Coder Social home page Coder Social logo

goth's Introduction

Build Status

Goth

Google + Auth = Goth

A simple library to generate and retrieve OAuth2 tokens for use with Google Cloud Service accounts.

It can either retrieve tokens using service account credentials or from Google's metadata service for applications running on Google Cloud Platform.

Installation

  1. Add Goth to your list of dependencies in mix.exs:
def deps do
  [{:goth, "~> 0.8.0"}]
end
  1. Pass in your credentials json downloaded from your GCE account:
config :goth,
  json: "path/to/google/json/creds.json" |> File.read!

Or, via an ENV var:

config :goth, json: {:system, "GCP_CREDENTIALS"}

Or, via your own config module:

config :goth, config_module: MyConfigMod
defmodule MyConfigMod do
  use Goth.Config

  def init(config) do
    {:ok, Keyword.put(config, :json, System.get_env("MY_GCP_JSON_CREDENTIALS"))}
  end
end

You can also use a JSON file containing an array of service accounts to be able to use different identities in your application. Each service account will be identified by its client_email, which can be passed to Goth.Token.for_scope/1 to specify which service account to use.

For example, if your JSON file contains the following:

[
  {
    "client_email": "[email protected]",
    ...
  },
  {
    "client_email": "[email protected]",
    ...
  }
]

You can use the following to get a token for the second service account:

def get_token do
  {:ok, token} = Goth.Token.for_scope({
    "[email protected]",
    "https://www.googleapis.com/auth/cloud-platform.read-only"})
end

You can skip the last step if your application will run on a GCP or GKE instance with appropriate permissions.

If you need to set the email account to impersonate. For example when using service accounts

config :goth,
  json: {:system, "GCP_CREDENTIALS"},
  actor_email: "[email protected]"

Alternatively, you can pass your sub email on a per-call basis, for example:

Goth.Token.for_scope("https://www.googleapis.com/auth/pubsub",
                     "[email protected]")

If you need to disable Goth in certain environments, you can set a disabled flag in your config:

config :goth,
  disabled: true

This initializes Goth with an empty config, so any attempts to actually generate tokens will fail.

Usage

Retrieve a token:

Call Token.for_scope/1 passing in a string of scopes, separated by a space:

alias Goth.Token
{:ok, token} = Token.for_scope("https://www.googleapis.com/auth/pubsub")
#=>
  %Goth.Token{
    expires: 1453356568,
    token: "ya29.cALlJ4ICWRvMkYB-WsAR-CZnExE459PA7QPqKg5nei9y2T9-iqmbcgxq8XrTATNn_BPim",
    type: "Bearer"
  }

goth's People

Contributors

peburrows avatar tazjin avatar dazuma avatar p42ul avatar gonzooo avatar stratus3d avatar amuino avatar apognu avatar arrel avatar hassox avatar rubas avatar tsubery avatar magnetised avatar leapingfrogs avatar jordanadams avatar nitinstp23 avatar jayjun avatar sadraskol avatar yuyabee avatar

Watchers

James Cloos avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.