I'm wondering why the information necessary for downloading the file can't just be encoded as a URL parameter.
When the user clicks a file download link it should be possible to generate a short lived token that authenticates the user against googleusercontent.com.
When the user clicks a file download link it should be possible to generate a short lived token that authenticates the user against googleusercontent.com.