Skip to content

Figure out how to support "usable auth" for gcloud-node #376

Description

@jgeewax

See googleapis/google-api-nodejs-client#354

Ideally we would somehow integrate this code. Maybe it means a separate google-authkit-node repository that we depend on ?

/cc @stephenplusplus @ryanseys

Activity

  1. added this to the Core Stable milestone on Feb 2, 2015
  2. ryanseys commented on Feb 8, 2015

    @ryanseys
    Contributor

    Ideally there would be 1 module that all of auth gets incorporated into. Right now, it's all mixed across gtoken, google-service-account, among other libraries and implementations. I like the way that googleapis currently accomplishes at least the accepting of generic auth objects:

    var google  = require('googleapis');
    var OAuth2 = google.auth.OAuth2Client;
    var JWT = google.auth.JWT;
    var myAuthClient = new OAuth2(/** ...  */);
    myAuthClient = new JWT(/* ... */); // or use a JWT client
    myAuthClient = 'SOME API KEY'; // or even a plain API key.
    
    var drive = google.drive({ version: 'v2', auth: myAuthClient });
    drive.files.insert(options, callback);

    So I think it's a matter of removing that auth logic and objects (plus the changes in googleapis/google-api-nodejs-client#354) into a giant epic auth module.

  3. ryanseys commented on Feb 13, 2015

    @ryanseys
    Contributor

    There's a repo in the works here for nodejs auth: https://github.com/google/google-auth-library-nodejs

    @jgeewax can you get @stephenplusplus access to this?

  4. stephenplusplus commented on Feb 16, 2015

    @stephenplusplus
    Contributor

    I'm in. Thanks!

  5. jgeewax commented on Feb 17, 2015

    @jgeewax
    ContributorAuthor

    Just to be clear, what I mean by usable auth here is "if I don't want to think about it in code, I don't have to think about it".

    Right now, we have to explicitly define the credentials and whatnot somewhere. If that ever happens, we should use those settings. End of story.

    If those aren't set anywhere, we should evaluate things in the following order:

    1. If I have environment variables for anything credential related, use that. break;
    2. If I'm in App Engine, use that set of credentials and defaults. break;
    3. If I'm in Compute Engine, use that set of credentials and defaults. break;

    This means that the "default case" (var gcloud = require('gcloud');) which previously meant "this still needs to be configured" now means "we'll try the list of stuff, and it might be configured depending on the the environment".

    In code this means the following should work in GAE, GCE, or if I have the right environment variables set:

    var gcloud = require('gcloud');
    dataset = gcloud.datastore.dataset();
    query = dataset.createQuery('Person');
    dataset.runQuery(query, function(...) { ... });

    You can still always explicitly override those things later:

    // Continued from above, with the same gcloud that *was* configured properly via env
    var dataset = gcloud.datastore.dataset({
      projectId: 'myProject',
      keyFilename: '/path/to/keyfile.json'
    });
    // Dataset uses another set of explicit credentials.

    This may or may not merit a helper method gcloud.isConfigured() which returns true if and only if the instance of gcloud is ready to send requests.

  6. stephenplusplus commented on Feb 18, 2015

    @stephenplusplus
    Contributor

    This is a good plan, it's just a matter of nailing down the environment variables to look for in all of those environments and any API endpoints/authentication procedures that may change based on the environment.

  7. ryanseys commented on Feb 24, 2015

    @ryanseys
    Contributor

    Here's how googleapis may be changed to support this: googleapis/google-api-nodejs-client#374

    Adding here for reference when we want to consider using the same library.

  8. jgeewax commented on Mar 6, 2015

    @jgeewax
    ContributorAuthor

    Just FYI, hopefully we can rely on https://github.com/google/google-auth-library-nodejs (npm install google-auth-library).

    Do the methods in that library do the thing we want ?

  9. tbetbetbe commented on Mar 6, 2015

    @tbetbetbe

    If https://github.com/google/google-auth-library-nodejs has gaps, please add an issue or send a PR. We will respond promptly.

  10. anthmgoogle commented on Mar 9, 2015

    @anthmgoogle

    The new library https://github.com/google/google-auth-library-nodejs is defintely the home for this. The default credentials should by fully functional now. If possible, we should try to take a dependency on this library. It should allow you to have a default behavior that uses the ADC under the covers and no credentials as input, and also have way of initializing the service that takes the type returned by this method as an optional input.

  11. 36 remaining items

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

coretype: questionRequest for information or clarification. Not an issue.

Type

No type

Projects

No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions