Repository navigation
Is it possible to use ApplicationDefaultCredentials for SignUrlOption? #701
Description
Activity
I think there should be an interface for Credentials and use it as the argument, just my 2 cents
- addedapi: storageIssues related to the Cloud Storage API.Issues related to the Cloud Storage API.
on Mar 2, 2016 Indeed as of now you can only explicitly set
com.google.gcloud.AuthCredentials.ServiceAccountAuthCredentials.However if you don't specify it
signUrlmay still work based on your service auth config (if it is configured withAuthCredentials.ServiceAccountAuthCredentialsor usingApplicationDefaultAuthCredentialsAND the default auth config is associated with a service account.ApplicationDefaultAuthCredentialsis not required to be associated with a service account (and provide private-key).Ok, thanks! I didn't know that you can not use the GCE service account for signing URL. However, isn't it appropriate for that method to receive an interface? Especially if there is a possibility that GCE service account can be used for signing in the future (I'm not sure though).
Related:
http://googlecloudplatform.github.io/gcloud-python/stable/storage-blobs.html#gcloud.storage.blob.Blob.generate_signed_url
googleapis/google-cloud-python#922Yes, we could do something similar to
gcloud-pythonand acceptAuthCredentialsinstead of the specificServiceAccountAuthCredentialsbut similar to the Python API this class does not expose
in its API a service-account or private key.We could still get it and then reject any instances that are not known to us to support the signing.
I don't like that such enforcement is a run-time failure but maybe that is not too bad as a runtime
failure is already possible when not providing anything.
Also, I don't like that this way a user could not implement its own AuthCrendentials to work
with the signing as the signature does not specify it.We could define a Signing interface and make some of our AuthCrendentials credentials implement it.
I am +1 for it. Is that what you are suggesting?@ajkannan is it something that you will be interested in and have time for it?
@aozarov Yeah, that seems a right approach!
Sure, I can take this issue.
For the record the proposed change will allow us to support signing on App Engine (and we plan to do so). However, it is still not supported via the default compute engine credentials.
Fixed with #854
17 remaining items
- added 2 commits that reference this issue
on Feb 1, 2023 - added 2 commits that reference this issue
on Jan 22, 2026 - added a commit that references this issue
on Mar 23, 2026 - added a commit that references this issue
on Mar 30, 2026 - added a commit that references this issue
on Apr 1, 2026 - added a commit that references this issue
on Jul 13, 2026
Currently Storage.SignUrlOption receives
com.google.gcloud.AuthCredentials.ServiceAccountAuthCredentials, but how to use ApplicationDefaultAuthCredentials with that method? I think we should allow using ApplicationDefaultAuthCredentials if possible.