您最多选择25个主题 主题必须以字母或数字开头,可以包含连字符 (-),并且长度不得超过35个字符
 
 
 

215 行
8.5 KiB

  1. // Copyright 2019 Google LLC
  2. //
  3. // Licensed under the Apache License, Version 2.0 (the "License");
  4. // you may not use this file except in compliance with the License.
  5. // You may obtain a copy of the License at
  6. //
  7. // https://www.apache.org/licenses/LICENSE-2.0
  8. //
  9. // Unless required by applicable law or agreed to in writing, software
  10. // distributed under the License is distributed on an "AS IS" BASIS,
  11. // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  12. // See the License for the specific language governing permissions and
  13. // limitations under the License.
  14. // Code generated by gapic-generator. DO NOT EDIT.
  15. package credentials
  16. import (
  17. "context"
  18. "time"
  19. gax "github.com/googleapis/gax-go/v2"
  20. "google.golang.org/api/option"
  21. "google.golang.org/api/transport"
  22. credentialspb "google.golang.org/genproto/googleapis/iam/credentials/v1"
  23. "google.golang.org/grpc"
  24. "google.golang.org/grpc/codes"
  25. "google.golang.org/grpc/metadata"
  26. )
  27. // IamCredentialsCallOptions contains the retry settings for each method of IamCredentialsClient.
  28. type IamCredentialsCallOptions struct {
  29. GenerateAccessToken []gax.CallOption
  30. GenerateIdToken []gax.CallOption
  31. SignBlob []gax.CallOption
  32. SignJwt []gax.CallOption
  33. GenerateIdentityBindingAccessToken []gax.CallOption
  34. }
  35. func defaultIamCredentialsClientOptions() []option.ClientOption {
  36. return []option.ClientOption{
  37. option.WithEndpoint("iamcredentials.googleapis.com:443"),
  38. option.WithScopes(DefaultAuthScopes()...),
  39. }
  40. }
  41. func defaultIamCredentialsCallOptions() *IamCredentialsCallOptions {
  42. retry := map[[2]string][]gax.CallOption{
  43. {"default", "idempotent"}: {
  44. gax.WithRetry(func() gax.Retryer {
  45. return gax.OnCodes([]codes.Code{
  46. codes.DeadlineExceeded,
  47. codes.Unavailable,
  48. }, gax.Backoff{
  49. Initial: 100 * time.Millisecond,
  50. Max: 60000 * time.Millisecond,
  51. Multiplier: 1.3,
  52. })
  53. }),
  54. },
  55. }
  56. return &IamCredentialsCallOptions{
  57. GenerateAccessToken: retry[[2]string{"default", "idempotent"}],
  58. GenerateIdToken: retry[[2]string{"default", "idempotent"}],
  59. SignBlob: retry[[2]string{"default", "idempotent"}],
  60. SignJwt: retry[[2]string{"default", "idempotent"}],
  61. GenerateIdentityBindingAccessToken: retry[[2]string{"default", "idempotent"}],
  62. }
  63. }
  64. // IamCredentialsClient is a client for interacting with IAM Service Account Credentials API.
  65. //
  66. // Methods, except Close, may be called concurrently. However, fields must not be modified concurrently with method calls.
  67. type IamCredentialsClient struct {
  68. // The connection to the service.
  69. conn *grpc.ClientConn
  70. // The gRPC API client.
  71. iamCredentialsClient credentialspb.IAMCredentialsClient
  72. // The call options for this service.
  73. CallOptions *IamCredentialsCallOptions
  74. // The x-goog-* metadata to be sent with each request.
  75. xGoogMetadata metadata.MD
  76. }
  77. // NewIamCredentialsClient creates a new iam credentials client.
  78. //
  79. // A service account is a special type of Google account that belongs to your
  80. // application or a virtual machine (VM), instead of to an individual end user.
  81. // Your application assumes the identity of the service account to call Google
  82. // APIs, so that the users aren't directly involved.
  83. //
  84. // Service account credentials are used to temporarily assume the identity
  85. // of the service account. Supported credential types include OAuth 2.0 access
  86. // tokens, OpenID Connect ID tokens, self-signed JSON Web Tokens (JWTs), and
  87. // more.
  88. func NewIamCredentialsClient(ctx context.Context, opts ...option.ClientOption) (*IamCredentialsClient, error) {
  89. conn, err := transport.DialGRPC(ctx, append(defaultIamCredentialsClientOptions(), opts...)...)
  90. if err != nil {
  91. return nil, err
  92. }
  93. c := &IamCredentialsClient{
  94. conn: conn,
  95. CallOptions: defaultIamCredentialsCallOptions(),
  96. iamCredentialsClient: credentialspb.NewIAMCredentialsClient(conn),
  97. }
  98. c.setGoogleClientInfo()
  99. return c, nil
  100. }
  101. // Connection returns the client's connection to the API service.
  102. func (c *IamCredentialsClient) Connection() *grpc.ClientConn {
  103. return c.conn
  104. }
  105. // Close closes the connection to the API service. The user should invoke this when
  106. // the client is no longer required.
  107. func (c *IamCredentialsClient) Close() error {
  108. return c.conn.Close()
  109. }
  110. // setGoogleClientInfo sets the name and version of the application in
  111. // the `x-goog-api-client` header passed on each request. Intended for
  112. // use by Google-written clients.
  113. func (c *IamCredentialsClient) setGoogleClientInfo(keyval ...string) {
  114. kv := append([]string{"gl-go", versionGo()}, keyval...)
  115. kv = append(kv, "gapic", versionClient, "gax", gax.Version, "grpc", grpc.Version)
  116. c.xGoogMetadata = metadata.Pairs("x-goog-api-client", gax.XGoogHeader(kv...))
  117. }
  118. // GenerateAccessToken generates an OAuth 2.0 access token for a service account.
  119. func (c *IamCredentialsClient) GenerateAccessToken(ctx context.Context, req *credentialspb.GenerateAccessTokenRequest, opts ...gax.CallOption) (*credentialspb.GenerateAccessTokenResponse, error) {
  120. ctx = insertMetadata(ctx, c.xGoogMetadata)
  121. opts = append(c.CallOptions.GenerateAccessToken[0:len(c.CallOptions.GenerateAccessToken):len(c.CallOptions.GenerateAccessToken)], opts...)
  122. var resp *credentialspb.GenerateAccessTokenResponse
  123. err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
  124. var err error
  125. resp, err = c.iamCredentialsClient.GenerateAccessToken(ctx, req, settings.GRPC...)
  126. return err
  127. }, opts...)
  128. if err != nil {
  129. return nil, err
  130. }
  131. return resp, nil
  132. }
  133. // GenerateIdToken generates an OpenID Connect ID token for a service account.
  134. func (c *IamCredentialsClient) GenerateIdToken(ctx context.Context, req *credentialspb.GenerateIdTokenRequest, opts ...gax.CallOption) (*credentialspb.GenerateIdTokenResponse, error) {
  135. ctx = insertMetadata(ctx, c.xGoogMetadata)
  136. opts = append(c.CallOptions.GenerateIdToken[0:len(c.CallOptions.GenerateIdToken):len(c.CallOptions.GenerateIdToken)], opts...)
  137. var resp *credentialspb.GenerateIdTokenResponse
  138. err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
  139. var err error
  140. resp, err = c.iamCredentialsClient.GenerateIdToken(ctx, req, settings.GRPC...)
  141. return err
  142. }, opts...)
  143. if err != nil {
  144. return nil, err
  145. }
  146. return resp, nil
  147. }
  148. // SignBlob signs a blob using a service account's system-managed private key.
  149. func (c *IamCredentialsClient) SignBlob(ctx context.Context, req *credentialspb.SignBlobRequest, opts ...gax.CallOption) (*credentialspb.SignBlobResponse, error) {
  150. ctx = insertMetadata(ctx, c.xGoogMetadata)
  151. opts = append(c.CallOptions.SignBlob[0:len(c.CallOptions.SignBlob):len(c.CallOptions.SignBlob)], opts...)
  152. var resp *credentialspb.SignBlobResponse
  153. err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
  154. var err error
  155. resp, err = c.iamCredentialsClient.SignBlob(ctx, req, settings.GRPC...)
  156. return err
  157. }, opts...)
  158. if err != nil {
  159. return nil, err
  160. }
  161. return resp, nil
  162. }
  163. // SignJwt signs a JWT using a service account's system-managed private key.
  164. func (c *IamCredentialsClient) SignJwt(ctx context.Context, req *credentialspb.SignJwtRequest, opts ...gax.CallOption) (*credentialspb.SignJwtResponse, error) {
  165. ctx = insertMetadata(ctx, c.xGoogMetadata)
  166. opts = append(c.CallOptions.SignJwt[0:len(c.CallOptions.SignJwt):len(c.CallOptions.SignJwt)], opts...)
  167. var resp *credentialspb.SignJwtResponse
  168. err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
  169. var err error
  170. resp, err = c.iamCredentialsClient.SignJwt(ctx, req, settings.GRPC...)
  171. return err
  172. }, opts...)
  173. if err != nil {
  174. return nil, err
  175. }
  176. return resp, nil
  177. }
  178. // GenerateIdentityBindingAccessToken exchange a JWT signed by third party identity provider to an OAuth 2.0
  179. // access token
  180. func (c *IamCredentialsClient) GenerateIdentityBindingAccessToken(ctx context.Context, req *credentialspb.GenerateIdentityBindingAccessTokenRequest, opts ...gax.CallOption) (*credentialspb.GenerateIdentityBindingAccessTokenResponse, error) {
  181. ctx = insertMetadata(ctx, c.xGoogMetadata)
  182. opts = append(c.CallOptions.GenerateIdentityBindingAccessToken[0:len(c.CallOptions.GenerateIdentityBindingAccessToken):len(c.CallOptions.GenerateIdentityBindingAccessToken)], opts...)
  183. var resp *credentialspb.GenerateIdentityBindingAccessTokenResponse
  184. err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
  185. var err error
  186. resp, err = c.iamCredentialsClient.GenerateIdentityBindingAccessToken(ctx, req, settings.GRPC...)
  187. return err
  188. }, opts...)
  189. if err != nil {
  190. return nil, err
  191. }
  192. return resp, nil
  193. }