

  • tedfranklin's avatar
    tedfranklin
    New member | Level 2
    3 years ago

    I imagine the 768 people who voted for this know about 100x as much about security as the users who are unaware of the problem.  I spent two hours researching this because I simply couldn't believe that Dropbox had not addressed this. Dropbox may want to keep things simple for users and developers but this absolutely needs to be fixed.  Dropbox is one popular but poorly designed app away from a major security scandal. With all the warnings posted here about the risk this poses to users, the legal liability could be serious.

  • Synaesthete's avatar
    Synaesthete
    New member | Level 2
    3 years ago

    I agree and feel this should be escalated, but don't understand the proper channels for doing so. This is critical.

  • WaltG's avatar
    WaltG
    New member | Level 2
    2 years ago

    This is idiotic.  It would be super simple to have either a folder/file list in the connected apps settings, or an ability to add connected apps at the folder/file sharing settings.  If I want some company out of god-knows-where to drop files in a folder through their app, why would I give them access to all my data in Dropbox?  I guess the workaround is to create a 2nd free account for a particular app, doesn't seem efficient.

About Integrations

Find solutions to issues with third-party integrations from the Dropbox Community. Share advice and help members with their integration questions.

Need More Support

The Dropbox Community team is active from Monday to Friday. We try to respond to you as soon as we can, usually within 2 hours.

If you need more help you can view your support options (expected response time for an email or ticket is 24 hours), or contact us on X or Facebook.

For more info on available support options for your Dropbox plan, see this article.

If you found the answer to your question in this Community thread, please 'like' the post to say thanks and to let us know it was useful!