Provide separate scopes list for delegated credentials

Scope changes in delegated credentials require coordinated external changes,
therefore should be separate from those used in the application default
credential.

-------------
Created by MOE: https://github.com/google/moe
MOE_MIGRATED_REVID=212488389
This commit is contained in:
weiminyu 2018-09-11 11:28:13 -07:00 committed by Ben McIlwain
parent 5c1d9bd5c3
commit dbb1f1649d
4 changed files with 31 additions and 10 deletions

View file

@ -42,7 +42,7 @@ public abstract class CredentialModule {
@Provides @Provides
@Singleton @Singleton
public static GoogleCredential provideDefaultCredential( public static GoogleCredential provideDefaultCredential(
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes) { @Config("defaultCredentialOauthScopes") ImmutableList<String> requiredScopes) {
GoogleCredential credential; GoogleCredential credential;
try { try {
credential = GoogleCredential.getApplicationDefault(); credential = GoogleCredential.getApplicationDefault();
@ -60,7 +60,7 @@ public abstract class CredentialModule {
@Provides @Provides
@Singleton @Singleton
public static GoogleCredential provideJsonCredential( public static GoogleCredential provideJsonCredential(
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes, @Config("defaultCredentialOauthScopes") ImmutableList<String> requiredScopes,
@Key("jsonCredential") String jsonCredential) { @Key("jsonCredential") String jsonCredential) {
GoogleCredential credential; GoogleCredential credential;
try { try {
@ -89,7 +89,7 @@ public abstract class CredentialModule {
@Provides @Provides
@Singleton @Singleton
public static GoogleCredential provideDelegatedCredential( public static GoogleCredential provideDelegatedCredential(
@Config("credentialOauthScopes") ImmutableList<String> requiredScopes, @Config("delegatedCredentialOauthScopes") ImmutableList<String> requiredScopes,
@JsonCredential GoogleCredential googleCredential, @JsonCredential GoogleCredential googleCredential,
@Config("gSuiteAdminAccountEmailAddress") String gSuiteAdminAccountEmailAddress) { @Config("gSuiteAdminAccountEmailAddress") String gSuiteAdminAccountEmailAddress) {
return new GoogleCredential.Builder() return new GoogleCredential.Builder()

View file

@ -1143,12 +1143,22 @@ public final class RegistryConfig {
return ImmutableSet.copyOf(config.oAuth.allowedOauthClientIds); return ImmutableSet.copyOf(config.oAuth.allowedOauthClientIds);
} }
/** Provides the OAuth scopes required for accessing Google APIs. */ /**
* Provides the OAuth scopes required for accessing Google APIs using the default credential.
*/
@Provides @Provides
@Config("credentialOauthScopes") @Config("defaultCredentialOauthScopes")
public static ImmutableList<String> provideCredentialOauthScopes( public static ImmutableList<String> provideServiceAccountCredentialOauthScopes(
RegistryConfigSettings config) { RegistryConfigSettings config) {
return ImmutableList.copyOf(config.credentialOAuth.credentialOauthScopes); return ImmutableList.copyOf(config.credentialOAuth.defaultCredentialOauthScopes);
}
/** Provides the OAuth scopes required for delegated admin access to G Suite domain. */
@Provides
@Config("delegatedCredentialOauthScopes")
public static ImmutableList<String> provideDelegatedCredentialOauthScopes(
RegistryConfigSettings config) {
return ImmutableList.copyOf(config.credentialOAuth.delegatedCredentialOauthScopes);
} }
/** /**

View file

@ -58,7 +58,8 @@ public class RegistryConfigSettings {
/** Configuration options for accessing Google APIs. */ /** Configuration options for accessing Google APIs. */
public static class CredentialOAuth { public static class CredentialOAuth {
public List<String> credentialOauthScopes; public List<String> defaultCredentialOauthScopes;
public List<String> delegatedCredentialOauthScopes;
} }
/** Configuration options for the G Suite account used by Nomulus. */ /** Configuration options for the G Suite account used by Nomulus. */

View file

@ -177,17 +177,27 @@ oAuth:
allowedOauthClientIds: [] allowedOauthClientIds: []
credentialOAuth: credentialOAuth:
# OAuth scopes required for accessing Google APIs. # OAuth scopes required for accessing Google APIs using the default
credentialOauthScopes: # credential.
defaultCredentialOauthScopes:
# View and manage data in all Google Cloud APIs. # View and manage data in all Google Cloud APIs.
- https://www.googleapis.com/auth/cloud-platform - https://www.googleapis.com/auth/cloud-platform
# View and manage files in Google Drive. # View and manage files in Google Drive.
- https://www.googleapis.com/auth/drive - https://www.googleapis.com/auth/drive
# OAuth scopes required for delegated admin access to G Suite domain.
# Deployment of changes to this list must be coordinated with G Suite admin
# configuration, which can be managed in the admin console:
# - New scopes must be added to the G Suite domain configuration before the
# release is deployed.
# - Removed scopes must remain on G Suite domain configuration until the
# release is deployed.
delegatedCredentialOauthScopes:
# View and manage groups on your domain in Directory API. # View and manage groups on your domain in Directory API.
- https://www.googleapis.com/auth/admin.directory.group - https://www.googleapis.com/auth/admin.directory.group
# View and manage group settings in Group Settings API. # View and manage group settings in Group Settings API.
- https://www.googleapis.com/auth/apps.groups.settings - https://www.googleapis.com/auth/apps.groups.settings
icannReporting: icannReporting:
# URL we PUT monthly ICANN transactions reports to. # URL we PUT monthly ICANN transactions reports to.
icannTransactionsReportingUploadUrl: https://ry-api.icann.org/report/registrar-transactions icannTransactionsReportingUploadUrl: https://ry-api.icann.org/report/registrar-transactions