← All changes
|
includes/sdk/google/google/gax/src/CredentialsWrapper.php
+44
-44
1.2.12
→
1.4.2
View file →
| @@ -29,30 +29,28 @@ | ||
| 29 | 29 | * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT |
| 30 | 30 | * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE |
| 31 | 31 | * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. |
| 32 | 32 | */ |
| 33 | -namespace Dudlewebs\WPMCS\Google\ApiCore; | |
| 33 | +namespace Dudlewebs\WPMCS\GCP\Google\ApiCore; | |
| 34 | 34 | |
| 35 | 35 | use DomainException; |
| 36 | 36 | use Exception; |
| 37 | -use Dudlewebs\WPMCS\Google\Auth\ApplicationDefaultCredentials; | |
| 38 | -use Dudlewebs\WPMCS\Google\Auth\ProjectIdProviderInterface; | |
| 39 | -use Dudlewebs\WPMCS\Google\Auth\Cache\MemoryCacheItemPool; | |
| 40 | -use Dudlewebs\WPMCS\Google\Auth\Credentials\ServiceAccountCredentials; | |
| 41 | -use Dudlewebs\WPMCS\Google\Auth\CredentialsLoader; | |
| 42 | -use Dudlewebs\WPMCS\Google\Auth\FetchAuthTokenCache; | |
| 43 | -use Dudlewebs\WPMCS\Google\Auth\FetchAuthTokenInterface; | |
| 44 | -use Dudlewebs\WPMCS\Google\Auth\GetQuotaProjectInterface; | |
| 45 | -use Dudlewebs\WPMCS\Google\Auth\GetUniverseDomainInterface; | |
| 46 | -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\Guzzle6HttpHandler; | |
| 47 | -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\Guzzle7HttpHandler; | |
| 48 | -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\HttpHandlerFactory; | |
| 49 | -use Dudlewebs\WPMCS\Google\Auth\UpdateMetadataInterface; | |
| 50 | -use Dudlewebs\WPMCS\Psr\Cache\CacheItemPoolInterface; | |
| 37 | +use Dudlewebs\WPMCS\GCP\Google\Auth\ApplicationDefaultCredentials; | |
| 38 | +use Dudlewebs\WPMCS\GCP\Google\Auth\Cache\MemoryCacheItemPool; | |
| 39 | +use Dudlewebs\WPMCS\GCP\Google\Auth\Credentials\GCECredentials; | |
| 40 | +use Dudlewebs\WPMCS\GCP\Google\Auth\Credentials\ServiceAccountCredentials; | |
| 41 | +use Dudlewebs\WPMCS\GCP\Google\Auth\CredentialsLoader; | |
| 42 | +use Dudlewebs\WPMCS\GCP\Google\Auth\FetchAuthTokenCache; | |
| 43 | +use Dudlewebs\WPMCS\GCP\Google\Auth\FetchAuthTokenInterface; | |
| 44 | +use Dudlewebs\WPMCS\GCP\Google\Auth\GetQuotaProjectInterface; | |
| 45 | +use Dudlewebs\WPMCS\GCP\Google\Auth\GetUniverseDomainInterface; | |
| 46 | +use Dudlewebs\WPMCS\GCP\Google\Auth\ProjectIdProviderInterface; | |
| 47 | +use Dudlewebs\WPMCS\GCP\Google\Auth\UpdateMetadataInterface; | |
| 48 | +use Dudlewebs\WPMCS\GCP\Psr\Cache\CacheItemPoolInterface; | |
| 51 | 49 | /** |
| 52 | 50 | * The CredentialsWrapper object provides a wrapper around a FetchAuthTokenInterface. |
| 53 | 51 | */ |
| 54 | -class CredentialsWrapper implements ProjectIdProviderInterface | |
| 52 | +class CredentialsWrapper implements HeaderCredentialsInterface, ProjectIdProviderInterface | |
| 55 | 53 | { |
| 56 | 54 | use ValidationTrait; |
| 57 | 55 | /** @var FetchAuthTokenInterface $credentialsFetcher */ |
| 58 | 56 | private ?FetchAuthTokenInterface $credentialsFetcher = null; |
| @@ -70,12 +68,12 @@ | ||
| 70 | 68 | * specifically for authentication. Should match a signature of |
| 71 | 69 | * `function (RequestInterface $request, array $options) : ResponseInterface`. |
| 72 | 70 | * @throws ValidationException |
| 73 | 71 | */ |
| 74 | - public function __construct(FetchAuthTokenInterface $credentialsFetcher, callable $authHttpHandler = null, string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN) | |
| 72 | + public function __construct(FetchAuthTokenInterface $credentialsFetcher, ?callable $authHttpHandler = null, string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN) | |
| 75 | 73 | { |
| 76 | 74 | $this->credentialsFetcher = $credentialsFetcher; |
| 77 | - $this->authHttpHandler = $authHttpHandler ?: self::buildHttpHandlerFactory(); | |
| 75 | + $this->authHttpHandler = $authHttpHandler; | |
| 78 | 76 | if (empty($universeDomain)) { |
| 79 | 77 | throw new ValidationException('The universe domain cannot be empty'); |
| 80 | 78 | } |
| 81 | 79 | $this->universeDomain = $universeDomain; |
| @@ -119,20 +117,19 @@ | ||
| 119 | 117 | public static function build(array $args = [], string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN) |
| 120 | 118 | { |
| 121 | 119 | $args += ['keyFile' => null, 'scopes' => null, 'authHttpHandler' => null, 'enableCaching' => \true, 'authCache' => null, 'authCacheOptions' => [], 'quotaProject' => null, 'defaultScopes' => null, 'useJwtAccessWithScope' => \true]; |
| 122 | 120 | $keyFile = $args['keyFile']; |
| 123 | - $authHttpHandler = $args['authHttpHandler'] ?: self::buildHttpHandlerFactory(); | |
| 124 | - if (is_null($keyFile)) { | |
| 125 | - $loader = self::buildApplicationDefaultCredentials($args['scopes'], $authHttpHandler, $args['authCacheOptions'], $args['authCache'], $args['quotaProject'], $args['defaultScopes']); | |
| 121 | + if (\is_null($keyFile)) { | |
| 122 | + $loader = self::buildApplicationDefaultCredentials($args['scopes'], $args['authHttpHandler'], $args['authCacheOptions'], $args['authCache'], $args['quotaProject'], $args['defaultScopes']); | |
| 126 | 123 | if ($loader instanceof FetchAuthTokenCache) { |
| 127 | 124 | $loader = $loader->getFetcher(); |
| 128 | 125 | } |
| 129 | 126 | } else { |
| 130 | - if (is_string($keyFile)) { | |
| 131 | - if (!file_exists($keyFile)) { | |
| 127 | + if (\is_string($keyFile)) { | |
| 128 | + if (!\file_exists($keyFile)) { | |
| 132 | 129 | throw new ValidationException("Could not find keyfile: {$keyFile}"); |
| 133 | 130 | } |
| 134 | - $keyFile = json_decode(file_get_contents($keyFile), \true); | |
| 131 | + $keyFile = \json_decode(\file_get_contents($keyFile), \true); | |
| 135 | 132 | } |
| 136 | 133 | if (isset($args['quotaProject'])) { |
| 137 | 134 | $keyFile['quota_project_id'] = $args['quotaProject']; |
| 138 | 135 | } |
| @@ -146,14 +143,14 @@ | ||
| 146 | 143 | if ($args['enableCaching']) { |
| 147 | 144 | $authCache = $args['authCache'] ?: new MemoryCacheItemPool(); |
| 148 | 145 | $loader = new FetchAuthTokenCache($loader, $args['authCacheOptions'], $authCache); |
| 149 | 146 | } |
| 150 | - return new CredentialsWrapper($loader, $authHttpHandler, $universeDomain); | |
| 147 | + return new CredentialsWrapper($loader, $args['authHttpHandler'], $universeDomain); | |
| 151 | 148 | } |
| 152 | 149 | /** |
| 153 | 150 | * @return string|null The quota project associated with the credentials. |
| 154 | 151 | */ |
| 155 | - public function getQuotaProject() | |
| 152 | + public function getQuotaProject() : ?string | |
| 156 | 153 | { |
| 157 | 154 | if ($this->credentialsFetcher instanceof GetQuotaProjectInterface) { |
| 158 | 155 | return $this->credentialsFetcher->getQuotaProject(); |
| 159 | 156 | } |
| @@ -158,9 +155,9 @@ | ||
| 158 | 155 | return $this->credentialsFetcher->getQuotaProject(); |
| 159 | 156 | } |
| 160 | 157 | return null; |
| 161 | 158 | } |
| 162 | - public function getProjectId(callable $httpHandler = null): ?string | |
| 159 | + public function getProjectId(?callable $httpHandler = null) : ?string | |
| 163 | 160 | { |
| 164 | 161 | // Ensure that FetchAuthTokenCache does not throw an exception |
| 165 | 162 | if ($this->credentialsFetcher instanceof FetchAuthTokenCache && !$this->credentialsFetcher->getFetcher() instanceof ProjectIdProviderInterface) { |
| 166 | 163 | return null; |
| @@ -189,20 +186,20 @@ | ||
| 189 | 186 | /** |
| 190 | 187 | * @param string $audience optional audience for self-signed JWTs. |
| 191 | 188 | * @return callable Callable function that returns an authorization header. |
| 192 | 189 | */ |
| 193 | - public function getAuthorizationHeaderCallback($audience = null) | |
| 190 | + public function getAuthorizationHeaderCallback($audience = null) : ?callable | |
| 194 | 191 | { |
| 195 | 192 | // NOTE: changes to this function should be treated carefully and tested thoroughly. It will |
| 196 | 193 | // be passed into the gRPC c extension, and changes have the potential to trigger very |
| 197 | 194 | // difficult-to-diagnose segmentation faults. |
| 198 | - return function () use ($audience) { | |
| 195 | + return function () use($audience) { | |
| 199 | 196 | $token = $this->credentialsFetcher->getLastReceivedToken(); |
| 200 | 197 | if (self::isExpired($token)) { |
| 201 | 198 | $this->checkUniverseDomain(); |
| 202 | 199 | // Call updateMetadata to take advantage of self-signed JWTs |
| 203 | 200 | if ($this->credentialsFetcher instanceof UpdateMetadataInterface) { |
| 204 | - return $this->credentialsFetcher->updateMetadata([], $audience); | |
| 201 | + return $this->credentialsFetcher->updateMetadata([], $audience, $this->authHttpHandler); | |
| 205 | 202 | } |
| 206 | 203 | // In case a custom fetcher is provided (unlikely) which doesn't |
| 207 | 204 | // implement UpdateMetadataInterface |
| 208 | 205 | $token = $this->credentialsFetcher->fetchAuthToken($this->authHttpHandler); |
| @@ -218,30 +215,33 @@ | ||
| 218 | 215 | }; |
| 219 | 216 | } |
| 220 | 217 | /** |
| 221 | 218 | * Verify that the expected universe domain matches the universe domain from the credentials. |
| 219 | + * | |
| 220 | + * @throws ValidationException if the universe domain does not match. | |
| 222 | 221 | */ |
| 223 | - public function checkUniverseDomain() | |
| 222 | + public function checkUniverseDomain() : void | |
| 224 | 223 | { |
| 225 | - if (\false === $this->hasCheckedUniverse) { | |
| 224 | + if (\false === $this->hasCheckedUniverse && $this->shouldCheckUniverseDomain()) { | |
| 226 | 225 | $credentialsUniverse = $this->credentialsFetcher instanceof GetUniverseDomainInterface ? $this->credentialsFetcher->getUniverseDomain() : GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN; |
| 227 | 226 | if ($credentialsUniverse !== $this->universeDomain) { |
| 228 | - throw new ValidationException(sprintf('The configured universe domain (%s) does not match the credential universe domain (%s)', $this->universeDomain, $credentialsUniverse)); | |
| 227 | + throw new ValidationException(\sprintf('The configured universe domain (%s) does not match the credential universe domain (%s)', $this->universeDomain, $credentialsUniverse)); | |
| 229 | 228 | } |
| 230 | 229 | $this->hasCheckedUniverse = \true; |
| 231 | 230 | } |
| 232 | 231 | } |
| 233 | 232 | /** |
| 234 | - * @return Guzzle6HttpHandler|Guzzle7HttpHandler | |
| 235 | - * @throws ValidationException | |
| 233 | + * Skip universe domain check for Metadata server (e.g. GCE) credentials. | |
| 234 | + * | |
| 235 | + * @return bool | |
| 236 | 236 | */ |
| 237 | - private static function buildHttpHandlerFactory() | |
| 237 | + private function shouldCheckUniverseDomain() : bool | |
| 238 | 238 | { |
| 239 | - try { | |
| 240 | - return HttpHandlerFactory::build(); | |
| 241 | - } catch (Exception $ex) { | |
| 242 | - throw new ValidationException("Failed to build HttpHandler", $ex->getCode(), $ex); | |
| 239 | + $fetcher = $this->credentialsFetcher instanceof FetchAuthTokenCache ? $this->credentialsFetcher->getFetcher() : $this->credentialsFetcher; | |
| 240 | + if ($fetcher instanceof GCECredentials) { | |
| 241 | + return \false; | |
| 243 | 242 | } |
| 243 | + return \true; | |
| 244 | 244 | } |
| 245 | 245 | /** |
| 246 | 246 | * @param array $scopes |
| 247 | 247 | * @param callable $authHttpHandler |
| @@ -251,14 +251,14 @@ | ||
| 251 | 251 | * @param array $defaultScopes |
| 252 | 252 | * @return FetchAuthTokenInterface |
| 253 | 253 | * @throws ValidationException |
| 254 | 254 | */ |
| 255 | - private static function buildApplicationDefaultCredentials(array $scopes = null, callable $authHttpHandler = null, array $authCacheOptions = null, CacheItemPoolInterface $authCache = null, $quotaProject = null, array $defaultScopes = null) | |
| 255 | + private static function buildApplicationDefaultCredentials(?array $scopes = null, ?callable $authHttpHandler = null, ?array $authCacheOptions = null, ?CacheItemPoolInterface $authCache = null, $quotaProject = null, ?array $defaultScopes = null) | |
| 256 | 256 | { |
| 257 | 257 | try { |
| 258 | 258 | return ApplicationDefaultCredentials::getCredentials($scopes, $authHttpHandler, $authCacheOptions, $authCache, $quotaProject, $defaultScopes); |
| 259 | 259 | } catch (DomainException $ex) { |
| 260 | - throw new ValidationException("Could not construct ApplicationDefaultCredentials", $ex->getCode(), $ex); | |
| 260 | + throw new ValidationException('Could not construct ApplicationDefaultCredentials', $ex->getCode(), $ex); | |
| 261 | 261 | } |
| 262 | 262 | } |
| 263 | 263 | /** |
| 264 | 264 | * @param mixed $token |
| @@ -264,9 +264,9 @@ | ||
| 264 | 264 | * @param mixed $token |
| 265 | 265 | */ |
| 266 | 266 | private static function isValid($token) |
| 267 | 267 | { |
| 268 | - return is_array($token) && array_key_exists('access_token', $token); | |
| 268 | + return \is_array($token) && \array_key_exists('access_token', $token); | |
| 269 | 269 | } |
| 270 | 270 | /** |
| 271 | 271 | * @param mixed $token |
| 272 | 272 | */ |
| @@ -271,7 +271,7 @@ | ||
| 271 | 271 | * @param mixed $token |
| 272 | 272 | */ |
| 273 | 273 | private static function isExpired($token) |
| 274 | 274 | { |
| 275 | - return !(self::isValid($token) && array_key_exists('expires_at', $token) && $token['expires_at'] > time() + self::$eagerRefreshThresholdSeconds); | |
| 275 | + return !(self::isValid($token) && \array_key_exists('expires_at', $token) && $token['expires_at'] > \time() + self::$eagerRefreshThresholdSeconds); | |
| 276 | 276 | } |
| 277 | 277 | } |