googleapis / googleapis/google-cloud-python

Generate id_token from default credentials

オープン
#15,222 コメント 5 件 リアクション 26 件 担当者 1 名 @arithmetic1728 が担当を希望しています GitHub で見る
priority: p2 type: feature request
主要言語
Python
スター
5.4k
フォーク
1.8k
平均マージ
3日 4時間
マージ済み PR(30日)
122

説明

**Is your feature request related to a problem? Please describe.**

Currently, `google.auth.default()` generates `Credentials` that contain `.token` that is an access token.
We'd like to also generate `id_token` with the appropriate audience starting from default credentials.

This would allow us to submit requests that use `id_token` uniformly among different environments:
- Local Service Account key
- Cloud Functions
- Cloud Run
- App Engine
- GKE Workload Identity

**Describe the solution you'd like**

It would be great to add a method to `google.auth.credentials.Credentials` that allows `id_token` generation, e.g.
```py
credentials.id_token(audience='https://example.org')
```

**Describe alternatives you've considered**
So far, we had to rely on piece-meal approaches, like this example from https://github.com/apache/airflow/blob/master/airflow/providers/google/common/utils/id_token_credentials.py

This unnecessarily increases the complexity of third-party apps, and we have to re-implement the same logic in each one of them.

It would be preferable to incorporate such logic into this library instead.

**Additional context**

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。