feat(transport): Add Device Certificate Authentication support to GRPC (#682)

- Refactor GetClientCertificateSource and GetEndpoint helpers into a common "dca" package to be used by both http and grpc routes.
- Moved endpoint tests to dca_test.go.
- Update GetEndpoint to accept naked "host:port" as URL without merging with DefaultEndpoint. This is needed for GRPC DirectPath scenario, where "DefaultEndpoint" is likely not configured.
4 files changed
tree: 8ce99e70eab7b7e0010b1f471f9226766b3aa5ca
  1. .github/
  2. abusiveexperiencereport/
  3. acceleratedmobilepageurl/
  4. accessapproval/
  5. accesscontextmanager/
  6. adexchangebuyer/
  7. adexchangebuyer2/
  8. adexchangeseller/
  9. adexperiencereport/
  10. admin/
  11. admob/
  12. adsense/
  13. adsensehost/
  14. alertcenter/
  15. analytics/
  16. analyticsadmin/
  17. analyticsdata/
  18. analyticsreporting/
  19. androiddeviceprovisioning/
  20. androidenterprise/
  21. androidmanagement/
  22. androidpublisher/
  23. apigateway/
  24. apigee/
  25. appengine/
  26. appsactivity/
  27. appstate/
  28. artifactregistry/
  29. assuredworkloads/
  30. bigquery/
  31. bigqueryconnection/
  32. bigquerydatatransfer/
  33. bigqueryreservation/
  34. bigtableadmin/
  35. billingbudgets/
  36. binaryauthorization/
  37. blogger/
  38. books/
  39. calendar/
  40. chat/
  41. chromeuxreport/
  42. civicinfo/
  43. classroom/
  44. cloudasset/
  45. cloudbilling/
  46. cloudbuild/
  47. cloudcommerceprocurement/
  48. clouddebugger/
  49. clouderrorreporting/
  50. cloudfunctions/
  51. cloudidentity/
  52. cloudiot/
  53. cloudkms/
  54. cloudprivatecatalog/
  55. cloudprivatecatalogproducer/
  56. cloudprofiler/
  57. cloudresourcemanager/
  58. cloudscheduler/
  59. cloudsearch/
  60. cloudshell/
  61. cloudtasks/
  62. cloudtrace/
  63. commentanalyzer/
  64. composer/
  65. compute/
  66. consumersurveys/
  67. container/
  68. containeranalysis/
  69. content/
  70. customsearch/
  71. datacatalog/
  72. dataflow/
  73. datafusion/
  74. dataproc/
  75. datastore/
  76. deploymentmanager/
  77. dfareporting/
  78. dialogflow/
  79. digitalassetlinks/
  80. discovery/
  81. displayvideo/
  82. dlp/
  83. dns/
  84. docs/
  85. documentai/
  86. domainsrdap/
  87. doubleclickbidmanager/
  88. doubleclicksearch/
  89. drive/
  90. driveactivity/
  91. examples/
  92. factchecktools/
  93. fcm/
  94. file/
  95. firebase/
  96. firebasedynamiclinks/
  97. firebasehosting/
  98. firebaseml/
  99. firebaseremoteconfig/
  100. firebaserules/
  101. firestore/
  102. fitness/
  103. fusiontables/
  104. games/
  105. gamesconfiguration/
  106. gameservices/
  107. gamesmanagement/
  108. genomics/
  109. gmail/
  110. gmailpostmastertools/
  111. google-api-go-generator/
  112. googleapi/
  113. groupsmigration/
  114. groupssettings/
  115. healthcare/
  116. homegraph/
  117. iam/
  118. iamcredentials/
  119. iap/
  120. identitytoolkit/
  121. idtoken/
  122. indexing/
  123. integration-tests/
  124. internal/
  125. iterator/
  126. jobs/
  127. kgsearch/
  128. language/
  129. lib/
  130. libraryagent/
  131. licensing/
  132. lifesciences/
  133. localservices/
  134. logging/
  135. managedidentities/
  136. manufacturers/
  137. memcache/
  138. mirror/
  139. ml/
  140. monitoring/
  141. networkmanagement/
  142. oauth2/
  143. option/
  144. osconfig/
  145. oslogin/
  146. pagespeedonline/
  147. partners/
  148. people/
  149. playablelocations/
  150. playcustomapp/
  151. playmoviespartner/
  152. plus/
  153. plusdomains/
  154. policytroubleshooter/
  155. poly/
  156. prod_tt_sasportal/
  157. proximitybeacon/
  158. pubsub/
  159. pubsublite/
  160. qpxexpress/
  161. realtimebidding/
  162. recommendationengine/
  163. recommender/
  164. redis/
  165. remotebuildexecution/
  166. replicapool/
  167. replicapoolupdater/
  168. reseller/
  169. run/
  170. runtimeconfig/
  171. safebrowsing/
  172. sasportal/
  173. script/
  174. searchconsole/
  175. secretmanager/
  176. securitycenter/
  177. servicebroker/
  178. serviceconsumermanagement/
  179. servicecontrol/
  180. servicedirectory/
  181. servicemanagement/
  182. servicenetworking/
  183. serviceusage/
  184. serviceuser/
  185. sheets/
  186. siteverification/
  187. slides/
  188. smartdevicemanagement/
  189. sourcerepo/
  190. spanner/
  191. spectrum/
  192. speech/
  193. sql/
  194. sqladmin/
  195. storage/
  196. storagetransfer/
  197. streetviewpublish/
  198. sts/
  199. support/
  200. surveys/
  201. tagmanager/
  202. tasks/
  203. testing/
  204. texttospeech/
  205. toolresults/
  206. tpu/
  207. tracing/
  208. trafficdirector/
  209. translate/
  210. transport/
  211. urlshortener/
  212. vault/
  213. vectortile/
  214. verifiedaccess/
  215. videointelligence/
  216. vision/
  217. webfonts/
  218. webmasters/
  219. websecurityscanner/
  220. workflowexecutions/
  221. workflows/
  222. youtube/
  223. youtubeanalytics/
  224. youtubereporting/
  225. .gitignore
  226. .hgtags
  227. api-list.json
  228. AUTHORS
  229. CHANGES.md
  230. CONTRIBUTING.md
  231. CONTRIBUTORS
  232. doc.go
  233. GettingStarted.md
  234. go.mod
  235. go.sum
  236. LICENSE
  237. license_test.go
  238. NOTES
  239. README.md
  240. RELEASING.md
  241. synth.metadata
  242. synth.py
  243. TODO
  244. tools.go
README.md

Google APIs Client Library for Go

Getting Started

$ go get google.golang.org/api/tasks/v1
$ go get google.golang.org/api/moderator/v1
$ go get google.golang.org/api/urlshortener/v1
... etc ...

and using:

package main

import (
	"net/http"

	"google.golang.org/api/urlshortener/v1"
)

func main() {
	svc, err := urlshortener.New(http.DefaultClient)
	// ...
}

Status

GoDoc

These are auto-generated Go libraries from the Google Discovery Service's JSON description files of the available “new style” Google APIs.

Due to the auto-generated nature of this collection of libraries, complete APIs or specific versions can appear or go away without notice. As a result, you should always locally vendor any API(s) that your code relies upon.

These client libraries are officially supported by Google. However, the libraries are considered complete and are in maintenance mode. This means that we will address critical bugs and security issues but will not add any new features.

If you're working with Google Cloud Platform APIs such as Datastore or Pub/Sub, consider using the Cloud Client Libraries for Go instead. These are the new and idiomatic Go libraries targeted specifically at Google Cloud Platform Services.

The generator itself and the code it produces are beta. Some APIs are alpha/beta, and indicated as such in the import path (e.g., “google.golang.org/api/someapi/v1alpha”).

Application Default Credentials Example

Application Default Credentials provide a simplified way to obtain credentials for authenticating with Google APIs.

The Application Default Credentials authenticate as the application itself, which make them great for working with Google Cloud APIs like Storage or Datastore. They are the recommended form of authentication when building applications that run on Google Compute Engine or Google App Engine.

Default credentials are provided by the golang.org/x/oauth2/google package. To use them, add the following import:

import "golang.org/x/oauth2/google"

Some credentials types require you to specify scopes, and service entry points may not inject them. If you encounter this situation you may need to specify scopes as follows:

import (
        "context"
        "golang.org/x/oauth2/google"
        "google.golang.org/api/compute/v1"
)

func main() {
        // Use oauth2.NoContext if there isn't a good context to pass in.
        ctx := context.Background()

        client, err := google.DefaultClient(ctx, compute.ComputeScope)
        if err != nil {
                //...
        }
        computeService, err := compute.New(client)
        if err != nil {
                //...
        }
}

If you need a oauth2.TokenSource, use the DefaultTokenSource function:

ts, err := google.DefaultTokenSource(ctx, scope1, scope2, ...)
if err != nil {
        //...
}
client := oauth2.NewClient(ctx, ts)

See also: golang.org/x/oauth2/google package documentation.