mirror of
https://github.com/google/nomulus.git
synced 2025-05-09 16:28:21 +02:00
Provide separate scopes list for delegated credentials
Scope changes in delegated credentials require coordinated external changes, therefore should be separate from those used in the application default credential. ------------- Created by MOE: https://github.com/google/moe MOE_MIGRATED_REVID=212488389
This commit is contained in:
parent
5c1d9bd5c3
commit
dbb1f1649d
4 changed files with 31 additions and 10 deletions
|
@ -42,7 +42,7 @@ public abstract class CredentialModule {
|
||||||
@Provides
|
@Provides
|
||||||
@Singleton
|
@Singleton
|
||||||
public static GoogleCredential provideDefaultCredential(
|
public static GoogleCredential provideDefaultCredential(
|
||||||
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes) {
|
@Config("defaultCredentialOauthScopes") ImmutableList<String> requiredScopes) {
|
||||||
GoogleCredential credential;
|
GoogleCredential credential;
|
||||||
try {
|
try {
|
||||||
credential = GoogleCredential.getApplicationDefault();
|
credential = GoogleCredential.getApplicationDefault();
|
||||||
|
@ -60,7 +60,7 @@ public abstract class CredentialModule {
|
||||||
@Provides
|
@Provides
|
||||||
@Singleton
|
@Singleton
|
||||||
public static GoogleCredential provideJsonCredential(
|
public static GoogleCredential provideJsonCredential(
|
||||||
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes,
|
@Config("defaultCredentialOauthScopes") ImmutableList<String> requiredScopes,
|
||||||
@Key("jsonCredential") String jsonCredential) {
|
@Key("jsonCredential") String jsonCredential) {
|
||||||
GoogleCredential credential;
|
GoogleCredential credential;
|
||||||
try {
|
try {
|
||||||
|
@ -89,7 +89,7 @@ public abstract class CredentialModule {
|
||||||
@Provides
|
@Provides
|
||||||
@Singleton
|
@Singleton
|
||||||
public static GoogleCredential provideDelegatedCredential(
|
public static GoogleCredential provideDelegatedCredential(
|
||||||
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes,
|
@Config("delegatedCredentialOauthScopes") ImmutableList<String> requiredScopes,
|
||||||
@JsonCredential GoogleCredential googleCredential,
|
@JsonCredential GoogleCredential googleCredential,
|
||||||
@Config("gSuiteAdminAccountEmailAddress") String gSuiteAdminAccountEmailAddress) {
|
@Config("gSuiteAdminAccountEmailAddress") String gSuiteAdminAccountEmailAddress) {
|
||||||
return new GoogleCredential.Builder()
|
return new GoogleCredential.Builder()
|
||||||
|
|
|
@ -1143,12 +1143,22 @@ public final class RegistryConfig {
|
||||||
return ImmutableSet.copyOf(config.oAuth.allowedOauthClientIds);
|
return ImmutableSet.copyOf(config.oAuth.allowedOauthClientIds);
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Provides the OAuth scopes required for accessing Google APIs. */
|
/**
|
||||||
|
* Provides the OAuth scopes required for accessing Google APIs using the default credential.
|
||||||
|
*/
|
||||||
@Provides
|
@Provides
|
||||||
@Config("credentialOauthScopes")
|
@Config("defaultCredentialOauthScopes")
|
||||||
public static ImmutableList<String> provideCredentialOauthScopes(
|
public static ImmutableList<String> provideServiceAccountCredentialOauthScopes(
|
||||||
RegistryConfigSettings config) {
|
RegistryConfigSettings config) {
|
||||||
return ImmutableList.copyOf(config.credentialOAuth.credentialOauthScopes);
|
return ImmutableList.copyOf(config.credentialOAuth.defaultCredentialOauthScopes);
|
||||||
|
}
|
||||||
|
|
||||||
|
/** Provides the OAuth scopes required for delegated admin access to G Suite domain. */
|
||||||
|
@Provides
|
||||||
|
@Config("delegatedCredentialOauthScopes")
|
||||||
|
public static ImmutableList<String> provideDelegatedCredentialOauthScopes(
|
||||||
|
RegistryConfigSettings config) {
|
||||||
|
return ImmutableList.copyOf(config.credentialOAuth.delegatedCredentialOauthScopes);
|
||||||
}
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
|
|
|
@ -58,7 +58,8 @@ public class RegistryConfigSettings {
|
||||||
|
|
||||||
/** Configuration options for accessing Google APIs. */
|
/** Configuration options for accessing Google APIs. */
|
||||||
public static class CredentialOAuth {
|
public static class CredentialOAuth {
|
||||||
public List<String> credentialOauthScopes;
|
public List<String> defaultCredentialOauthScopes;
|
||||||
|
public List<String> delegatedCredentialOauthScopes;
|
||||||
}
|
}
|
||||||
|
|
||||||
/** Configuration options for the G Suite account used by Nomulus. */
|
/** Configuration options for the G Suite account used by Nomulus. */
|
||||||
|
|
|
@ -177,17 +177,27 @@ oAuth:
|
||||||
allowedOauthClientIds: []
|
allowedOauthClientIds: []
|
||||||
|
|
||||||
credentialOAuth:
|
credentialOAuth:
|
||||||
# OAuth scopes required for accessing Google APIs.
|
# OAuth scopes required for accessing Google APIs using the default
|
||||||
credentialOauthScopes:
|
# credential.
|
||||||
|
defaultCredentialOauthScopes:
|
||||||
# View and manage data in all Google Cloud APIs.
|
# View and manage data in all Google Cloud APIs.
|
||||||
- https://www.googleapis.com/auth/cloud-platform
|
- https://www.googleapis.com/auth/cloud-platform
|
||||||
# View and manage files in Google Drive.
|
# View and manage files in Google Drive.
|
||||||
- https://www.googleapis.com/auth/drive
|
- https://www.googleapis.com/auth/drive
|
||||||
|
# OAuth scopes required for delegated admin access to G Suite domain.
|
||||||
|
# Deployment of changes to this list must be coordinated with G Suite admin
|
||||||
|
# configuration, which can be managed in the admin console:
|
||||||
|
# - New scopes must be added to the G Suite domain configuration before the
|
||||||
|
# release is deployed.
|
||||||
|
# - Removed scopes must remain on G Suite domain configuration until the
|
||||||
|
# release is deployed.
|
||||||
|
delegatedCredentialOauthScopes:
|
||||||
# View and manage groups on your domain in Directory API.
|
# View and manage groups on your domain in Directory API.
|
||||||
- https://www.googleapis.com/auth/admin.directory.group
|
- https://www.googleapis.com/auth/admin.directory.group
|
||||||
# View and manage group settings in Group Settings API.
|
# View and manage group settings in Group Settings API.
|
||||||
- https://www.googleapis.com/auth/apps.groups.settings
|
- https://www.googleapis.com/auth/apps.groups.settings
|
||||||
|
|
||||||
|
|
||||||
icannReporting:
|
icannReporting:
|
||||||
# URL we PUT monthly ICANN transactions reports to.
|
# URL we PUT monthly ICANN transactions reports to.
|
||||||
icannTransactionsReportingUploadUrl: https://ry-api.icann.org/report/registrar-transactions
|
icannTransactionsReportingUploadUrl: https://ry-api.icann.org/report/registrar-transactions
|
||||||
|
|
Loading…
Add table
Reference in a new issue