Skip to content

Commit ae67d10

Browse files
feat: add always_use_jwt_access (#334)
... chore: update gapic-generator-ruby to the latest commit chore: release gapic-generator-typescript 1.5.0 Committer: @miraleung PiperOrigin-RevId: 380641501 Source-Link: googleapis/googleapis@076f7e9 Source-Link: googleapis/googleapis-gen@27e4c88
1 parent 660bd7e commit ae67d10

File tree

15 files changed

+113
-383
lines changed

15 files changed

+113
-383
lines changed

.coveragerc

-1
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,6 @@
22
branch = True
33

44
[report]
5-
fail_under = 100
65
show_missing = True
76
omit =
87
google/cloud/logging/__init__.py

google/cloud/logging_v2/services/config_service_v2/transports/base.py

+14-26
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
from google.api_core import gapic_v1 # type: ignore
2525
from google.api_core import retry as retries # type: ignore
2626
from google.auth import credentials as ga_credentials # type: ignore
27+
from google.oauth2 import service_account # type: ignore
2728

2829
from google.cloud.logging_v2.types import logging_config
2930
from google.protobuf import empty_pb2 # type: ignore
@@ -44,8 +45,6 @@
4445
except pkg_resources.DistributionNotFound: # pragma: NO COVER
4546
_GOOGLE_AUTH_VERSION = None
4647

47-
_API_CORE_VERSION = google.api_core.__version__
48-
4948

5049
class ConfigServiceV2Transport(abc.ABC):
5150
"""Abstract transport class for ConfigServiceV2."""
@@ -68,6 +67,7 @@ def __init__(
6867
scopes: Optional[Sequence[str]] = None,
6968
quota_project_id: Optional[str] = None,
7069
client_info: gapic_v1.client_info.ClientInfo = DEFAULT_CLIENT_INFO,
70+
always_use_jwt_access: Optional[bool] = False,
7171
**kwargs,
7272
) -> None:
7373
"""Instantiate the transport.
@@ -91,6 +91,8 @@ def __init__(
9191
API requests. If ``None``, then default info will be used.
9292
Generally, you only need to set this if you're developing
9393
your own client library.
94+
always_use_jwt_access (Optional[bool]): Whether self signed JWT should
95+
be used for service account credentials.
9496
"""
9597
# Save the hostname. Default to port 443 (HTTPS) if none is specified.
9698
if ":" not in host:
@@ -119,13 +121,20 @@ def __init__(
119121
**scopes_kwargs, quota_project_id=quota_project_id
120122
)
121123

124+
# If the credentials is service account credentials, then always try to use self signed JWT.
125+
if (
126+
always_use_jwt_access
127+
and isinstance(credentials, service_account.Credentials)
128+
and hasattr(service_account.Credentials, "with_always_use_jwt_access")
129+
):
130+
credentials = credentials.with_always_use_jwt_access(True)
131+
122132
# Save the credentials.
123133
self._credentials = credentials
124134

125-
# TODO(busunkim): These two class methods are in the base transport
135+
# TODO(busunkim): This method is in the base transport
126136
# to avoid duplicating code across the transport classes. These functions
127-
# should be deleted once the minimum required versions of google-api-core
128-
# and google-auth are increased.
137+
# should be deleted once the minimum required versions of google-auth is increased.
129138

130139
# TODO: Remove this function once google-auth >= 1.25.0 is required
131140
@classmethod
@@ -146,27 +155,6 @@ def _get_scopes_kwargs(
146155

147156
return scopes_kwargs
148157

149-
# TODO: Remove this function once google-api-core >= 1.26.0 is required
150-
@classmethod
151-
def _get_self_signed_jwt_kwargs(
152-
cls, host: str, scopes: Optional[Sequence[str]]
153-
) -> Dict[str, Union[Optional[Sequence[str]], str]]:
154-
"""Returns kwargs to pass to grpc_helpers.create_channel depending on the google-api-core version"""
155-
156-
self_signed_jwt_kwargs: Dict[str, Union[Optional[Sequence[str]], str]] = {}
157-
158-
if _API_CORE_VERSION and (
159-
packaging.version.parse(_API_CORE_VERSION)
160-
>= packaging.version.parse("1.26.0")
161-
):
162-
self_signed_jwt_kwargs["default_scopes"] = cls.AUTH_SCOPES
163-
self_signed_jwt_kwargs["scopes"] = scopes
164-
self_signed_jwt_kwargs["default_host"] = cls.DEFAULT_HOST
165-
else:
166-
self_signed_jwt_kwargs["scopes"] = scopes or cls.AUTH_SCOPES
167-
168-
return self_signed_jwt_kwargs
169-
170158
def _prep_wrapped_messages(self, client_info):
171159
# Precompute the wrapped methods.
172160
self._wrapped_methods = {

google/cloud/logging_v2/services/config_service_v2/transports/grpc.py

+4-3
Original file line numberDiff line numberDiff line change
@@ -150,6 +150,7 @@ def __init__(
150150
scopes=scopes,
151151
quota_project_id=quota_project_id,
152152
client_info=client_info,
153+
always_use_jwt_access=True,
153154
)
154155

155156
if not self._grpc_channel:
@@ -205,14 +206,14 @@ def create_channel(
205206
and ``credentials_file`` are passed.
206207
"""
207208

208-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
209-
210209
return grpc_helpers.create_channel(
211210
host,
212211
credentials=credentials,
213212
credentials_file=credentials_file,
214213
quota_project_id=quota_project_id,
215-
**self_signed_jwt_kwargs,
214+
default_scopes=cls.AUTH_SCOPES,
215+
scopes=scopes,
216+
default_host=cls.DEFAULT_HOST,
216217
**kwargs,
217218
)
218219

google/cloud/logging_v2/services/config_service_v2/transports/grpc_asyncio.py

+4-3
Original file line numberDiff line numberDiff line change
@@ -79,14 +79,14 @@ def create_channel(
7979
aio.Channel: A gRPC AsyncIO channel object.
8080
"""
8181

82-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
83-
8482
return grpc_helpers_async.create_channel(
8583
host,
8684
credentials=credentials,
8785
credentials_file=credentials_file,
8886
quota_project_id=quota_project_id,
89-
**self_signed_jwt_kwargs,
87+
default_scopes=cls.AUTH_SCOPES,
88+
scopes=scopes,
89+
default_host=cls.DEFAULT_HOST,
9090
**kwargs,
9191
)
9292

@@ -196,6 +196,7 @@ def __init__(
196196
scopes=scopes,
197197
quota_project_id=quota_project_id,
198198
client_info=client_info,
199+
always_use_jwt_access=True,
199200
)
200201

201202
if not self._grpc_channel:

google/cloud/logging_v2/services/logging_service_v2/transports/base.py

+14-26
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
from google.api_core import gapic_v1 # type: ignore
2525
from google.api_core import retry as retries # type: ignore
2626
from google.auth import credentials as ga_credentials # type: ignore
27+
from google.oauth2 import service_account # type: ignore
2728

2829
from google.cloud.logging_v2.types import logging
2930
from google.protobuf import empty_pb2 # type: ignore
@@ -44,8 +45,6 @@
4445
except pkg_resources.DistributionNotFound: # pragma: NO COVER
4546
_GOOGLE_AUTH_VERSION = None
4647

47-
_API_CORE_VERSION = google.api_core.__version__
48-
4948

5049
class LoggingServiceV2Transport(abc.ABC):
5150
"""Abstract transport class for LoggingServiceV2."""
@@ -69,6 +68,7 @@ def __init__(
6968
scopes: Optional[Sequence[str]] = None,
7069
quota_project_id: Optional[str] = None,
7170
client_info: gapic_v1.client_info.ClientInfo = DEFAULT_CLIENT_INFO,
71+
always_use_jwt_access: Optional[bool] = False,
7272
**kwargs,
7373
) -> None:
7474
"""Instantiate the transport.
@@ -92,6 +92,8 @@ def __init__(
9292
API requests. If ``None``, then default info will be used.
9393
Generally, you only need to set this if you're developing
9494
your own client library.
95+
always_use_jwt_access (Optional[bool]): Whether self signed JWT should
96+
be used for service account credentials.
9597
"""
9698
# Save the hostname. Default to port 443 (HTTPS) if none is specified.
9799
if ":" not in host:
@@ -120,13 +122,20 @@ def __init__(
120122
**scopes_kwargs, quota_project_id=quota_project_id
121123
)
122124

125+
# If the credentials is service account credentials, then always try to use self signed JWT.
126+
if (
127+
always_use_jwt_access
128+
and isinstance(credentials, service_account.Credentials)
129+
and hasattr(service_account.Credentials, "with_always_use_jwt_access")
130+
):
131+
credentials = credentials.with_always_use_jwt_access(True)
132+
123133
# Save the credentials.
124134
self._credentials = credentials
125135

126-
# TODO(busunkim): These two class methods are in the base transport
136+
# TODO(busunkim): This method is in the base transport
127137
# to avoid duplicating code across the transport classes. These functions
128-
# should be deleted once the minimum required versions of google-api-core
129-
# and google-auth are increased.
138+
# should be deleted once the minimum required versions of google-auth is increased.
130139

131140
# TODO: Remove this function once google-auth >= 1.25.0 is required
132141
@classmethod
@@ -147,27 +156,6 @@ def _get_scopes_kwargs(
147156

148157
return scopes_kwargs
149158

150-
# TODO: Remove this function once google-api-core >= 1.26.0 is required
151-
@classmethod
152-
def _get_self_signed_jwt_kwargs(
153-
cls, host: str, scopes: Optional[Sequence[str]]
154-
) -> Dict[str, Union[Optional[Sequence[str]], str]]:
155-
"""Returns kwargs to pass to grpc_helpers.create_channel depending on the google-api-core version"""
156-
157-
self_signed_jwt_kwargs: Dict[str, Union[Optional[Sequence[str]], str]] = {}
158-
159-
if _API_CORE_VERSION and (
160-
packaging.version.parse(_API_CORE_VERSION)
161-
>= packaging.version.parse("1.26.0")
162-
):
163-
self_signed_jwt_kwargs["default_scopes"] = cls.AUTH_SCOPES
164-
self_signed_jwt_kwargs["scopes"] = scopes
165-
self_signed_jwt_kwargs["default_host"] = cls.DEFAULT_HOST
166-
else:
167-
self_signed_jwt_kwargs["scopes"] = scopes or cls.AUTH_SCOPES
168-
169-
return self_signed_jwt_kwargs
170-
171159
def _prep_wrapped_messages(self, client_info):
172160
# Precompute the wrapped methods.
173161
self._wrapped_methods = {

google/cloud/logging_v2/services/logging_service_v2/transports/grpc.py

+4-3
Original file line numberDiff line numberDiff line change
@@ -150,6 +150,7 @@ def __init__(
150150
scopes=scopes,
151151
quota_project_id=quota_project_id,
152152
client_info=client_info,
153+
always_use_jwt_access=True,
153154
)
154155

155156
if not self._grpc_channel:
@@ -205,14 +206,14 @@ def create_channel(
205206
and ``credentials_file`` are passed.
206207
"""
207208

208-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
209-
210209
return grpc_helpers.create_channel(
211210
host,
212211
credentials=credentials,
213212
credentials_file=credentials_file,
214213
quota_project_id=quota_project_id,
215-
**self_signed_jwt_kwargs,
214+
default_scopes=cls.AUTH_SCOPES,
215+
scopes=scopes,
216+
default_host=cls.DEFAULT_HOST,
216217
**kwargs,
217218
)
218219

google/cloud/logging_v2/services/logging_service_v2/transports/grpc_asyncio.py

+4-3
Original file line numberDiff line numberDiff line change
@@ -79,14 +79,14 @@ def create_channel(
7979
aio.Channel: A gRPC AsyncIO channel object.
8080
"""
8181

82-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
83-
8482
return grpc_helpers_async.create_channel(
8583
host,
8684
credentials=credentials,
8785
credentials_file=credentials_file,
8886
quota_project_id=quota_project_id,
89-
**self_signed_jwt_kwargs,
87+
default_scopes=cls.AUTH_SCOPES,
88+
scopes=scopes,
89+
default_host=cls.DEFAULT_HOST,
9090
**kwargs,
9191
)
9292

@@ -196,6 +196,7 @@ def __init__(
196196
scopes=scopes,
197197
quota_project_id=quota_project_id,
198198
client_info=client_info,
199+
always_use_jwt_access=True,
199200
)
200201

201202
if not self._grpc_channel:

google/cloud/logging_v2/services/metrics_service_v2/transports/base.py

+14-26
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
from google.api_core import gapic_v1 # type: ignore
2525
from google.api_core import retry as retries # type: ignore
2626
from google.auth import credentials as ga_credentials # type: ignore
27+
from google.oauth2 import service_account # type: ignore
2728

2829
from google.cloud.logging_v2.types import logging_metrics
2930
from google.protobuf import empty_pb2 # type: ignore
@@ -44,8 +45,6 @@
4445
except pkg_resources.DistributionNotFound: # pragma: NO COVER
4546
_GOOGLE_AUTH_VERSION = None
4647

47-
_API_CORE_VERSION = google.api_core.__version__
48-
4948

5049
class MetricsServiceV2Transport(abc.ABC):
5150
"""Abstract transport class for MetricsServiceV2."""
@@ -69,6 +68,7 @@ def __init__(
6968
scopes: Optional[Sequence[str]] = None,
7069
quota_project_id: Optional[str] = None,
7170
client_info: gapic_v1.client_info.ClientInfo = DEFAULT_CLIENT_INFO,
71+
always_use_jwt_access: Optional[bool] = False,
7272
**kwargs,
7373
) -> None:
7474
"""Instantiate the transport.
@@ -92,6 +92,8 @@ def __init__(
9292
API requests. If ``None``, then default info will be used.
9393
Generally, you only need to set this if you're developing
9494
your own client library.
95+
always_use_jwt_access (Optional[bool]): Whether self signed JWT should
96+
be used for service account credentials.
9597
"""
9698
# Save the hostname. Default to port 443 (HTTPS) if none is specified.
9799
if ":" not in host:
@@ -120,13 +122,20 @@ def __init__(
120122
**scopes_kwargs, quota_project_id=quota_project_id
121123
)
122124

125+
# If the credentials is service account credentials, then always try to use self signed JWT.
126+
if (
127+
always_use_jwt_access
128+
and isinstance(credentials, service_account.Credentials)
129+
and hasattr(service_account.Credentials, "with_always_use_jwt_access")
130+
):
131+
credentials = credentials.with_always_use_jwt_access(True)
132+
123133
# Save the credentials.
124134
self._credentials = credentials
125135

126-
# TODO(busunkim): These two class methods are in the base transport
136+
# TODO(busunkim): This method is in the base transport
127137
# to avoid duplicating code across the transport classes. These functions
128-
# should be deleted once the minimum required versions of google-api-core
129-
# and google-auth are increased.
138+
# should be deleted once the minimum required versions of google-auth is increased.
130139

131140
# TODO: Remove this function once google-auth >= 1.25.0 is required
132141
@classmethod
@@ -147,27 +156,6 @@ def _get_scopes_kwargs(
147156

148157
return scopes_kwargs
149158

150-
# TODO: Remove this function once google-api-core >= 1.26.0 is required
151-
@classmethod
152-
def _get_self_signed_jwt_kwargs(
153-
cls, host: str, scopes: Optional[Sequence[str]]
154-
) -> Dict[str, Union[Optional[Sequence[str]], str]]:
155-
"""Returns kwargs to pass to grpc_helpers.create_channel depending on the google-api-core version"""
156-
157-
self_signed_jwt_kwargs: Dict[str, Union[Optional[Sequence[str]], str]] = {}
158-
159-
if _API_CORE_VERSION and (
160-
packaging.version.parse(_API_CORE_VERSION)
161-
>= packaging.version.parse("1.26.0")
162-
):
163-
self_signed_jwt_kwargs["default_scopes"] = cls.AUTH_SCOPES
164-
self_signed_jwt_kwargs["scopes"] = scopes
165-
self_signed_jwt_kwargs["default_host"] = cls.DEFAULT_HOST
166-
else:
167-
self_signed_jwt_kwargs["scopes"] = scopes or cls.AUTH_SCOPES
168-
169-
return self_signed_jwt_kwargs
170-
171159
def _prep_wrapped_messages(self, client_info):
172160
# Precompute the wrapped methods.
173161
self._wrapped_methods = {

google/cloud/logging_v2/services/metrics_service_v2/transports/grpc.py

+4-3
Original file line numberDiff line numberDiff line change
@@ -150,6 +150,7 @@ def __init__(
150150
scopes=scopes,
151151
quota_project_id=quota_project_id,
152152
client_info=client_info,
153+
always_use_jwt_access=True,
153154
)
154155

155156
if not self._grpc_channel:
@@ -205,14 +206,14 @@ def create_channel(
205206
and ``credentials_file`` are passed.
206207
"""
207208

208-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
209-
210209
return grpc_helpers.create_channel(
211210
host,
212211
credentials=credentials,
213212
credentials_file=credentials_file,
214213
quota_project_id=quota_project_id,
215-
**self_signed_jwt_kwargs,
214+
default_scopes=cls.AUTH_SCOPES,
215+
scopes=scopes,
216+
default_host=cls.DEFAULT_HOST,
216217
**kwargs,
217218
)
218219

0 commit comments

Comments
 (0)