google / google/oauth2l

Fall back to gcloud session if application_default_credentials.json is invalid/expired

Open
#171 3 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
737
Forks
95
Avg merge
10h 38m
Merged PRs (30d)
2

Description

If `~/.config/gcloud/application_default_credentials.json` exists and is invalid, oauth2l will always fail, even if I log in to gcloud using `gcloud auth login`.

This is quite annoying, since it is quite common for stale `~/.config/gcloud/application_default_credentials.json` to be hanging around (i.e. if I ran `gcloud auth login --update-adc` yesterday, but later logged in today without `--update-adc`). In my company, `application_default_credentials.json` that are fetched in this way expire relatively quickly (24 hours or less).

It would be very convenient if `oauth2l` did some or all of the following:

- fall back to the non-application-default gcloud session if application_default_credentials.json fail
- add a flag to make oauth2l ignore application_default_credentials.json
- change the priority order, so that a gcloud session is preferred over application_default_credentials.json

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.