credentialsFetcher = $credentialsFetcher; $this->authHttpHandler = $authHttpHandler ?: self::buildHttpHandlerFactory(); } /** * Factory method to create a CredentialsWrapper from an array of options. * * @param array $args { * An array of optional arguments. * * @type string|array $keyFile * Credentials to be used. Accepts either a path to a credentials file, or a decoded * credentials file as a PHP array. If this is not specified, application default * credentials will be used. * @type string[] $scopes * A string array of scopes to use when acquiring credentials. * @type callable $authHttpHandler * A handler used to deliver PSR-7 requests specifically * for authentication. Should match a signature of * `function (RequestInterface $request, array $options) : ResponseInterface`. * @type bool $enableCaching * Enable caching of access tokens. Defaults to true. * @type CacheItemPoolInterface $authCache * A cache for storing access tokens. Defaults to a simple in memory implementation. * @type array $authCacheOptions * Cache configuration options. * } * @return CredentialsWrapper * @throws ValidationException */ public static function build(array $args = []) { $args += [ 'keyFile' => null, 'scopes' => null, 'authHttpHandler' => null, 'enableCaching' => true, 'authCache' => null, 'authCacheOptions' => [], ]; $keyFile = $args['keyFile']; $authHttpHandler = $args['authHttpHandler'] ?: self::buildHttpHandlerFactory(); if (is_null($keyFile)) { $loader = self::buildApplicationDefaultCredentials( $args['scopes'], $authHttpHandler ); } else { if (is_string($keyFile)) { if (!file_exists($keyFile)) { throw new ValidationException("Could not find keyfile: $keyFile"); } $keyFile = json_decode(file_get_contents($keyFile), true); } $loader = CredentialsLoader::makeCredentials($args['scopes'], $keyFile); } if ($args['enableCaching']) { $authCache = $args['authCache'] ?: new MemoryCacheItemPool(); $loader = new FetchAuthTokenCache( $loader, $args['authCacheOptions'], $authCache ); } return new CredentialsWrapper($loader, $authHttpHandler); } /** * @return string Bearer string containing access token. */ public function getBearerString() { return 'Bearer ' . self::getToken($this->credentialsFetcher, $this->authHttpHandler); } /** * @return callable Callable function that returns an authorization header. */ public function getAuthorizationHeaderCallback() { $credentialsFetcher = $this->credentialsFetcher; $authHttpHandler = $this->authHttpHandler; // NOTE: changes to this function should be treated carefully and tested thoroughly. It will // be passed into the gRPC c extension, and changes have the potential to trigger very // difficult-to-diagnose segmentation faults. return function () use ($credentialsFetcher, $authHttpHandler) { return ['authorization' => ['Bearer ' . self::getToken($credentialsFetcher, $authHttpHandler)]]; }; } /** * @return Guzzle5HttpHandler|Guzzle6HttpHandler * @throws ValidationException */ private static function buildHttpHandlerFactory() { try { return HttpHandlerFactory::build(); } catch (Exception $ex) { throw new ValidationException("Failed to build HttpHandler", $ex->getCode(), $ex); } } /** * @param array $scopes * @param callable $authHttpHandler * @param array $authCacheOptions * @param CacheItemPoolInterface $authCache * @return CredentialsLoader * @throws ValidationException */ private static function buildApplicationDefaultCredentials( array $scopes = null, callable $authHttpHandler = null, array $authCacheOptions = null, CacheItemPoolInterface $authCache = null ) { try { return ApplicationDefaultCredentials::getCredentials( $scopes, $authHttpHandler, $authCacheOptions, $authCache ); } catch (DomainException $ex) { throw new ValidationException("Could not construct ApplicationDefaultCredentials", $ex->getCode(), $ex); } } private static function getToken($credentialsFetcher, $authHttpHandler) { $token = $credentialsFetcher->getLastReceivedToken(); if (self::isExpired($token)) { $token = $credentialsFetcher->fetchAuthToken($authHttpHandler); if (!self::isValid($token)) { return ''; } } return $token['access_token']; } private static function isValid($token) { return is_array($token) && array_key_exists('access_token', $token); } private static function isExpired($token) { return !(self::isValid($token) && array_key_exists('expires_at', $token) && $token['expires_at'] > time()); } }