Skip to content
This repository was archived by the owner on Sep 5, 2023. It is now read-only.

Commit e1ee4c7

Browse files
feat: add always_use_jwt_access (#137)
... chore: update gapic-generator-ruby to the latest commit chore: release gapic-generator-typescript 1.5.0 Committer: @miraleung PiperOrigin-RevId: 380641501 Source-Link: googleapis/googleapis@076f7e9 Source-Link: https://github.com/googleapis/googleapis-gen/commit/27e4c88b4048e5f56508d4e1aa417d60a3380892
1 parent 7cc316c commit e1ee4c7

File tree

7 files changed

+39
-124
lines changed

7 files changed

+39
-124
lines changed

.coveragerc

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,6 @@
22
branch = True
33

44
[report]
5-
fail_under = 100
65
show_missing = True
76
omit =
87
google/cloud/secretmanager/__init__.py

google/cloud/secretmanager_v1/services/secret_manager_service/transports/base.py

Lines changed: 14 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -24,6 +24,7 @@
2424
from google.api_core import gapic_v1 # type: ignore
2525
from google.api_core import retry as retries # type: ignore
2626
from google.auth import credentials as ga_credentials # type: ignore
27+
from google.oauth2 import service_account # type: ignore
2728

2829
from google.cloud.secretmanager_v1.types import resources
2930
from google.cloud.secretmanager_v1.types import service
@@ -49,8 +50,6 @@
4950
except pkg_resources.DistributionNotFound: # pragma: NO COVER
5051
_GOOGLE_AUTH_VERSION = None
5152

52-
_API_CORE_VERSION = google.api_core.__version__
53-
5453

5554
class SecretManagerServiceTransport(abc.ABC):
5655
"""Abstract transport class for SecretManagerService."""
@@ -68,6 +67,7 @@ def __init__(
6867
scopes: Optional[Sequence[str]] = None,
6968
quota_project_id: Optional[str] = None,
7069
client_info: gapic_v1.client_info.ClientInfo = DEFAULT_CLIENT_INFO,
70+
always_use_jwt_access: Optional[bool] = False,
7171
**kwargs,
7272
) -> None:
7373
"""Instantiate the transport.
@@ -91,6 +91,8 @@ def __init__(
9191
API requests. If ``None``, then default info will be used.
9292
Generally, you only need to set this if you're developing
9393
your own client library.
94+
always_use_jwt_access (Optional[bool]): Whether self signed JWT should
95+
be used for service account credentials.
9496
"""
9597
# Save the hostname. Default to port 443 (HTTPS) if none is specified.
9698
if ":" not in host:
@@ -119,13 +121,20 @@ def __init__(
119121
**scopes_kwargs, quota_project_id=quota_project_id
120122
)
121123

124+
# If the credentials is service account credentials, then always try to use self signed JWT.
125+
if (
126+
always_use_jwt_access
127+
and isinstance(credentials, service_account.Credentials)
128+
and hasattr(service_account.Credentials, "with_always_use_jwt_access")
129+
):
130+
credentials = credentials.with_always_use_jwt_access(True)
131+
122132
# Save the credentials.
123133
self._credentials = credentials
124134

125-
# TODO(busunkim): These two class methods are in the base transport
135+
# TODO(busunkim): This method is in the base transport
126136
# to avoid duplicating code across the transport classes. These functions
127-
# should be deleted once the minimum required versions of google-api-core
128-
# and google-auth are increased.
137+
# should be deleted once the minimum required versions of google-auth is increased.
129138

130139
# TODO: Remove this function once google-auth >= 1.25.0 is required
131140
@classmethod
@@ -146,27 +155,6 @@ def _get_scopes_kwargs(
146155

147156
return scopes_kwargs
148157

149-
# TODO: Remove this function once google-api-core >= 1.26.0 is required
150-
@classmethod
151-
def _get_self_signed_jwt_kwargs(
152-
cls, host: str, scopes: Optional[Sequence[str]]
153-
) -> Dict[str, Union[Optional[Sequence[str]], str]]:
154-
"""Returns kwargs to pass to grpc_helpers.create_channel depending on the google-api-core version"""
155-
156-
self_signed_jwt_kwargs: Dict[str, Union[Optional[Sequence[str]], str]] = {}
157-
158-
if _API_CORE_VERSION and (
159-
packaging.version.parse(_API_CORE_VERSION)
160-
>= packaging.version.parse("1.26.0")
161-
):
162-
self_signed_jwt_kwargs["default_scopes"] = cls.AUTH_SCOPES
163-
self_signed_jwt_kwargs["scopes"] = scopes
164-
self_signed_jwt_kwargs["default_host"] = cls.DEFAULT_HOST
165-
else:
166-
self_signed_jwt_kwargs["scopes"] = scopes or cls.AUTH_SCOPES
167-
168-
return self_signed_jwt_kwargs
169-
170158
def _prep_wrapped_messages(self, client_info):
171159
# Precompute the wrapped methods.
172160
self._wrapped_methods = {

google/cloud/secretmanager_v1/services/secret_manager_service/transports/grpc.py

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -159,6 +159,7 @@ def __init__(
159159
scopes=scopes,
160160
quota_project_id=quota_project_id,
161161
client_info=client_info,
162+
always_use_jwt_access=True,
162163
)
163164

164165
if not self._grpc_channel:
@@ -214,14 +215,14 @@ def create_channel(
214215
and ``credentials_file`` are passed.
215216
"""
216217

217-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
218-
219218
return grpc_helpers.create_channel(
220219
host,
221220
credentials=credentials,
222221
credentials_file=credentials_file,
223222
quota_project_id=quota_project_id,
224-
**self_signed_jwt_kwargs,
223+
default_scopes=cls.AUTH_SCOPES,
224+
scopes=scopes,
225+
default_host=cls.DEFAULT_HOST,
225226
**kwargs,
226227
)
227228

google/cloud/secretmanager_v1/services/secret_manager_service/transports/grpc_asyncio.py

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -88,14 +88,14 @@ def create_channel(
8888
aio.Channel: A gRPC AsyncIO channel object.
8989
"""
9090

91-
self_signed_jwt_kwargs = cls._get_self_signed_jwt_kwargs(host, scopes)
92-
9391
return grpc_helpers_async.create_channel(
9492
host,
9593
credentials=credentials,
9694
credentials_file=credentials_file,
9795
quota_project_id=quota_project_id,
98-
**self_signed_jwt_kwargs,
96+
default_scopes=cls.AUTH_SCOPES,
97+
scopes=scopes,
98+
default_host=cls.DEFAULT_HOST,
9999
**kwargs,
100100
)
101101

@@ -205,6 +205,7 @@ def __init__(
205205
scopes=scopes,
206206
quota_project_id=quota_project_id,
207207
client_info=client_info,
208+
always_use_jwt_access=True,
208209
)
209210

210211
if not self._grpc_channel:

setup.py

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@
2525
version = "2.5.0"
2626
release_status = "Development Status :: 5 - Production/Stable"
2727
dependencies = [
28-
"google-api-core[grpc] >= 1.22.2, < 2.0.0dev",
28+
"google-api-core[grpc] >= 1.26.0, <2.0.0dev",
2929
"grpc-google-iam-v1 >= 0.12.3, < 0.13dev",
3030
"proto-plus >= 1.4.0",
3131
"packaging >= 14.3",

testing/constraints-3.6.txt

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -5,7 +5,7 @@
55
#
66
# e.g., if setup.py has "foo >= 1.14.0, < 2.0.0dev",
77
# Then this file should have foo==1.14.0
8-
google-api-core==1.22.2
8+
google-api-core==1.26.0
99
grpc-google-iam-v1==0.12.3
1010
proto-plus==1.4.0
1111
libcst==0.2.5

tests/unit/gapic/secretmanager_v1/test_secret_manager_service.py

Lines changed: 15 additions & 89 deletions
Original file line numberDiff line numberDiff line change
@@ -39,9 +39,6 @@
3939
)
4040
from google.cloud.secretmanager_v1.services.secret_manager_service import pagers
4141
from google.cloud.secretmanager_v1.services.secret_manager_service import transports
42-
from google.cloud.secretmanager_v1.services.secret_manager_service.transports.base import (
43-
_API_CORE_VERSION,
44-
)
4542
from google.cloud.secretmanager_v1.services.secret_manager_service.transports.base import (
4643
_GOOGLE_AUTH_VERSION,
4744
)
@@ -58,8 +55,9 @@
5855
import google.auth
5956

6057

61-
# TODO(busunkim): Once google-api-core >= 1.26.0 is required:
62-
# - Delete all the api-core and auth "less than" test cases
58+
# TODO(busunkim): Once google-auth >= 1.25.0 is required transitively
59+
# through google-api-core:
60+
# - Delete the auth "less than" test cases
6361
# - Delete these pytest markers (Make the "greater than or equal to" tests the default).
6462
requires_google_auth_lt_1_25_0 = pytest.mark.skipif(
6563
packaging.version.parse(_GOOGLE_AUTH_VERSION) >= packaging.version.parse("1.25.0"),
@@ -70,16 +68,6 @@
7068
reason="This test requires google-auth >= 1.25.0",
7169
)
7270

73-
requires_api_core_lt_1_26_0 = pytest.mark.skipif(
74-
packaging.version.parse(_API_CORE_VERSION) >= packaging.version.parse("1.26.0"),
75-
reason="This test requires google-api-core < 1.26.0",
76-
)
77-
78-
requires_api_core_gte_1_26_0 = pytest.mark.skipif(
79-
packaging.version.parse(_API_CORE_VERSION) < packaging.version.parse("1.26.0"),
80-
reason="This test requires google-api-core >= 1.26.0",
81-
)
82-
8371

8472
def client_cert_source_callback():
8573
return b"cert bytes", b"key bytes"
@@ -143,6 +131,18 @@ def test_secret_manager_service_client_from_service_account_info(client_class):
143131
assert client.transport._host == "secretmanager.googleapis.com:443"
144132

145133

134+
@pytest.mark.parametrize(
135+
"client_class", [SecretManagerServiceClient, SecretManagerServiceAsyncClient,]
136+
)
137+
def test_secret_manager_service_client_service_account_always_use_jwt(client_class):
138+
with mock.patch.object(
139+
service_account.Credentials, "with_always_use_jwt_access", create=True
140+
) as use_jwt:
141+
creds = service_account.Credentials(None, None, None)
142+
client = client_class(credentials=creds)
143+
use_jwt.assert_called_with(True)
144+
145+
146146
@pytest.mark.parametrize(
147147
"client_class", [SecretManagerServiceClient, SecretManagerServiceAsyncClient,]
148148
)
@@ -4211,7 +4211,6 @@ def test_secret_manager_service_transport_auth_adc_old_google_auth(transport_cla
42114211
(transports.SecretManagerServiceGrpcAsyncIOTransport, grpc_helpers_async),
42124212
],
42134213
)
4214-
@requires_api_core_gte_1_26_0
42154214
def test_secret_manager_service_transport_create_channel(transport_class, grpc_helpers):
42164215
# If credentials and host are not provided, the transport class should use
42174216
# ADC credentials.
@@ -4240,79 +4239,6 @@ def test_secret_manager_service_transport_create_channel(transport_class, grpc_h
42404239
)
42414240

42424241

4243-
@pytest.mark.parametrize(
4244-
"transport_class,grpc_helpers",
4245-
[
4246-
(transports.SecretManagerServiceGrpcTransport, grpc_helpers),
4247-
(transports.SecretManagerServiceGrpcAsyncIOTransport, grpc_helpers_async),
4248-
],
4249-
)
4250-
@requires_api_core_lt_1_26_0
4251-
def test_secret_manager_service_transport_create_channel_old_api_core(
4252-
transport_class, grpc_helpers
4253-
):
4254-
# If credentials and host are not provided, the transport class should use
4255-
# ADC credentials.
4256-
with mock.patch.object(
4257-
google.auth, "default", autospec=True
4258-
) as adc, mock.patch.object(
4259-
grpc_helpers, "create_channel", autospec=True
4260-
) as create_channel:
4261-
creds = ga_credentials.AnonymousCredentials()
4262-
adc.return_value = (creds, None)
4263-
transport_class(quota_project_id="octopus")
4264-
4265-
create_channel.assert_called_with(
4266-
"secretmanager.googleapis.com:443",
4267-
credentials=creds,
4268-
credentials_file=None,
4269-
quota_project_id="octopus",
4270-
scopes=("https://www.googleapis.com/auth/cloud-platform",),
4271-
ssl_credentials=None,
4272-
options=[
4273-
("grpc.max_send_message_length", -1),
4274-
("grpc.max_receive_message_length", -1),
4275-
],
4276-
)
4277-
4278-
4279-
@pytest.mark.parametrize(
4280-
"transport_class,grpc_helpers",
4281-
[
4282-
(transports.SecretManagerServiceGrpcTransport, grpc_helpers),
4283-
(transports.SecretManagerServiceGrpcAsyncIOTransport, grpc_helpers_async),
4284-
],
4285-
)
4286-
@requires_api_core_lt_1_26_0
4287-
def test_secret_manager_service_transport_create_channel_user_scopes(
4288-
transport_class, grpc_helpers
4289-
):
4290-
# If credentials and host are not provided, the transport class should use
4291-
# ADC credentials.
4292-
with mock.patch.object(
4293-
google.auth, "default", autospec=True
4294-
) as adc, mock.patch.object(
4295-
grpc_helpers, "create_channel", autospec=True
4296-
) as create_channel:
4297-
creds = ga_credentials.AnonymousCredentials()
4298-
adc.return_value = (creds, None)
4299-
4300-
transport_class(quota_project_id="octopus", scopes=["1", "2"])
4301-
4302-
create_channel.assert_called_with(
4303-
"secretmanager.googleapis.com:443",
4304-
credentials=creds,
4305-
credentials_file=None,
4306-
quota_project_id="octopus",
4307-
scopes=["1", "2"],
4308-
ssl_credentials=None,
4309-
options=[
4310-
("grpc.max_send_message_length", -1),
4311-
("grpc.max_receive_message_length", -1),
4312-
],
4313-
)
4314-
4315-
43164242
@pytest.mark.parametrize(
43174243
"transport_class",
43184244
[

0 commit comments

Comments
 (0)