`google.api.Service` config seems to require an audience to avoid JWT validation errors
Mantenedores costumam responder em até 5 dias
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 2/5
- Tempo estimado
- 1-3 horas
- Facilidade para iniciantes
- 38/100
- Tipo de issue
- Bug
- Clareza
- Claramente especificada
- Status de atividade
- Estagnada
- Stack de tecnologia
- python
- Domínio
- api, authentication
Direção de pesquisa
Comece por endpoints/bookstore-grpc/api_config_auth.yaml e endpoints/bookstore-grpc-transcoding/api_config_auth.yaml e, em seguida, examine jwt_token_gen.py e bookstore_client.py quanto ao fluxo de autenticação. Reproduza a solicitação JWT descrita na issue e verifique se ambas as configurações de serviço aceitam a autenticação pretendida da conta de serviço sem o erro de validação do audience.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
In which file did you encounter the issue?
Did you change the file? If so, how?
Yes, in the following section of the files:
#
# Request authentication.
#
authentication:
providers:
- id: google_service_account
# Replace SERVICE-ACCOUNT-ID with your service account's email address.
issuer: SERVICE-ACCOUNT-ID
jwks_uri: https://www.googleapis.com/robot/v1/metadata/x509/SERVICE-ACCOUNT-ID
rules:
# This auth rule will apply to all methods.
- selector: "*"
requirements:
- provider_id: google_service_account
I added an audience field to the config:
#
# Request authentication.
#
authentication:
providers:
- id: google_service_account
# Replace SERVICE-ACCOUNT-ID with your service account's email address.
issuer: SERVICE-ACCOUNT-ID
jwks_uri: https://www.googleapis.com/robot/v1/metadata/x509/SERVICE-ACCOUNT-ID
audiences: DEFAULT_HOSTNAME
rules:
# This auth rule will apply to all methods.
- selector: "*"
requirements:
- provider_id: google_service_account
Describe the issue
When using current api_config_auth.yaml for service-account JWT authentication I continued to get "{"message":"Audiences in Jwt are not allowed","code":403}". This error was present regardless of whether the JWT I passed had an audience. I used jwt_token_gen.py to generate the JWTs to pass when reaching out to the api python3 bookstore_client.py --auth_token JWT_TOKEN --host= DEFAULT_HOSTNAME --port 443 --use_tls true.
To generate a JWT without an audience field I commented out the 'aud' portion of the payload in jwt_token_gen.py . I tried without an audience and with the service name as an audience and each test provided the same error message. I inspected each JWT in jwt.io to ensure that each JWT claim was how I expected.
Overall, I suspect the google.api.Service spec has a different behavior for expected audiences than the OpenAPI spec (which doesn't required audience). Adding audience to the config resolved the issue and allowed me to hit the API with service-account JWT authentication enabled. Willing to create a PR to incorporate audiences: DEFAULT_HOSTNAME if approved 👍
- Linguagem predominante
- Jupyter Notebook
- Estrelas
- 8.1k
- Forks
- 6.7k
- Merge médio
- 4d 12h
- PRs com merge (30d)
- 9
Preparar o ambiente
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de GoogleCloudPlatform/python-docs-samples
-
samples
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
GoogleCloudPlatform/python-docs-samples#14609 ·
Mantenedores costumam responder em até 5 dias
-
samples
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 92/100
GoogleCloudPlatform/python-docs-samples#14610 ·
Mantenedores costumam responder em até 5 dias
-
samples
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
GoogleCloudPlatform/python-docs-samples#14611 ·
Mantenedores costumam responder em até 5 dias
-
chore(generative_ai) Update model references for generative_ai samplesTalvez livre de novo @XrossFox assumiu há 154 dias e não há nenhum pull request aberto. Abertasamples
GoogleCloudPlatform/python-docs-samples#14117 · 1 responsável ·
Mantenedores costumam responder em até 5 dias
-
Fix Pipeline dependency issues for geospatial-classification/serving_appTalvez livre de novo @XrossFox assumiu há 166 dias e não há nenhum pull request aberto. Abertasamples
GoogleCloudPlatform/python-docs-samples#14091 · 1 responsável ·
Mantenedores costumam responder em até 5 dias
Todas as issues de GoogleCloudPlatform/python-docs-samples
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
SciML/Evolutionary.jl#182 ·
Mantenedores costumam responder em até 1 dia
-
Missing GLM modelsAberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
simonw/llm-mistral#43 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
rossoctl/context-guru#346 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
prime-radiant-inc/evener#2883 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
GoogleChromeLabs/project-sesame#216 ·
Mantenedores costumam responder em até 12 dias