Repository navigation
Figure out how to support "usable auth" for gcloud-node #376
Description
Activity
- addedtype: questionRequest for information or clarification. Not an issue.Request for information or clarification. Not an issue.
on Feb 2, 2015 Ideally there would be 1 module that all of auth gets incorporated into. Right now, it's all mixed across
gtoken,google-service-account, among other libraries and implementations. I like the way thatgoogleapiscurrently accomplishes at least the accepting of generic auth objects:var google = require('googleapis'); var OAuth2 = google.auth.OAuth2Client; var JWT = google.auth.JWT; var myAuthClient = new OAuth2(/** ... */); myAuthClient = new JWT(/* ... */); // or use a JWT client myAuthClient = 'SOME API KEY'; // or even a plain API key. var drive = google.drive({ version: 'v2', auth: myAuthClient }); drive.files.insert(options, callback);
So I think it's a matter of removing that auth logic and objects (plus the changes in googleapis/google-api-nodejs-client#354) into a giant epic auth module.
There's a repo in the works here for nodejs auth: https://github.com/google/google-auth-library-nodejs
@jgeewax can you get @stephenplusplus access to this?
I'm in. Thanks!
Just to be clear, what I mean by usable auth here is "if I don't want to think about it in code, I don't have to think about it".
Right now, we have to explicitly define the credentials and whatnot somewhere. If that ever happens, we should use those settings. End of story.
If those aren't set anywhere, we should evaluate things in the following order:
- If I have environment variables for anything credential related, use that.
break; - If I'm in App Engine, use that set of credentials and defaults.
break; - If I'm in Compute Engine, use that set of credentials and defaults.
break;
This means that the "default case" (
var gcloud = require('gcloud');) which previously meant "this still needs to be configured" now means "we'll try the list of stuff, and it might be configured depending on the the environment".In code this means the following should work in GAE, GCE, or if I have the right environment variables set:
var gcloud = require('gcloud'); dataset = gcloud.datastore.dataset(); query = dataset.createQuery('Person'); dataset.runQuery(query, function(...) { ... });
You can still always explicitly override those things later:
// Continued from above, with the same gcloud that *was* configured properly via env var dataset = gcloud.datastore.dataset({ projectId: 'myProject', keyFilename: '/path/to/keyfile.json' }); // Dataset uses another set of explicit credentials.
This may or may not merit a helper method
gcloud.isConfigured()which returns true if and only if the instance ofgcloudis ready to send requests.- If I have environment variables for anything credential related, use that.
This is a good plan, it's just a matter of nailing down the environment variables to look for in all of those environments and any API endpoints/authentication procedures that may change based on the environment.
Here's how
googleapismay be changed to support this: googleapis/google-api-nodejs-client#374Adding here for reference when we want to consider using the same library.
Just FYI, hopefully we can rely on https://github.com/google/google-auth-library-nodejs (
npm install google-auth-library).Do the methods in that library do the thing we want ?
If https://github.com/google/google-auth-library-nodejs has gaps, please add an issue or send a PR. We will respond promptly.
The new library https://github.com/google/google-auth-library-nodejs is defintely the home for this. The default credentials should by fully functional now. If possible, we should try to take a dependency on this library. It should allow you to have a default behavior that uses the ADC under the covers and no credentials as input, and also have way of initializing the service that takes the type returned by this method as an optional input.
36 remaining items
- added a commit that references this issue
on Feb 2, 2026 - added a commit that references this issue
on Feb 3, 2026 - added a commit that references this issue
on Feb 23, 2026 - added 2 commits that reference this issue
on Feb 24, 2026 - added a commit that references this issue
on Feb 26, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 5, 2026 - added a commit that references this issue
on Mar 12, 2026 - added a commit that references this issue
on Mar 18, 2026
See googleapis/google-api-nodejs-client#354
Ideally we would somehow integrate this code. Maybe it means a separate google-authkit-node repository that we depend on ?
/cc @stephenplusplus @ryanseys