PluginProbe
Media Cloud Sync / 1.4.2
Media Cloud Sync v1.4.2
1.4.2 1.4.1 1.4.0 1.3.12 1.3.11 1.3.10 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.2.0 1.2.10 1.2.11 1.2.12 1.2.13 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 All 36 releases
← All changes | includes/sdk/google/google/gax/src/CredentialsWrapper.php +44 -44 1.2.12 → 1.4.2 View file →
@@ -29,30 +29,28 @@
29 29 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
30 30 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE
31 31 * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
32 32 */
33 -namespace Dudlewebs\WPMCS\Google\ApiCore;
33 +namespace Dudlewebs\WPMCS\GCP\Google\ApiCore;
34 34
35 35 use DomainException;
36 36 use Exception;
37 -use Dudlewebs\WPMCS\Google\Auth\ApplicationDefaultCredentials;
38 -use Dudlewebs\WPMCS\Google\Auth\ProjectIdProviderInterface;
39 -use Dudlewebs\WPMCS\Google\Auth\Cache\MemoryCacheItemPool;
40 -use Dudlewebs\WPMCS\Google\Auth\Credentials\ServiceAccountCredentials;
41 -use Dudlewebs\WPMCS\Google\Auth\CredentialsLoader;
42 -use Dudlewebs\WPMCS\Google\Auth\FetchAuthTokenCache;
43 -use Dudlewebs\WPMCS\Google\Auth\FetchAuthTokenInterface;
44 -use Dudlewebs\WPMCS\Google\Auth\GetQuotaProjectInterface;
45 -use Dudlewebs\WPMCS\Google\Auth\GetUniverseDomainInterface;
46 -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\Guzzle6HttpHandler;
47 -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\Guzzle7HttpHandler;
48 -use Dudlewebs\WPMCS\Google\Auth\HttpHandler\HttpHandlerFactory;
49 -use Dudlewebs\WPMCS\Google\Auth\UpdateMetadataInterface;
50 -use Dudlewebs\WPMCS\Psr\Cache\CacheItemPoolInterface;
37 +use Dudlewebs\WPMCS\GCP\Google\Auth\ApplicationDefaultCredentials;
38 +use Dudlewebs\WPMCS\GCP\Google\Auth\Cache\MemoryCacheItemPool;
39 +use Dudlewebs\WPMCS\GCP\Google\Auth\Credentials\GCECredentials;
40 +use Dudlewebs\WPMCS\GCP\Google\Auth\Credentials\ServiceAccountCredentials;
41 +use Dudlewebs\WPMCS\GCP\Google\Auth\CredentialsLoader;
42 +use Dudlewebs\WPMCS\GCP\Google\Auth\FetchAuthTokenCache;
43 +use Dudlewebs\WPMCS\GCP\Google\Auth\FetchAuthTokenInterface;
44 +use Dudlewebs\WPMCS\GCP\Google\Auth\GetQuotaProjectInterface;
45 +use Dudlewebs\WPMCS\GCP\Google\Auth\GetUniverseDomainInterface;
46 +use Dudlewebs\WPMCS\GCP\Google\Auth\ProjectIdProviderInterface;
47 +use Dudlewebs\WPMCS\GCP\Google\Auth\UpdateMetadataInterface;
48 +use Dudlewebs\WPMCS\GCP\Psr\Cache\CacheItemPoolInterface;
51 49 /**
52 50 * The CredentialsWrapper object provides a wrapper around a FetchAuthTokenInterface.
53 51 */
54 -class CredentialsWrapper implements ProjectIdProviderInterface
52 +class CredentialsWrapper implements HeaderCredentialsInterface, ProjectIdProviderInterface
55 53 {
56 54 use ValidationTrait;
57 55 /** @var FetchAuthTokenInterface $credentialsFetcher */
58 56 private ?FetchAuthTokenInterface $credentialsFetcher = null;
@@ -70,12 +68,12 @@
70 68 * specifically for authentication. Should match a signature of
71 69 * `function (RequestInterface $request, array $options) : ResponseInterface`.
72 70 * @throws ValidationException
73 71 */
74 - public function __construct(FetchAuthTokenInterface $credentialsFetcher, callable $authHttpHandler = null, string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN)
72 + public function __construct(FetchAuthTokenInterface $credentialsFetcher, ?callable $authHttpHandler = null, string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN)
75 73 {
76 74 $this->credentialsFetcher = $credentialsFetcher;
77 - $this->authHttpHandler = $authHttpHandler ?: self::buildHttpHandlerFactory();
75 + $this->authHttpHandler = $authHttpHandler;
78 76 if (empty($universeDomain)) {
79 77 throw new ValidationException('The universe domain cannot be empty');
80 78 }
81 79 $this->universeDomain = $universeDomain;
@@ -119,20 +117,19 @@
119 117 public static function build(array $args = [], string $universeDomain = GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN)
120 118 {
121 119 $args += ['keyFile' => null, 'scopes' => null, 'authHttpHandler' => null, 'enableCaching' => \true, 'authCache' => null, 'authCacheOptions' => [], 'quotaProject' => null, 'defaultScopes' => null, 'useJwtAccessWithScope' => \true];
122 120 $keyFile = $args['keyFile'];
123 - $authHttpHandler = $args['authHttpHandler'] ?: self::buildHttpHandlerFactory();
124 - if (is_null($keyFile)) {
125 - $loader = self::buildApplicationDefaultCredentials($args['scopes'], $authHttpHandler, $args['authCacheOptions'], $args['authCache'], $args['quotaProject'], $args['defaultScopes']);
121 + if (\is_null($keyFile)) {
122 + $loader = self::buildApplicationDefaultCredentials($args['scopes'], $args['authHttpHandler'], $args['authCacheOptions'], $args['authCache'], $args['quotaProject'], $args['defaultScopes']);
126 123 if ($loader instanceof FetchAuthTokenCache) {
127 124 $loader = $loader->getFetcher();
128 125 }
129 126 } else {
130 - if (is_string($keyFile)) {
131 - if (!file_exists($keyFile)) {
127 + if (\is_string($keyFile)) {
128 + if (!\file_exists($keyFile)) {
132 129 throw new ValidationException("Could not find keyfile: {$keyFile}");
133 130 }
134 - $keyFile = json_decode(file_get_contents($keyFile), \true);
131 + $keyFile = \json_decode(\file_get_contents($keyFile), \true);
135 132 }
136 133 if (isset($args['quotaProject'])) {
137 134 $keyFile['quota_project_id'] = $args['quotaProject'];
138 135 }
@@ -146,14 +143,14 @@
146 143 if ($args['enableCaching']) {
147 144 $authCache = $args['authCache'] ?: new MemoryCacheItemPool();
148 145 $loader = new FetchAuthTokenCache($loader, $args['authCacheOptions'], $authCache);
149 146 }
150 - return new CredentialsWrapper($loader, $authHttpHandler, $universeDomain);
147 + return new CredentialsWrapper($loader, $args['authHttpHandler'], $universeDomain);
151 148 }
152 149 /**
153 150 * @return string|null The quota project associated with the credentials.
154 151 */
155 - public function getQuotaProject()
152 + public function getQuotaProject() : ?string
156 153 {
157 154 if ($this->credentialsFetcher instanceof GetQuotaProjectInterface) {
158 155 return $this->credentialsFetcher->getQuotaProject();
159 156 }
@@ -158,9 +155,9 @@
158 155 return $this->credentialsFetcher->getQuotaProject();
159 156 }
160 157 return null;
161 158 }
162 - public function getProjectId(callable $httpHandler = null): ?string
159 + public function getProjectId(?callable $httpHandler = null) : ?string
163 160 {
164 161 // Ensure that FetchAuthTokenCache does not throw an exception
165 162 if ($this->credentialsFetcher instanceof FetchAuthTokenCache && !$this->credentialsFetcher->getFetcher() instanceof ProjectIdProviderInterface) {
166 163 return null;
@@ -189,20 +186,20 @@
189 186 /**
190 187 * @param string $audience optional audience for self-signed JWTs.
191 188 * @return callable Callable function that returns an authorization header.
192 189 */
193 - public function getAuthorizationHeaderCallback($audience = null)
190 + public function getAuthorizationHeaderCallback($audience = null) : ?callable
194 191 {
195 192 // NOTE: changes to this function should be treated carefully and tested thoroughly. It will
196 193 // be passed into the gRPC c extension, and changes have the potential to trigger very
197 194 // difficult-to-diagnose segmentation faults.
198 - return function () use ($audience) {
195 + return function () use($audience) {
199 196 $token = $this->credentialsFetcher->getLastReceivedToken();
200 197 if (self::isExpired($token)) {
201 198 $this->checkUniverseDomain();
202 199 // Call updateMetadata to take advantage of self-signed JWTs
203 200 if ($this->credentialsFetcher instanceof UpdateMetadataInterface) {
204 - return $this->credentialsFetcher->updateMetadata([], $audience);
201 + return $this->credentialsFetcher->updateMetadata([], $audience, $this->authHttpHandler);
205 202 }
206 203 // In case a custom fetcher is provided (unlikely) which doesn't
207 204 // implement UpdateMetadataInterface
208 205 $token = $this->credentialsFetcher->fetchAuthToken($this->authHttpHandler);
@@ -218,30 +215,33 @@
218 215 };
219 216 }
220 217 /**
221 218 * Verify that the expected universe domain matches the universe domain from the credentials.
219 + *
220 + * @throws ValidationException if the universe domain does not match.
222 221 */
223 - public function checkUniverseDomain()
222 + public function checkUniverseDomain() : void
224 223 {
225 - if (\false === $this->hasCheckedUniverse) {
224 + if (\false === $this->hasCheckedUniverse && $this->shouldCheckUniverseDomain()) {
226 225 $credentialsUniverse = $this->credentialsFetcher instanceof GetUniverseDomainInterface ? $this->credentialsFetcher->getUniverseDomain() : GetUniverseDomainInterface::DEFAULT_UNIVERSE_DOMAIN;
227 226 if ($credentialsUniverse !== $this->universeDomain) {
228 - throw new ValidationException(sprintf('The configured universe domain (%s) does not match the credential universe domain (%s)', $this->universeDomain, $credentialsUniverse));
227 + throw new ValidationException(\sprintf('The configured universe domain (%s) does not match the credential universe domain (%s)', $this->universeDomain, $credentialsUniverse));
229 228 }
230 229 $this->hasCheckedUniverse = \true;
231 230 }
232 231 }
233 232 /**
234 - * @return Guzzle6HttpHandler|Guzzle7HttpHandler
235 - * @throws ValidationException
233 + * Skip universe domain check for Metadata server (e.g. GCE) credentials.
234 + *
235 + * @return bool
236 236 */
237 - private static function buildHttpHandlerFactory()
237 + private function shouldCheckUniverseDomain() : bool
238 238 {
239 - try {
240 - return HttpHandlerFactory::build();
241 - } catch (Exception $ex) {
242 - throw new ValidationException("Failed to build HttpHandler", $ex->getCode(), $ex);
239 + $fetcher = $this->credentialsFetcher instanceof FetchAuthTokenCache ? $this->credentialsFetcher->getFetcher() : $this->credentialsFetcher;
240 + if ($fetcher instanceof GCECredentials) {
241 + return \false;
243 242 }
243 + return \true;
244 244 }
245 245 /**
246 246 * @param array $scopes
247 247 * @param callable $authHttpHandler
@@ -251,14 +251,14 @@
251 251 * @param array $defaultScopes
252 252 * @return FetchAuthTokenInterface
253 253 * @throws ValidationException
254 254 */
255 - private static function buildApplicationDefaultCredentials(array $scopes = null, callable $authHttpHandler = null, array $authCacheOptions = null, CacheItemPoolInterface $authCache = null, $quotaProject = null, array $defaultScopes = null)
255 + private static function buildApplicationDefaultCredentials(?array $scopes = null, ?callable $authHttpHandler = null, ?array $authCacheOptions = null, ?CacheItemPoolInterface $authCache = null, $quotaProject = null, ?array $defaultScopes = null)
256 256 {
257 257 try {
258 258 return ApplicationDefaultCredentials::getCredentials($scopes, $authHttpHandler, $authCacheOptions, $authCache, $quotaProject, $defaultScopes);
259 259 } catch (DomainException $ex) {
260 - throw new ValidationException("Could not construct ApplicationDefaultCredentials", $ex->getCode(), $ex);
260 + throw new ValidationException('Could not construct ApplicationDefaultCredentials', $ex->getCode(), $ex);
261 261 }
262 262 }
263 263 /**
264 264 * @param mixed $token
@@ -264,9 +264,9 @@
264 264 * @param mixed $token
265 265 */
266 266 private static function isValid($token)
267 267 {
268 - return is_array($token) && array_key_exists('access_token', $token);
268 + return \is_array($token) && \array_key_exists('access_token', $token);
269 269 }
270 270 /**
271 271 * @param mixed $token
272 272 */
@@ -271,7 +271,7 @@
271 271 * @param mixed $token
272 272 */
273 273 private static function isExpired($token)
274 274 {
275 - return !(self::isValid($token) && array_key_exists('expires_at', $token) && $token['expires_at'] > time() + self::$eagerRefreshThresholdSeconds);
275 + return !(self::isValid($token) && \array_key_exists('expires_at', $token) && $token['expires_at'] > \time() + self::$eagerRefreshThresholdSeconds);
276 276 }
277 277 }