Skip to content

MyCustomerSecretKey is missing secret_key (secretKey) #768

Description

@jeliker1

Model MyCustomerSecretKey does not include secret_key attribute though it is absolutely returned from the API. I see secret_key is included in CustomerSecretKey model. In both cases the API documentation does not show secret_key is a return value though it absolutely is. Frankly, if it were not in the return the API would be pointless as creating a new key without being able to retrieve the new value is of no use.

Consider this example:

identity_domain_client = oci.identity_domains.IdentityDomainsClient(
    config, signer=signer, service_endpoint=domain.url
)
new_key = oci.identity_domains.models.MyCustomerSecretKey(
    display_name="SDK",
    schemas=["urn:ietf:params:scim:schemas:oracle:idcs:customerSecretKey"],
)
resp = identity_domain_client.create_my_customer_secret_key(
    my_customer_secret_key=new_key,
)

resp.data.display_name
'SDK'

resp.data.access_key
'bc8309f45128a4658b18d38fff3997d605d7c380'

resp.data.secret_key
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
AttributeError: 'MyCustomerSecretKey' object has no attribute 'secret_key'

…however, this works:

endpoint = "/admin/v1/MyCustomerSecretKeys"
body = {
    "displayName": "REST",
    "schemas": ["urn:ietf:params:scim:schemas:oracle:idcs:customerSecretKey"],
}
resp = requests.post(domain.url + endpoint, auth=signer, json=body)
jsonresp = json.loads(resp.content)

jsonresp["displayName"]
'REST'

jsonresp["accessKey"]
'e74aec6e2317b972691986696403f0b175f60880'

jsonresp["secretKey"]
'tXaYYB0gFUF2/4UthIyYZqCh4Y5tQ3Sp2lxVJKvF+RI='

…so obviously the value for secretKey (or secret_key) should be in the response (as I say, otherwise, what's the point of creating the key?).

Activity

  1. adizohar commented on May 27, 2025

    @adizohar
    Member
  2. github-anurag commented on May 27, 2025

    @github-anurag
    Contributor

    @jeliker1
    The response from the API should have the secretKey. What version of the OCI Python SDK are you using? Can you check if the issue goes away after upgrading the SDK version?
    Refer Docs: CustomerSecretKey

  3. github-anurag commented on May 27, 2025

    @github-anurag
    Contributor

    Thanks for the pull request @jeliker1. As mentioned in the Pull reuqest, this is an auto-generated file based on the spec provided by the service team. I will follow up with the service team that owns this API to fix this in their spec. In the meanwhile can you please use the workaround suggested by @adizohar

  4. jeliker1 commented on May 27, 2025

    @jeliker1
    Author

    @github-anurag I'm using 2.153.0. Definitely API does have the value in raw response, but since secretKey is not in the MyCustomerSecretKey model it's not be propagated to the SDK response. See my pull request #769 which is to simply add the missing attributes. Also, noteworthy that model CustomerSecretKey (which you reference) does have the secretKey value but MyCustomerSecretKey did not (until my contribution). However, API call to create MyCustomerSecretKey (/admin/v1/MyCustomerSecretKeys) does indeed return the secretKey attribute (though SDK response does not).

    See here: MyCustomerSecretKey

  5. jeliker1 commented on May 27, 2025

    @jeliker1
    Author

    You can try to fetch the key after creation using get_customer_secret_key(customer_secret_key_id) https://docs.oracle.com/en-us/iaas/tools/python/2.152.1/api/identity_domains/models/oci.identity_domains.models.CustomerSecretKey.html#oci.identity_domains.models.CustomerSecretKey

    Does not appear that is retrievable

    identity_domain_client = oci.identity_domains.IdentityDomainsClient(
        config, signer=signer, service_endpoint=domain.url
    )
    new_key = oci.identity_domains.models.MyCustomerSecretKey(
        display_name="SDK",
        schemas=["urn:ietf:params:scim:schemas:oracle:idcs:customerSecretKey"],
    )
    resp = identity_domain_client.create_my_customer_secret_key(
        my_customer_secret_key=new_key,
    )
    
    resp.data.display_name
    'SDK'
    
    resp.data.id
    '15a4dfb6489fa82b366095fa9e034e0b'
    
    resp2 = identity_domain_client.get_my_customer_secret_key(
        my_customer_secret_key_id = resp.data.id
    )
    
    resp2.data.id
    '15a4dfb6489fa82b366095fa9e034e0b'
    
    resp2.data.secret_key
    
    resp2.data.access_key
    'dba5a6811c08221d28cbedf45c9a46a65c730a79'
    
    resp3 = identity_domain_client.get_customer_secret_key(
        customer_secret_key_id = resp.data.id,
        attributes = 'access_key,display_name,id,secret_key',
        attribute_sets = ['all']
    )
    
    resp3.data.access_key
    'dba5a6811c08221d28cbedf45c9a46a65c730a79'
    
    resp3.data.secret_key
    
    resp3.data.display_name
    'SDK'
    
    resp3.data.id
    '15a4dfb6489fa82b366095fa9e034e0b'
  6. adizohar commented on May 27, 2025

    @adizohar
    Member

    Thank you for checking the retrieval, the team will fix the secret_key in the create secret code.

  7. jeliker1 commented on May 27, 2025

    @jeliker1
    Author

    @github-anurag I'm using 2.153.0. Definitely API does have the value in raw response, but since secretKey is not in the MyCustomerSecretKey model it's not be propagated to the SDK response. See my pull request #769 which is to simply add the missing attributes. Also, noteworthy that model CustomerSecretKey (which you reference) does have the secretKey value but MyCustomerSecretKey did not (until my contribution). However, API call to create MyCustomerSecretKey (/admin/v1/MyCustomerSecretKeys) does indeed return the secretKey attribute (though SDK response does not).

    See here: MyCustomerSecretKey

    Odd too that you say the model I updated comes from services team. Why then do you think CustomerSecretKey model correctly includes secret_key attribute but MyCustomerSecretKey does not include secret_key? When I check public docs I see that neither CustomerSecretKey nor MyCustomerSecretKey shows secretKey attribute though both should and do return that attribute:

  8. github-anurag commented on May 27, 2025

    @github-anurag
    Contributor

    @jeliker1
    You are correct, the public API docs do not mention the SecretKey in either CustomerSecretKey or MyCustomerSecretKey . I was referring the Python SDK code and docs
    Refer code: customer_secret_key model

    I have contacted the service team on this issue. The model needs to be fixed via the spec unfortunately, as any manual change would get overridden in the next release.

  9. jeliker1 commented on May 28, 2025

    @jeliker1
    Author

    @jeliker1 You are correct, the public API docs do not mention the SecretKey in either CustomerSecretKey or MyCustomerSecretKey . I was referring the Python SDK code and docs Refer code: customer_secret_key model

    I have contacted the service team on this issue. The model needs to be fixed via the spec unfortunately, as any manual change would get overridden in the next release.

    Thank you for following up on this with me! I hope this isn't too big a change to hope for! Seems like a straightforward "correction" but I'm not sure the API team will agree. Again, hopefully they will… 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Identity DomainsIssue pertains to the Identity Domains service

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions