Documentation
¶
Overview ¶
Package googlekey reads a Google service account's JSON key file (#2061): the fields the jwt_bearer grant is filled from, the identity an administrator is shown in place of the redacted file, and the operator's next step for each of Google's refusals. It knows nothing about connections; internal/upstreamauth applies what it reads.
Index ¶
Constants ¶
const ConfigKey = "google_service_account_json" // #nosec G101 -- map key, not a credential
ConfigKey is the connection-config key holding the whole key file. Encrypted at rest (pkg/platform/fieldcrypt) and read back as "[REDACTED]".
const TokenURL = "https://oauth2.googleapis.com/token" // #nosec G101 -- a public endpoint URL, not a credential
TokenURL is Google's OAuth token endpoint, the token_uri every key file Google issues carries. A connection whose key is a stored secret exchanges there unless it sets oauth_token_url, because the file is not read until the first call.
Variables ¶
This section is empty.
Functions ¶
func APIHint ¶
APIHint is the operator's next step for a Google API refusing a call a service-account connection made, or "" when the response is not one. A valid token is not access: the API must be enabled in the account's Cloud project, and the account granted inside the product. body is the decoded response.
func Normalize ¶
Normalize returns cfg with google_service_account_json as a string. A JSON client may send the key file as the object it is rather than a string of JSON; both are accepted, and the object is written back as its text, because the at-rest encryption encrypts a string value and would store an object's private key as it came. cfg is returned unchanged when the key is absent or already a string, and a copy otherwise. A value of any other type is refused.
Types ¶
type Identity ¶
type Identity struct {
ClientEmail string `json:"client_email"`
ProjectID string `json:"project_id"`
PrivateKeyID string `json:"private_key_id"`
}
Identity is what a key file says about whose key it is: nothing in it is secret, which is why the admin API reads it back beside the redacted file, so an administrator can tell which account and which key a connection uses.
type KeyFile ¶
type KeyFile struct {
Type string `json:"type"`
ProjectID string `json:"project_id"`
PrivateKeyID string `json:"private_key_id"`
PrivateKey string `json:"private_key"`
ClientEmail string `json:"client_email"`
TokenURI string `json:"token_uri"`
}
KeyFile is the part of a key file the platform reads.