googlekey

package
v1.142.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: Apache-2.0 Imports: 8 Imported by: 0

Documentation

Overview

Package googlekey reads a Google service account's JSON key file (#2061): the fields the jwt_bearer grant is filled from, the identity an administrator is shown in place of the redacted file, and the operator's next step for each of Google's refusals. It knows nothing about connections; internal/upstreamauth applies what it reads.

Index

Constants

View Source
const ConfigKey = "google_service_account_json" // #nosec G101 -- map key, not a credential

ConfigKey is the connection-config key holding the whole key file. Encrypted at rest (pkg/platform/fieldcrypt) and read back as "[REDACTED]".

View Source
const TokenURL = "https://oauth2.googleapis.com/token" // #nosec G101 -- a public endpoint URL, not a credential

TokenURL is Google's OAuth token endpoint, the token_uri every key file Google issues carries. A connection whose key is a stored secret exchanges there unless it sets oauth_token_url, because the file is not read until the first call.

Variables

This section is empty.

Functions

func APIHint

func APIHint(status int, body any) string

APIHint is the operator's next step for a Google API refusing a call a service-account connection made, or "" when the response is not one. A valid token is not access: the API must be enabled in the account's Cloud project, and the account granted inside the product. body is the decoded response.

func Normalize

func Normalize(cfg map[string]any) (map[string]any, error)

Normalize returns cfg with google_service_account_json as a string. A JSON client may send the key file as the object it is rather than a string of JSON; both are accepted, and the object is written back as its text, because the at-rest encryption encrypts a string value and would store an object's private key as it came. cfg is returned unchanged when the key is absent or already a string, and a copy otherwise. A value of any other type is refused.

func TokenHint

func TokenHint(code, description string) string

TokenHint is the operator's next step for a refusal Google's token endpoint answers with, or "" when the refusal is not one of Google's. Each is fixed outside the platform, which is why it rides with the upstream's words.

Types

type Identity

type Identity struct {
	ClientEmail  string `json:"client_email"`
	ProjectID    string `json:"project_id"`
	PrivateKeyID string `json:"private_key_id"`
}

Identity is what a key file says about whose key it is: nothing in it is secret, which is why the admin API reads it back beside the redacted file, so an administrator can tell which account and which key a connection uses.

func IdentityOf

func IdentityOf(cfg map[string]any) (Identity, bool)

IdentityOf reads the identity out of a connection config holding a key file, for the admin API to show beside the redacted value. ok is false when the config holds none, or a file that does not parse.

type KeyFile

type KeyFile struct {
	Type         string `json:"type"`
	ProjectID    string `json:"project_id"`
	PrivateKeyID string `json:"private_key_id"`
	PrivateKey   string `json:"private_key"`
	ClientEmail  string `json:"client_email"`
	TokenURI     string `json:"token_uri"`
}

KeyFile is the part of a key file the platform reads.

func Parse

func Parse(raw string) (KeyFile, error)

Parse reads a key file. Every refusal names the field, never a value: the input is a private key.

func (KeyFile) Identity

func (sa KeyFile) Identity() Identity

Identity is the non-secret half of the key file.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL