Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix: use source credential expiration when STS does not return expires_in #699

Merged
merged 8 commits into from
Jul 26, 2021
Merged

Conversation

lsirac
Copy link
Contributor

@lsirac lsirac commented Jul 22, 2021

For the CAB flow, STS only returns expires_in if the source access token belongs to a service account.
For other source credential types, we can copy the source credentials expiration as the generated downscoped token
will always have the same expiration time as the source credentials.

TimurSadykov and others added 6 commits July 7, 2021 12:42
ServiceAccountCredentials tests for 4110
* feat: self signed jwt support

* update

* address comments

* allow to use uri as audience

* address comments
@lsirac lsirac requested a review from a team as a code owner July 22, 2021 17:39
@google-cla google-cla bot added the cla: yes This human has signed the Contributor License Agreement. label Jul 22, 2021
@lsirac lsirac requested a review from TimurSadykov July 22, 2021 17:50
@lsirac lsirac merged commit 4b23843 into googleapis:cab Jul 26, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
cla: yes This human has signed the Contributor License Agreement.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants