-
Notifications
You must be signed in to change notification settings - Fork 2.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
AWS, Core, GCP: Support relative credential endpoint / pass OAuth2 token to credential provider #11954
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
90f7152
to
71cde42
Compare
71cde42
to
e555a96
Compare
creechy
reviewed
Jan 13, 2025
Minor comments and we should add a description, but LGTM. |
e555a96
to
1212bc0
Compare
1212bc0
to
362bf01
Compare
danielcweeks
approved these changes
Jan 14, 2025
a2dccd1
to
3d42850
Compare
…ken to credential provider
3d42850
to
ad6b255
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The goal of this PR is to improve the credential URI / token handling when a server sends back properties to a client in order to indicate that refreshing vended credentials is supported. In detail, the following things are improved here:
credentials.uri
. However, the catalog URI itself is already passed via the properties and so having support for a relative credential path can make things easier for servers. This is being changed for S3 + GCP in this PR.VendedCredentialsProvider
(specific to S3) currently requires the OAuth2 token to be passed viaclient.credentials-provider.token
in order to be properly passed down fromAwsClientProperties
to theVendedCredentialsProvider
. This is being simplified in this PR so that the same OAuth2 token is passed down toVendedCredentialsProvider
that already exists in the properties undertoken
. Note thatclient.credentials-provider.token
still takes precedence in case that property exists