blob: afe7dc45dc39f198a143155305187bd5bf67cf2d [file] [log] [blame]
Jon Wayne Parrotta896d2a2016-11-02 23:42:51 -07001# Copyright 2016 Google Inc.
2#
3# Licensed under the Apache License, Version 2.0 (the "License");
4# you may not use this file except in compliance with the License.
5# You may obtain a copy of the License at
6#
7# http://www.apache.org/licenses/LICENSE-2.0
8#
9# Unless required by applicable law or agreed to in writing, software
10# distributed under the License is distributed on an "AS IS" BASIS,
11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
12# See the License for the specific language governing permissions and
13# limitations under the License.
14
15"""Helpers for transitioning from oauth2client to google-auth.
16
17.. warning::
18 This module is private as it is intended to assist first-party downstream
19 clients with the transition from oauth2client to google-auth.
20"""
21
22from __future__ import absolute_import
23
Danny Hermesae5d3a42017-11-09 12:04:14 -080024import six
25
Jon Wayne Parrotta896d2a2016-11-02 23:42:51 -070026from google.auth import _helpers
27import google.auth.app_engine
Teddy Sudola10b15e2018-10-05 10:20:33 -070028import google.auth.compute_engine
Jon Wayne Parrotta896d2a2016-11-02 23:42:51 -070029import google.oauth2.credentials
30import google.oauth2.service_account
31
32try:
33 import oauth2client.client
34 import oauth2client.contrib.gce
35 import oauth2client.service_account
Danny Hermes895e3692017-11-09 11:35:57 -080036except ImportError as caught_exc:
Danny Hermesae5d3a42017-11-09 12:04:14 -080037 six.raise_from(
38 ImportError('oauth2client is not installed.'), caught_exc)
Jon Wayne Parrotta896d2a2016-11-02 23:42:51 -070039
40try:
Teddy Sudola10b15e2018-10-05 10:20:33 -070041 import oauth2client.contrib.appengine # pytype: disable=import-error
Jon Wayne Parrotta896d2a2016-11-02 23:42:51 -070042 _HAS_APPENGINE = True
43except ImportError:
44 _HAS_APPENGINE = False
45
46
47_CONVERT_ERROR_TMPL = (
48 'Unable to convert {} to a google-auth credentials class.')
49
50
51def _convert_oauth2_credentials(credentials):
52 """Converts to :class:`google.oauth2.credentials.Credentials`.
53
54 Args:
55 credentials (Union[oauth2client.client.OAuth2Credentials,
56 oauth2client.client.GoogleCredentials]): The credentials to
57 convert.
58
59 Returns:
60 google.oauth2.credentials.Credentials: The converted credentials.
61 """
62 new_credentials = google.oauth2.credentials.Credentials(
63 token=credentials.access_token,
64 refresh_token=credentials.refresh_token,
65 token_uri=credentials.token_uri,
66 client_id=credentials.client_id,
67 client_secret=credentials.client_secret,
68 scopes=credentials.scopes)
69
70 new_credentials._expires = credentials.token_expiry
71
72 return new_credentials
73
74
75def _convert_service_account_credentials(credentials):
76 """Converts to :class:`google.oauth2.service_account.Credentials`.
77
78 Args:
79 credentials (Union[
80 oauth2client.service_account.ServiceAccountCredentials,
81 oauth2client.service_account._JWTAccessCredentials]): The
82 credentials to convert.
83
84 Returns:
85 google.oauth2.service_account.Credentials: The converted credentials.
86 """
87 info = credentials.serialization_data.copy()
88 info['token_uri'] = credentials.token_uri
89 return google.oauth2.service_account.Credentials.from_service_account_info(
90 info)
91
92
93def _convert_gce_app_assertion_credentials(credentials):
94 """Converts to :class:`google.auth.compute_engine.Credentials`.
95
96 Args:
97 credentials (oauth2client.contrib.gce.AppAssertionCredentials): The
98 credentials to convert.
99
100 Returns:
101 google.oauth2.service_account.Credentials: The converted credentials.
102 """
103 return google.auth.compute_engine.Credentials(
104 service_account_email=credentials.service_account_email)
105
106
107def _convert_appengine_app_assertion_credentials(credentials):
108 """Converts to :class:`google.auth.app_engine.Credentials`.
109
110 Args:
111 credentials (oauth2client.contrib.app_engine.AppAssertionCredentials):
112 The credentials to convert.
113
114 Returns:
115 google.oauth2.service_account.Credentials: The converted credentials.
116 """
117 # pylint: disable=invalid-name
118 return google.auth.app_engine.Credentials(
119 scopes=_helpers.string_to_scopes(credentials.scope),
120 service_account_id=credentials.service_account_id)
121
122
123_CLASS_CONVERSION_MAP = {
124 oauth2client.client.OAuth2Credentials: _convert_oauth2_credentials,
125 oauth2client.client.GoogleCredentials: _convert_oauth2_credentials,
126 oauth2client.service_account.ServiceAccountCredentials:
127 _convert_service_account_credentials,
128 oauth2client.service_account._JWTAccessCredentials:
129 _convert_service_account_credentials,
130 oauth2client.contrib.gce.AppAssertionCredentials:
131 _convert_gce_app_assertion_credentials,
132}
133
134if _HAS_APPENGINE:
135 _CLASS_CONVERSION_MAP[
136 oauth2client.contrib.appengine.AppAssertionCredentials] = (
137 _convert_appengine_app_assertion_credentials)
138
139
140def convert(credentials):
141 """Convert oauth2client credentials to google-auth credentials.
142
143 This class converts:
144
145 - :class:`oauth2client.client.OAuth2Credentials` to
146 :class:`google.oauth2.credentials.Credentials`.
147 - :class:`oauth2client.client.GoogleCredentials` to
148 :class:`google.oauth2.credentials.Credentials`.
149 - :class:`oauth2client.service_account.ServiceAccountCredentials` to
150 :class:`google.oauth2.service_account.Credentials`.
151 - :class:`oauth2client.service_account._JWTAccessCredentials` to
152 :class:`google.oauth2.service_account.Credentials`.
153 - :class:`oauth2client.contrib.gce.AppAssertionCredentials` to
154 :class:`google.auth.compute_engine.Credentials`.
155 - :class:`oauth2client.contrib.appengine.AppAssertionCredentials` to
156 :class:`google.auth.app_engine.Credentials`.
157
158 Returns:
159 google.auth.credentials.Credentials: The converted credentials.
160
161 Raises:
162 ValueError: If the credentials could not be converted.
163 """
164
165 credentials_class = type(credentials)
166
167 try:
168 return _CLASS_CONVERSION_MAP[credentials_class](credentials)
Danny Hermes895e3692017-11-09 11:35:57 -0800169 except KeyError as caught_exc:
170 new_exc = ValueError(_CONVERT_ERROR_TMPL.format(credentials_class))
171 six.raise_from(new_exc, caught_exc)