This is how you set up your Google Drive as a target for your backups. You do not enter a password: you sign in at Google, give your consent there and come back to the “Targets” page.
What you need
- a Google account with enough free space for your backups,
- a website whose admin area can be reached via https://,
- the PHP extension cURL with https on the web server.
If the web server lacks cURL, Google Drive is greyed out in the selection of the target types and carries the label Not available on this server.
Step 1: Choose the target type
Open the Targets page and click Add target. Choose Google Drive.
- Name is up to you. The plugin suggests “Google Drive 1”; any name that is not in use yet works.
- The note on the sign-in says that you will be redirected to Google and come back to this page afterwards, and that the service auth.cloneworx.de brokers the sign-in.
- The note of the target type says what the plugin sees in your Google Drive and in which folder the backups end up.
- Connect with Google starts the sign-in.
The form has no field for a password and no button Test connection: a target of the type Google Drive only comes into being with the sign-in.
Step 2: Connect with Google
Click Connect with Google. Your browser leaves the Targets page:
- At Google, choose your account and give your consent. If the consent page of Google shows a checkbox for the access to the files, tick it.
- After that, the service auth.cloneworx.de shows a page that names the website to which the access is handed over. Only continue if that is your website.
- Your browser comes back to the Targets page. There it briefly says Finishing the sign-in …
The plugin saves the target, tests the connection at once and reports the result: “…” saved and connected. You do not have to save any more.
- All targets are connected.
- The message names the target: saved and connected.
- The new target is in the list. The green dot means: connected.
- The location of the target is the address of the connected Google account and the folder in Google Drive.
A sign-in that has been started is valid for 15 minutes. Plans and backups use a target only after a successful connection test.
If the plugin finds backups in Google Drive that are not in your list, the tile Backups found at “…” appears. More about this: Find backups again after a total loss.
Step 3: Choose the target in the backup plan
- Your first target: The plugin creates the plan “Daily backup”: daily at a random time, everything, this target, Max. backups 7. The plan is paused until you switch it on.
- Another target: Choose it on the Backup page in the tile Backup plans in a plan. The free version allows two plans and one target per plan.
More about this: Schedule backups automatically.
When the sign-in does not work
If you come back from Google without access, no target is created. The Targets page reports the reason, and the form opens again with your entries.
- The message says: Google reports that access was not granted. Nothing was connected.
- The form is open again, with your entries.
- Connect with Google starts the sign-in again.
| Message | What to do |
|---|---|
| Connecting needs https: the address of the admin area of this website does not begin with https. | The message is shown in the form before the browser leaves the page. The sign-in service hands over an access only to a website whose admin area can be reached via https://. Switch the website to https. |
| The sign-in was cancelled. Nothing was connected. | This is information, not an error. Click Connect with Google once more if you want to set up the target. |
| … reports that access was not granted. Nothing was connected. | Start the sign-in again and give your consent at Google. |
| You did not allow the access to your files: the box on the consent page of … was not ticked. Connect again and tick the box. | Start the sign-in again and tick the box on the consent page of Google. |
| This sign-in is unknown or has expired. Please connect again. | Here the form does not open again. Click Add target and start again. |
| The sign-in took too long or was already used. Please connect again. | Start the sign-in again. |
| The sign-in service cannot be reached at the moment. Please try again later. | Try again later. Below the message, Show log leads to the general log. |
| … cannot be reached at the moment or reports an error. Please try again later. | The message names Google. Try again later. Here too, Show log leads to the general log. |
| The sign-in worked, but the first access to the account failed: … | The reason follows the colon. Start the sign-in again once it is resolved. |
What the plugin may see in Google Drive
The plugin asks Google for a single permission: to see, create and delete the files and folders that it has created itself. Google calls this scope drive.file. The plugin does not see any other file in your Google Drive.
One consequence: the plugin does not see a folder that you created yourself in Google Drive either. If you enter its name, the plugin creates a second folder with the same name.
The sign-in service auth.cloneworx.de
Google gives an access only to an app that identifies itself with a secret. A secret cannot be in a plugin whose code anyone can read. That is why it lives with a small service by cloneworx, auth.cloneworx.de, which brokers the sign-in.
| Who sends | What the service learns |
|---|---|
| Your browser, after your click on Connect with Google | the address of the admin page of your website, a random value and the language |
| Your web server, after the return | the code of the sign-in. With it the service fetches the access at Google and passes it on in its response. |
| Your web server, as long as the target is in use | the stored permanent access, whenever a new access is needed: about once per hour |
In addition, as with every request, the IP addresses of browser and web server. The service stores nothing. It never receives a backup, never a file and never the address of your Google account. An access is never part of an address and is bound to the website that started the sign-in.
At the target two values are stored, encrypted like every password of a target: the permanent access and the access that is valid for about an hour. The address of the connected Google account is shown visibly at the target so that you can see where the backups go. It never appears in the log or in the support report.
The fields of the Extended view
- Folder in Google Drive is the folder in “My Drive” that receives the backups. The default is “cloneworx Backup”. The plugin creates the folder.
- Connection timeout (seconds) takes 3 to 60, the default is 10.
- Upload rate (bytes per second) may stay empty: then what the connection test measured applies. Based on it the plugin chooses the size of the sections of an upload.
The folder may have several levels, for example Backups/Website. The backups are stored in “My Drive” under <folder>/cloneworx-backup-<code>/<backup>/. Structure and files of a backup are the same as at any other target.
Editing and testing the target
In the row of the target, click More …, then Edit.
- Name is the name of the target in lists and messages.
- The connected account is the address of the Google account in which the backups are stored.
- Save saves your changes.
- Connect again with Google starts the sign-in for this target again.
- Test connection tests the connection.
The connection test writes a small file to Google Drive, reads it back and deletes it again. In addition it uploads a test file in two sections, asks Google in between how far the upload has got, measures the upload rate and compares the checksum. It deletes this file again as well.
- The result of the test: the connection works, a test file was written, read back and deleted.
- The upload method and the measured upload rate.
| Line in the result | Meaning |
|---|---|
| Connection works: a test file was written, read back and deleted. | Writing, reading back and deleting work. |
| Upload method: in sections (resumable upload); an upload continues where it stopped. | The plugin uploads every file in sections. An interrupted step costs only its time. |
| Measured upload rate: … per second. | Based on the rate the plugin chooses the size of the sections: so that a section and the response from Google fit into the rest of a step. |
Warnings after a successful test
Warnings are shown in yellow below the result. The target is usable nevertheless.
| Warning | Meaning |
|---|---|
| A folder at the target holds several entries with the same name. The oldest one counts. | See the section “Good to know”: names in Google Drive are not unique. |
| The consent is limited in time and ends on …. After that the target must be connected again. | Connect the target again after this day. |
| The service names no checksum for the file; after an upload only the size is checked. | After an upload the plugin compares the size, not the checksum. |
When the test fails
A failed test names the cause, for some causes the reason in more detail below it, and then the error message from Google in the line Message from the target: … The error message is not translated. The address of the Google account is replaced by <user> in it.
| Message | What to do |
|---|---|
| The target reports that there is no space left. | Free up space in your Google account and test again. |
|
The account refused the access. The provider no longer accepts the stored consent. Connect the target again. |
See the section “Disconnected and connecting again”. |
| The account does not allow this request. | Google refused the request, for example because of a rule of the account. The reason is named in the line Message from the target: … |
|
The sign-in service did not return a new access. The sign-in service cannot be reached. |
The plugin could not fetch a new access. Test again later. |
| The target asked for a pause: it is busy, or it received too many requests. | Google limits the number of requests. Test again later. In a backup the plugin itself waits as long as Google names, and then tries again. |
Disconnected and connecting again
Google no longer accepts a consent
- if you have withdrawn it in your Google account,
- if it has not been used for six months,
- if the same Google account has been connected with cloneworx Backup more than 100 times: then the oldest connection ends.
The plugin then marks the target as disconnected at once. Backups skip it until you connect it again.
- The status tile names the disconnected target, the cause and the next step.
- Connect again opens the form of the disconnected target.
- Disconnected is shown in the list at the target. The dot in front of it is yellow.
As the cause the status tile names: The provider no longer accepts the stored consent: it was withdrawn or has expired. Below it the next step is shown: Next step: connect “…” again. Until then, backups skip this target. Click Connect again.
- The connected account is the address of the Google account in which the backups are stored.
- The cause is shown in yellow, with the same wording as in the status tile: Google no longer accepts the stored consent.
- Connect again with Google starts the sign-in.
Click Connect again with Google and give your consent at Google as when setting up. The target, its name and its backups are kept.
The plugin replaces the two stored accesses at the website with the new ones. It revokes nothing at Google: the access the target had until then stays valid there. That also applies if you connect again a target that is not disconnected.
Good to know
Deleting is final
A backup that the plugin deletes in Google Drive does not go to the trash of Google Drive. It is gone.
- Names in Google Drive are not unique. A folder can hold two entries with the same name. The plugin then takes the oldest one, and the connection test warns. If you rename a folder of the plugin in Google Drive, the plugin still finds it. If you move it to another place, the plugin does not follow.
- Free space. Google names the free space of the account. If a backup does not fit in there, it skips this target and goes to the other targets of the plan. It ends “with warnings” and names the target, the space needed and the free space. If Google Drive is the only target, the job ends before it writes anything.
- Uploads. The plugin uploads a file in sections. A section is a multiple of 256 KiB. The plugin chooses its size based on the measured upload rate so that the section and the response from Google fit into the rest of a step. A step that has already done work does not start another request to Google when less than 6 seconds are left: the next step continues with its full time. Every step first asks Google how far the upload has got.
- The finished file. A file appears in Google Drive only with its last section, in one go. After that the plugin compares size and checksum at Google with the local file.
- A connection that is too slow. If a section does not arrive even after repeated attempts before the time of a step has run out, the plugin reports: An upload did not arrive before the time of a step ran out: the connection to the target is too slow for it. Below it the reason is named: This service takes an upload only in sections of at least 256 KiB, and such a section has to arrive within one step.
- A folder is removed by the plugin only if Google lists it as empty.
- No download through the plugin. Backups that are stored only in Google Drive you fetch in Google Drive. Restore, check and finding backups read directly from Google Drive.
- Removing the target deletes both accesses from the database of the website. The plugin revokes nothing at Google, not even when you delete the plugin: the access the target had stays valid there. The consent itself stays listed in your Google account, in the Security area under third-party apps and services, until you remove it there. Whoever removes it there disconnects every website that is connected with this Google account.
- The plugin also uses a proxy from the
wp-config.phpfor this target type. It never follows a redirect. - Below the selection of the target types the note reads: Names and logos of third parties are the property of their respective owners. This does not imply any affiliation or partnership.
See also
- Which target suits you?
- The “Targets” page
- Renew the credentials of a target
- Remove a target
- Store backups in Dropbox
- Uninstall the plugin
On the command line
WP-CLI not set up yet? How to install WP-CLI.
You create a target of the type Google Drive in the browser, on the Targets page: that is where you give your consent at Google. Connecting again also only works in the browser. Testing, checking and removing also work with WP-CLI:
# Show targets with ID and state wp cloneworx-backup target list # Test the connection wp cloneworx-backup target test google-drive-1 # Check the backups at this target wp cloneworx-backup target check google-drive-1 # Remove the target; the backups in Google Drive are kept wp cloneworx-backup target remove google-drive-1