vendor: update all dependencies

This commit is contained in:
Nick Craig-Wood
2017-07-23 08:51:42 +01:00
parent 0b6fba34a3
commit eb87cf6f12
2008 changed files with 352617 additions and 1004734 deletions
+14 -5
View File
@@ -15,7 +15,7 @@
// AUTO-GENERATED CODE. DO NOT EDIT.
// Package admin is an experimental, auto-generated package for the
// admin API.
// Google Identity and Access Management (IAM) API.
//
// Manages identity and access control for Google Cloud Platform resources,
// including the creation of service accounts, which you can use to
@@ -27,9 +27,18 @@ import (
"google.golang.org/grpc/metadata"
)
func insertXGoog(ctx context.Context, val string) context.Context {
md, _ := metadata.FromContext(ctx)
func insertXGoog(ctx context.Context, val []string) context.Context {
md, _ := metadata.FromOutgoingContext(ctx)
md = md.Copy()
md["x-goog-api-client"] = []string{val}
return metadata.NewContext(ctx, md)
md["x-goog-api-client"] = val
return metadata.NewOutgoingContext(ctx, md)
}
// DefaultAuthScopes reports the authentication scopes required
// by this package.
func DefaultAuthScopes() []string {
return []string{
"https://www.googleapis.com/auth/cloud-platform",
"https://www.googleapis.com/auth/iam",
}
}
+74 -74
View File
@@ -59,10 +59,7 @@ type IamCallOptions struct {
func defaultIamClientOptions() []option.ClientOption {
return []option.ClientOption{
option.WithEndpoint("iam.googleapis.com:443"),
option.WithScopes(
"https://www.googleapis.com/auth/cloud-platform",
"https://www.googleapis.com/auth/iam",
),
option.WithScopes(DefaultAuthScopes()...),
}
}
@@ -80,17 +77,6 @@ func defaultIamCallOptions() *IamCallOptions {
})
}),
},
{"default", "non_idempotent"}: {
gax.WithRetry(func() gax.Retryer {
return gax.OnCodes([]codes.Code{
codes.Unavailable,
}, gax.Backoff{
Initial: 100 * time.Millisecond,
Max: 60000 * time.Millisecond,
Multiplier: 1.3,
})
}),
},
}
return &IamCallOptions{
ListServiceAccounts: retry[[2]string{"default", "idempotent"}],
@@ -122,7 +108,7 @@ type IamClient struct {
CallOptions *IamCallOptions
// The metadata to be sent with each request.
xGoogHeader string
xGoogHeader []string
}
// NewIamClient creates a new iam client.
@@ -174,8 +160,8 @@ func (c *IamClient) Close() error {
// use by Google-written clients.
func (c *IamClient) SetGoogleClientInfo(keyval ...string) {
kv := append([]string{"gl-go", version.Go()}, keyval...)
kv = append(kv, "gapic", version.Repo, "gax", gax.Version, "grpc", "")
c.xGoogHeader = gax.XGoogHeader(kv...)
kv = append(kv, "gapic", version.Repo, "gax", gax.Version, "grpc", grpc.Version)
c.xGoogHeader = []string{gax.XGoogHeader(kv...)}
}
// IamProjectPath returns the path for the project resource.
@@ -215,8 +201,9 @@ func IamKeyPath(project, serviceAccount, key string) string {
}
// ListServiceAccounts lists [ServiceAccounts][google.iam.admin.v1.ServiceAccount] for a project.
func (c *IamClient) ListServiceAccounts(ctx context.Context, req *adminpb.ListServiceAccountsRequest) *ServiceAccountIterator {
func (c *IamClient) ListServiceAccounts(ctx context.Context, req *adminpb.ListServiceAccountsRequest, opts ...gax.CallOption) *ServiceAccountIterator {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.ListServiceAccounts[0:len(c.CallOptions.ListServiceAccounts):len(c.CallOptions.ListServiceAccounts)], opts...)
it := &ServiceAccountIterator{}
it.InternalFetch = func(pageSize int, pageToken string) ([]*adminpb.ServiceAccount, string, error) {
var resp *adminpb.ListServiceAccountsResponse
@@ -226,11 +213,11 @@ func (c *IamClient) ListServiceAccounts(ctx context.Context, req *adminpb.ListSe
} else {
req.PageSize = int32(pageSize)
}
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.ListServiceAccounts(ctx, req)
resp, err = c.iamClient.ListServiceAccounts(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.ListServiceAccounts...)
}, opts...)
if err != nil {
return nil, "", err
}
@@ -249,14 +236,15 @@ func (c *IamClient) ListServiceAccounts(ctx context.Context, req *adminpb.ListSe
}
// GetServiceAccount gets a [ServiceAccount][google.iam.admin.v1.ServiceAccount].
func (c *IamClient) GetServiceAccount(ctx context.Context, req *adminpb.GetServiceAccountRequest) (*adminpb.ServiceAccount, error) {
func (c *IamClient) GetServiceAccount(ctx context.Context, req *adminpb.GetServiceAccountRequest, opts ...gax.CallOption) (*adminpb.ServiceAccount, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.GetServiceAccount[0:len(c.CallOptions.GetServiceAccount):len(c.CallOptions.GetServiceAccount)], opts...)
var resp *adminpb.ServiceAccount
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.GetServiceAccount(ctx, req)
resp, err = c.iamClient.GetServiceAccount(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.GetServiceAccount...)
}, opts...)
if err != nil {
return nil, err
}
@@ -265,14 +253,15 @@ func (c *IamClient) GetServiceAccount(ctx context.Context, req *adminpb.GetServi
// CreateServiceAccount creates a [ServiceAccount][google.iam.admin.v1.ServiceAccount]
// and returns it.
func (c *IamClient) CreateServiceAccount(ctx context.Context, req *adminpb.CreateServiceAccountRequest) (*adminpb.ServiceAccount, error) {
func (c *IamClient) CreateServiceAccount(ctx context.Context, req *adminpb.CreateServiceAccountRequest, opts ...gax.CallOption) (*adminpb.ServiceAccount, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.CreateServiceAccount[0:len(c.CallOptions.CreateServiceAccount):len(c.CallOptions.CreateServiceAccount)], opts...)
var resp *adminpb.ServiceAccount
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.CreateServiceAccount(ctx, req)
resp, err = c.iamClient.CreateServiceAccount(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.CreateServiceAccount...)
}, opts...)
if err != nil {
return nil, err
}
@@ -284,14 +273,15 @@ func (c *IamClient) CreateServiceAccount(ctx context.Context, req *adminpb.Creat
// Currently, only the following fields are updatable:
// `display_name` .
// The `etag` is mandatory.
func (c *IamClient) UpdateServiceAccount(ctx context.Context, req *adminpb.ServiceAccount) (*adminpb.ServiceAccount, error) {
func (c *IamClient) UpdateServiceAccount(ctx context.Context, req *adminpb.ServiceAccount, opts ...gax.CallOption) (*adminpb.ServiceAccount, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.UpdateServiceAccount[0:len(c.CallOptions.UpdateServiceAccount):len(c.CallOptions.UpdateServiceAccount)], opts...)
var resp *adminpb.ServiceAccount
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.UpdateServiceAccount(ctx, req)
resp, err = c.iamClient.UpdateServiceAccount(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.UpdateServiceAccount...)
}, opts...)
if err != nil {
return nil, err
}
@@ -299,25 +289,27 @@ func (c *IamClient) UpdateServiceAccount(ctx context.Context, req *adminpb.Servi
}
// DeleteServiceAccount deletes a [ServiceAccount][google.iam.admin.v1.ServiceAccount].
func (c *IamClient) DeleteServiceAccount(ctx context.Context, req *adminpb.DeleteServiceAccountRequest) error {
func (c *IamClient) DeleteServiceAccount(ctx context.Context, req *adminpb.DeleteServiceAccountRequest, opts ...gax.CallOption) error {
ctx = insertXGoog(ctx, c.xGoogHeader)
err := gax.Invoke(ctx, func(ctx context.Context) error {
opts = append(c.CallOptions.DeleteServiceAccount[0:len(c.CallOptions.DeleteServiceAccount):len(c.CallOptions.DeleteServiceAccount)], opts...)
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
_, err = c.iamClient.DeleteServiceAccount(ctx, req)
_, err = c.iamClient.DeleteServiceAccount(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.DeleteServiceAccount...)
}, opts...)
return err
}
// ListServiceAccountKeys lists [ServiceAccountKeys][google.iam.admin.v1.ServiceAccountKey].
func (c *IamClient) ListServiceAccountKeys(ctx context.Context, req *adminpb.ListServiceAccountKeysRequest) (*adminpb.ListServiceAccountKeysResponse, error) {
func (c *IamClient) ListServiceAccountKeys(ctx context.Context, req *adminpb.ListServiceAccountKeysRequest, opts ...gax.CallOption) (*adminpb.ListServiceAccountKeysResponse, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.ListServiceAccountKeys[0:len(c.CallOptions.ListServiceAccountKeys):len(c.CallOptions.ListServiceAccountKeys)], opts...)
var resp *adminpb.ListServiceAccountKeysResponse
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.ListServiceAccountKeys(ctx, req)
resp, err = c.iamClient.ListServiceAccountKeys(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.ListServiceAccountKeys...)
}, opts...)
if err != nil {
return nil, err
}
@@ -326,14 +318,15 @@ func (c *IamClient) ListServiceAccountKeys(ctx context.Context, req *adminpb.Lis
// GetServiceAccountKey gets the [ServiceAccountKey][google.iam.admin.v1.ServiceAccountKey]
// by key id.
func (c *IamClient) GetServiceAccountKey(ctx context.Context, req *adminpb.GetServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
func (c *IamClient) GetServiceAccountKey(ctx context.Context, req *adminpb.GetServiceAccountKeyRequest, opts ...gax.CallOption) (*adminpb.ServiceAccountKey, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.GetServiceAccountKey[0:len(c.CallOptions.GetServiceAccountKey):len(c.CallOptions.GetServiceAccountKey)], opts...)
var resp *adminpb.ServiceAccountKey
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.GetServiceAccountKey(ctx, req)
resp, err = c.iamClient.GetServiceAccountKey(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.GetServiceAccountKey...)
}, opts...)
if err != nil {
return nil, err
}
@@ -342,14 +335,15 @@ func (c *IamClient) GetServiceAccountKey(ctx context.Context, req *adminpb.GetSe
// CreateServiceAccountKey creates a [ServiceAccountKey][google.iam.admin.v1.ServiceAccountKey]
// and returns it.
func (c *IamClient) CreateServiceAccountKey(ctx context.Context, req *adminpb.CreateServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
func (c *IamClient) CreateServiceAccountKey(ctx context.Context, req *adminpb.CreateServiceAccountKeyRequest, opts ...gax.CallOption) (*adminpb.ServiceAccountKey, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.CreateServiceAccountKey[0:len(c.CallOptions.CreateServiceAccountKey):len(c.CallOptions.CreateServiceAccountKey)], opts...)
var resp *adminpb.ServiceAccountKey
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.CreateServiceAccountKey(ctx, req)
resp, err = c.iamClient.CreateServiceAccountKey(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.CreateServiceAccountKey...)
}, opts...)
if err != nil {
return nil, err
}
@@ -357,25 +351,27 @@ func (c *IamClient) CreateServiceAccountKey(ctx context.Context, req *adminpb.Cr
}
// DeleteServiceAccountKey deletes a [ServiceAccountKey][google.iam.admin.v1.ServiceAccountKey].
func (c *IamClient) DeleteServiceAccountKey(ctx context.Context, req *adminpb.DeleteServiceAccountKeyRequest) error {
func (c *IamClient) DeleteServiceAccountKey(ctx context.Context, req *adminpb.DeleteServiceAccountKeyRequest, opts ...gax.CallOption) error {
ctx = insertXGoog(ctx, c.xGoogHeader)
err := gax.Invoke(ctx, func(ctx context.Context) error {
opts = append(c.CallOptions.DeleteServiceAccountKey[0:len(c.CallOptions.DeleteServiceAccountKey):len(c.CallOptions.DeleteServiceAccountKey)], opts...)
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
_, err = c.iamClient.DeleteServiceAccountKey(ctx, req)
_, err = c.iamClient.DeleteServiceAccountKey(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.DeleteServiceAccountKey...)
}, opts...)
return err
}
// SignBlob signs a blob using a service account's system-managed private key.
func (c *IamClient) SignBlob(ctx context.Context, req *adminpb.SignBlobRequest) (*adminpb.SignBlobResponse, error) {
func (c *IamClient) SignBlob(ctx context.Context, req *adminpb.SignBlobRequest, opts ...gax.CallOption) (*adminpb.SignBlobResponse, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.SignBlob[0:len(c.CallOptions.SignBlob):len(c.CallOptions.SignBlob)], opts...)
var resp *adminpb.SignBlobResponse
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.SignBlob(ctx, req)
resp, err = c.iamClient.SignBlob(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.SignBlob...)
}, opts...)
if err != nil {
return nil, err
}
@@ -384,14 +380,15 @@ func (c *IamClient) SignBlob(ctx context.Context, req *adminpb.SignBlobRequest)
// getIamPolicy returns the IAM access control policy for a
// [ServiceAccount][google.iam.admin.v1.ServiceAccount].
func (c *IamClient) getIamPolicy(ctx context.Context, req *iampb.GetIamPolicyRequest) (*iampb.Policy, error) {
func (c *IamClient) getIamPolicy(ctx context.Context, req *iampb.GetIamPolicyRequest, opts ...gax.CallOption) (*iampb.Policy, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.GetIamPolicy[0:len(c.CallOptions.GetIamPolicy):len(c.CallOptions.GetIamPolicy)], opts...)
var resp *iampb.Policy
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.GetIamPolicy(ctx, req)
resp, err = c.iamClient.GetIamPolicy(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.GetIamPolicy...)
}, opts...)
if err != nil {
return nil, err
}
@@ -400,14 +397,15 @@ func (c *IamClient) getIamPolicy(ctx context.Context, req *iampb.GetIamPolicyReq
// setIamPolicy sets the IAM access control policy for a
// [ServiceAccount][google.iam.admin.v1.ServiceAccount].
func (c *IamClient) setIamPolicy(ctx context.Context, req *iampb.SetIamPolicyRequest) (*iampb.Policy, error) {
func (c *IamClient) setIamPolicy(ctx context.Context, req *iampb.SetIamPolicyRequest, opts ...gax.CallOption) (*iampb.Policy, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.SetIamPolicy[0:len(c.CallOptions.SetIamPolicy):len(c.CallOptions.SetIamPolicy)], opts...)
var resp *iampb.Policy
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.SetIamPolicy(ctx, req)
resp, err = c.iamClient.SetIamPolicy(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.SetIamPolicy...)
}, opts...)
if err != nil {
return nil, err
}
@@ -416,14 +414,15 @@ func (c *IamClient) setIamPolicy(ctx context.Context, req *iampb.SetIamPolicyReq
// TestIamPermissions tests the specified permissions against the IAM access control policy
// for a [ServiceAccount][google.iam.admin.v1.ServiceAccount].
func (c *IamClient) TestIamPermissions(ctx context.Context, req *iampb.TestIamPermissionsRequest) (*iampb.TestIamPermissionsResponse, error) {
func (c *IamClient) TestIamPermissions(ctx context.Context, req *iampb.TestIamPermissionsRequest, opts ...gax.CallOption) (*iampb.TestIamPermissionsResponse, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.TestIamPermissions[0:len(c.CallOptions.TestIamPermissions):len(c.CallOptions.TestIamPermissions)], opts...)
var resp *iampb.TestIamPermissionsResponse
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.TestIamPermissions(ctx, req)
resp, err = c.iamClient.TestIamPermissions(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.TestIamPermissions...)
}, opts...)
if err != nil {
return nil, err
}
@@ -433,14 +432,15 @@ func (c *IamClient) TestIamPermissions(ctx context.Context, req *iampb.TestIamPe
// QueryGrantableRoles queries roles that can be granted on a particular resource.
// A role is grantable if it can be used as the role in a binding for a policy
// for that resource.
func (c *IamClient) QueryGrantableRoles(ctx context.Context, req *adminpb.QueryGrantableRolesRequest) (*adminpb.QueryGrantableRolesResponse, error) {
func (c *IamClient) QueryGrantableRoles(ctx context.Context, req *adminpb.QueryGrantableRolesRequest, opts ...gax.CallOption) (*adminpb.QueryGrantableRolesResponse, error) {
ctx = insertXGoog(ctx, c.xGoogHeader)
opts = append(c.CallOptions.QueryGrantableRoles[0:len(c.CallOptions.QueryGrantableRoles):len(c.CallOptions.QueryGrantableRoles)], opts...)
var resp *adminpb.QueryGrantableRolesResponse
err := gax.Invoke(ctx, func(ctx context.Context) error {
err := gax.Invoke(ctx, func(ctx context.Context, settings gax.CallSettings) error {
var err error
resp, err = c.iamClient.QueryGrantableRoles(ctx, req)
resp, err = c.iamClient.QueryGrantableRoles(ctx, req, settings.GRPC...)
return err
}, c.CallOptions.QueryGrantableRoles...)
}, opts...)
if err != nil {
return nil, err
}
+4 -1
View File
@@ -19,6 +19,7 @@ package admin_test
import (
"cloud.google.com/go/iam/admin/apiv1"
"golang.org/x/net/context"
"google.golang.org/api/iterator"
adminpb "google.golang.org/genproto/googleapis/iam/admin/v1"
iampb "google.golang.org/genproto/googleapis/iam/v1"
)
@@ -46,9 +47,11 @@ func ExampleIamClient_ListServiceAccounts() {
it := c.ListServiceAccounts(ctx, req)
for {
resp, err := it.Next()
if err == iterator.Done {
break
}
if err != nil {
// TODO: Handle error.
break
}
// TODO: Use resp.
_ = resp
+149 -61
View File
@@ -17,17 +17,19 @@
package admin
import (
google_protobuf "github.com/golang/protobuf/ptypes/empty"
emptypb "github.com/golang/protobuf/ptypes/empty"
adminpb "google.golang.org/genproto/googleapis/iam/admin/v1"
iampb "google.golang.org/genproto/googleapis/iam/v1"
)
import (
"flag"
"fmt"
"io"
"log"
"net"
"os"
"strings"
"testing"
"github.com/golang/protobuf/proto"
@@ -37,6 +39,8 @@ import (
status "google.golang.org/genproto/googleapis/rpc/status"
"google.golang.org/grpc"
"google.golang.org/grpc/codes"
"google.golang.org/grpc/metadata"
gstatus "google.golang.org/grpc/status"
)
var _ = io.EOF
@@ -58,7 +62,11 @@ type mockIamServer struct {
resps []proto.Message
}
func (s *mockIamServer) ListServiceAccounts(_ context.Context, req *adminpb.ListServiceAccountsRequest) (*adminpb.ListServiceAccountsResponse, error) {
func (s *mockIamServer) ListServiceAccounts(ctx context.Context, req *adminpb.ListServiceAccountsRequest) (*adminpb.ListServiceAccountsResponse, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -66,7 +74,11 @@ func (s *mockIamServer) ListServiceAccounts(_ context.Context, req *adminpb.List
return s.resps[0].(*adminpb.ListServiceAccountsResponse), nil
}
func (s *mockIamServer) GetServiceAccount(_ context.Context, req *adminpb.GetServiceAccountRequest) (*adminpb.ServiceAccount, error) {
func (s *mockIamServer) GetServiceAccount(ctx context.Context, req *adminpb.GetServiceAccountRequest) (*adminpb.ServiceAccount, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -74,7 +86,11 @@ func (s *mockIamServer) GetServiceAccount(_ context.Context, req *adminpb.GetSer
return s.resps[0].(*adminpb.ServiceAccount), nil
}
func (s *mockIamServer) CreateServiceAccount(_ context.Context, req *adminpb.CreateServiceAccountRequest) (*adminpb.ServiceAccount, error) {
func (s *mockIamServer) CreateServiceAccount(ctx context.Context, req *adminpb.CreateServiceAccountRequest) (*adminpb.ServiceAccount, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -82,7 +98,11 @@ func (s *mockIamServer) CreateServiceAccount(_ context.Context, req *adminpb.Cre
return s.resps[0].(*adminpb.ServiceAccount), nil
}
func (s *mockIamServer) UpdateServiceAccount(_ context.Context, req *adminpb.ServiceAccount) (*adminpb.ServiceAccount, error) {
func (s *mockIamServer) UpdateServiceAccount(ctx context.Context, req *adminpb.ServiceAccount) (*adminpb.ServiceAccount, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -90,15 +110,23 @@ func (s *mockIamServer) UpdateServiceAccount(_ context.Context, req *adminpb.Ser
return s.resps[0].(*adminpb.ServiceAccount), nil
}
func (s *mockIamServer) DeleteServiceAccount(_ context.Context, req *adminpb.DeleteServiceAccountRequest) (*google_protobuf.Empty, error) {
func (s *mockIamServer) DeleteServiceAccount(ctx context.Context, req *adminpb.DeleteServiceAccountRequest) (*emptypb.Empty, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
}
return s.resps[0].(*google_protobuf.Empty), nil
return s.resps[0].(*emptypb.Empty), nil
}
func (s *mockIamServer) ListServiceAccountKeys(_ context.Context, req *adminpb.ListServiceAccountKeysRequest) (*adminpb.ListServiceAccountKeysResponse, error) {
func (s *mockIamServer) ListServiceAccountKeys(ctx context.Context, req *adminpb.ListServiceAccountKeysRequest) (*adminpb.ListServiceAccountKeysResponse, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -106,7 +134,11 @@ func (s *mockIamServer) ListServiceAccountKeys(_ context.Context, req *adminpb.L
return s.resps[0].(*adminpb.ListServiceAccountKeysResponse), nil
}
func (s *mockIamServer) GetServiceAccountKey(_ context.Context, req *adminpb.GetServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
func (s *mockIamServer) GetServiceAccountKey(ctx context.Context, req *adminpb.GetServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -114,7 +146,11 @@ func (s *mockIamServer) GetServiceAccountKey(_ context.Context, req *adminpb.Get
return s.resps[0].(*adminpb.ServiceAccountKey), nil
}
func (s *mockIamServer) CreateServiceAccountKey(_ context.Context, req *adminpb.CreateServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
func (s *mockIamServer) CreateServiceAccountKey(ctx context.Context, req *adminpb.CreateServiceAccountKeyRequest) (*adminpb.ServiceAccountKey, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -122,15 +158,23 @@ func (s *mockIamServer) CreateServiceAccountKey(_ context.Context, req *adminpb.
return s.resps[0].(*adminpb.ServiceAccountKey), nil
}
func (s *mockIamServer) DeleteServiceAccountKey(_ context.Context, req *adminpb.DeleteServiceAccountKeyRequest) (*google_protobuf.Empty, error) {
func (s *mockIamServer) DeleteServiceAccountKey(ctx context.Context, req *adminpb.DeleteServiceAccountKeyRequest) (*emptypb.Empty, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
}
return s.resps[0].(*google_protobuf.Empty), nil
return s.resps[0].(*emptypb.Empty), nil
}
func (s *mockIamServer) SignBlob(_ context.Context, req *adminpb.SignBlobRequest) (*adminpb.SignBlobResponse, error) {
func (s *mockIamServer) SignBlob(ctx context.Context, req *adminpb.SignBlobRequest) (*adminpb.SignBlobResponse, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -138,7 +182,11 @@ func (s *mockIamServer) SignBlob(_ context.Context, req *adminpb.SignBlobRequest
return s.resps[0].(*adminpb.SignBlobResponse), nil
}
func (s *mockIamServer) GetIamPolicy(_ context.Context, req *iampb.GetIamPolicyRequest) (*iampb.Policy, error) {
func (s *mockIamServer) GetIamPolicy(ctx context.Context, req *iampb.GetIamPolicyRequest) (*iampb.Policy, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -146,7 +194,11 @@ func (s *mockIamServer) GetIamPolicy(_ context.Context, req *iampb.GetIamPolicyR
return s.resps[0].(*iampb.Policy), nil
}
func (s *mockIamServer) SetIamPolicy(_ context.Context, req *iampb.SetIamPolicyRequest) (*iampb.Policy, error) {
func (s *mockIamServer) SetIamPolicy(ctx context.Context, req *iampb.SetIamPolicyRequest) (*iampb.Policy, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -154,7 +206,11 @@ func (s *mockIamServer) SetIamPolicy(_ context.Context, req *iampb.SetIamPolicyR
return s.resps[0].(*iampb.Policy), nil
}
func (s *mockIamServer) TestIamPermissions(_ context.Context, req *iampb.TestIamPermissionsRequest) (*iampb.TestIamPermissionsResponse, error) {
func (s *mockIamServer) TestIamPermissions(ctx context.Context, req *iampb.TestIamPermissionsRequest) (*iampb.TestIamPermissionsResponse, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -162,7 +218,11 @@ func (s *mockIamServer) TestIamPermissions(_ context.Context, req *iampb.TestIam
return s.resps[0].(*iampb.TestIamPermissionsResponse), nil
}
func (s *mockIamServer) QueryGrantableRoles(_ context.Context, req *adminpb.QueryGrantableRolesRequest) (*adminpb.QueryGrantableRolesResponse, error) {
func (s *mockIamServer) QueryGrantableRoles(ctx context.Context, req *adminpb.QueryGrantableRolesRequest) (*adminpb.QueryGrantableRolesResponse, error) {
md, _ := metadata.FromIncomingContext(ctx)
if xg := md["x-goog-api-client"]; len(xg) == 0 || !strings.Contains(xg[0], "gl-go/") {
return nil, fmt.Errorf("x-goog-api-client = %v, expected gl-go key", xg)
}
s.reqs = append(s.reqs, req)
if s.err != nil {
return nil, s.err
@@ -249,8 +309,8 @@ func TestIamListServiceAccounts(t *testing.T) {
}
func TestIamListServiceAccountsError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamProjectPath("[PROJECT]")
var request = &adminpb.ListServiceAccountsRequest{
@@ -264,7 +324,9 @@ func TestIamListServiceAccountsError(t *testing.T) {
resp, err := c.ListServiceAccounts(context.Background(), request).Next()
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -318,8 +380,8 @@ func TestIamGetServiceAccount(t *testing.T) {
}
func TestIamGetServiceAccountError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var request = &adminpb.GetServiceAccountRequest{
@@ -333,7 +395,9 @@ func TestIamGetServiceAccountError(t *testing.T) {
resp, err := c.GetServiceAccount(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -389,8 +453,8 @@ func TestIamCreateServiceAccount(t *testing.T) {
}
func TestIamCreateServiceAccountError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamProjectPath("[PROJECT]")
var accountId string = "accountId-803333011"
@@ -406,7 +470,9 @@ func TestIamCreateServiceAccountError(t *testing.T) {
resp, err := c.CreateServiceAccount(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -460,8 +526,8 @@ func TestIamUpdateServiceAccount(t *testing.T) {
}
func TestIamUpdateServiceAccountError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var etag []byte = []byte("21")
var request = &adminpb.ServiceAccount{
@@ -475,13 +541,15 @@ func TestIamUpdateServiceAccountError(t *testing.T) {
resp, err := c.UpdateServiceAccount(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
}
func TestIamDeleteServiceAccount(t *testing.T) {
var expectedResponse *google_protobuf.Empty = &google_protobuf.Empty{}
var expectedResponse *emptypb.Empty = &emptypb.Empty{}
mockIam.err = nil
mockIam.reqs = nil
@@ -511,8 +579,8 @@ func TestIamDeleteServiceAccount(t *testing.T) {
}
func TestIamDeleteServiceAccountError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var request = &adminpb.DeleteServiceAccountRequest{
@@ -526,7 +594,9 @@ func TestIamDeleteServiceAccountError(t *testing.T) {
err = c.DeleteServiceAccount(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
}
@@ -564,8 +634,8 @@ func TestIamListServiceAccountKeys(t *testing.T) {
}
func TestIamListServiceAccountKeysError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var request = &adminpb.ListServiceAccountKeysRequest{
@@ -579,7 +649,9 @@ func TestIamListServiceAccountKeysError(t *testing.T) {
resp, err := c.ListServiceAccountKeys(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -625,8 +697,8 @@ func TestIamGetServiceAccountKey(t *testing.T) {
}
func TestIamGetServiceAccountKeyError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamKeyPath("[PROJECT]", "[SERVICE_ACCOUNT]", "[KEY]")
var request = &adminpb.GetServiceAccountKeyRequest{
@@ -640,7 +712,9 @@ func TestIamGetServiceAccountKeyError(t *testing.T) {
resp, err := c.GetServiceAccountKey(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -686,8 +760,8 @@ func TestIamCreateServiceAccountKey(t *testing.T) {
}
func TestIamCreateServiceAccountKeyError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var request = &adminpb.CreateServiceAccountKeyRequest{
@@ -701,13 +775,15 @@ func TestIamCreateServiceAccountKeyError(t *testing.T) {
resp, err := c.CreateServiceAccountKey(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
}
func TestIamDeleteServiceAccountKey(t *testing.T) {
var expectedResponse *google_protobuf.Empty = &google_protobuf.Empty{}
var expectedResponse *emptypb.Empty = &emptypb.Empty{}
mockIam.err = nil
mockIam.reqs = nil
@@ -737,8 +813,8 @@ func TestIamDeleteServiceAccountKey(t *testing.T) {
}
func TestIamDeleteServiceAccountKeyError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamKeyPath("[PROJECT]", "[SERVICE_ACCOUNT]", "[KEY]")
var request = &adminpb.DeleteServiceAccountKeyRequest{
@@ -752,7 +828,9 @@ func TestIamDeleteServiceAccountKeyError(t *testing.T) {
err = c.DeleteServiceAccountKey(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
}
@@ -797,8 +875,8 @@ func TestIamSignBlob(t *testing.T) {
}
func TestIamSignBlobError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedName string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var bytesToSign []byte = []byte("45")
@@ -814,7 +892,9 @@ func TestIamSignBlobError(t *testing.T) {
resp, err := c.SignBlob(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -858,8 +938,8 @@ func TestIamGetIamPolicy(t *testing.T) {
}
func TestIamGetIamPolicyError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedResource string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var request = &iampb.GetIamPolicyRequest{
@@ -873,7 +953,9 @@ func TestIamGetIamPolicyError(t *testing.T) {
resp, err := c.getIamPolicy(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -919,8 +1001,8 @@ func TestIamSetIamPolicy(t *testing.T) {
}
func TestIamSetIamPolicyError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedResource string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var policy *iampb.Policy = &iampb.Policy{}
@@ -936,7 +1018,9 @@ func TestIamSetIamPolicyError(t *testing.T) {
resp, err := c.setIamPolicy(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -977,8 +1061,8 @@ func TestIamTestIamPermissions(t *testing.T) {
}
func TestIamTestIamPermissionsError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var formattedResource string = IamServiceAccountPath("[PROJECT]", "[SERVICE_ACCOUNT]")
var permissions []string = nil
@@ -994,7 +1078,9 @@ func TestIamTestIamPermissionsError(t *testing.T) {
resp, err := c.TestIamPermissions(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
@@ -1033,8 +1119,8 @@ func TestIamQueryGrantableRoles(t *testing.T) {
}
func TestIamQueryGrantableRolesError(t *testing.T) {
errCode := codes.Internal
mockIam.err = grpc.Errorf(errCode, "test error")
errCode := codes.PermissionDenied
mockIam.err = gstatus.Error(errCode, "test error")
var fullResourceName string = "fullResourceName1300993644"
var request = &adminpb.QueryGrantableRolesRequest{
@@ -1048,7 +1134,9 @@ func TestIamQueryGrantableRolesError(t *testing.T) {
resp, err := c.QueryGrantableRoles(context.Background(), request)
if c := grpc.Code(err); c != errCode {
if st, ok := gstatus.FromError(err); !ok {
t.Errorf("got error %v, expected grpc error", err)
} else if c := st.Code(); c != errCode {
t.Errorf("got error code %q, want %q", c, errCode)
}
_ = resp
+83 -26
View File
@@ -27,9 +27,47 @@ import (
"google.golang.org/grpc"
)
// client abstracts the IAMPolicy API to allow multiple implementations.
type client interface {
Get(ctx context.Context, resource string) (*pb.Policy, error)
Set(ctx context.Context, resource string, p *pb.Policy) error
Test(ctx context.Context, resource string, perms []string) ([]string, error)
}
// grpcClient implements client for the standard gRPC-based IAMPolicy service.
type grpcClient struct {
c pb.IAMPolicyClient
}
func (g *grpcClient) Get(ctx context.Context, resource string) (*pb.Policy, error) {
proto, err := g.c.GetIamPolicy(ctx, &pb.GetIamPolicyRequest{Resource: resource})
if err != nil {
return nil, err
}
return proto, nil
}
func (g *grpcClient) Set(ctx context.Context, resource string, p *pb.Policy) error {
_, err := g.c.SetIamPolicy(ctx, &pb.SetIamPolicyRequest{
Resource: resource,
Policy: p,
})
return err
}
func (g *grpcClient) Test(ctx context.Context, resource string, perms []string) ([]string, error) {
res, err := g.c.TestIamPermissions(ctx, &pb.TestIamPermissionsRequest{
Resource: resource,
Permissions: perms,
})
if err != nil {
return nil, err
}
return res.Permissions, nil
}
// A Handle provides IAM operations for a resource.
type Handle struct {
c pb.IAMPolicyClient
c client
resource string
}
@@ -38,15 +76,23 @@ type Handle struct {
// InternalNewHandle returns a Handle for resource.
// The conn parameter refers to a server that must support the IAMPolicy service.
func InternalNewHandle(conn *grpc.ClientConn, resource string) *Handle {
return InternalNewHandleClient(&grpcClient{c: pb.NewIAMPolicyClient(conn)}, resource)
}
// InternalNewHandleClient is for use by the Google Cloud Libraries only.
//
// InternalNewHandleClient returns a Handle for resource using the given
// client implementation.
func InternalNewHandleClient(c client, resource string) *Handle {
return &Handle{
c: pb.NewIAMPolicyClient(conn),
c: c,
resource: resource,
}
}
// Policy retrieves the IAM policy for the resource.
func (h *Handle) Policy(ctx context.Context) (*Policy, error) {
proto, err := h.c.GetIamPolicy(ctx, &pb.GetIamPolicyRequest{Resource: h.resource})
proto, err := h.c.Get(ctx, h.resource)
if err != nil {
return nil, err
}
@@ -58,23 +104,12 @@ func (h *Handle) Policy(ctx context.Context) (*Policy, error) {
// If policy was created from a prior call to Get, then the modification will
// only succeed if the policy has not changed since the Get.
func (h *Handle) SetPolicy(ctx context.Context, policy *Policy) error {
_, err := h.c.SetIamPolicy(ctx, &pb.SetIamPolicyRequest{
Resource: h.resource,
Policy: policy.InternalProto,
})
return err
return h.c.Set(ctx, h.resource, policy.InternalProto)
}
// TestPermissions returns the subset of permissions that the caller has on the resource.
func (h *Handle) TestPermissions(ctx context.Context, permissions []string) ([]string, error) {
res, err := h.c.TestIamPermissions(ctx, &pb.TestIamPermissionsRequest{
Resource: h.resource,
Permissions: permissions,
})
if err != nil {
return nil, err
}
return res.Permissions, nil
return h.c.Test(ctx, h.resource, permissions)
}
// A RoleName is a name representing a collection of permissions.
@@ -146,16 +181,30 @@ func (p *Policy) Add(member string, r RoleName) {
// Remove removes member from role r if it is present.
func (p *Policy) Remove(member string, r RoleName) {
b := p.binding(r)
i := memberIndex(member, b)
if i < 0 {
bi := p.bindingIndex(r)
if bi < 0 {
return
}
// Order doesn't matter, so move the last member into the
// removed spot and shrink the slice.
bindings := p.InternalProto.Bindings
b := bindings[bi]
mi := memberIndex(member, b)
if mi < 0 {
return
}
// Order doesn't matter for bindings or members, so to remove, move the last item
// into the removed spot and shrink the slice.
if len(b.Members) == 1 {
// Remove binding.
last := len(bindings) - 1
bindings[bi] = bindings[last]
bindings[last] = nil
p.InternalProto.Bindings = bindings[:last]
return
}
// Remove member.
// TODO(jba): worry about multiple copies of m?
last := len(b.Members) - 1
b.Members[i] = b.Members[last]
b.Members[mi] = b.Members[last]
b.Members[last] = ""
b.Members = b.Members[:last]
}
@@ -174,15 +223,23 @@ func (p *Policy) Roles() []RoleName {
// binding returns the Binding for the suppied role, or nil if there isn't one.
func (p *Policy) binding(r RoleName) *pb.Binding {
if p.InternalProto == nil {
i := p.bindingIndex(r)
if i < 0 {
return nil
}
for _, b := range p.InternalProto.Bindings {
return p.InternalProto.Bindings[i]
}
func (p *Policy) bindingIndex(r RoleName) int {
if p.InternalProto == nil {
return -1
}
for i, b := range p.InternalProto.Bindings {
if b.Role == string(r) {
return b
return i
}
}
return nil
return -1
}
// memberIndex returns the index of m in b's Members, or -1 if not found.
+2 -2
View File
@@ -62,10 +62,10 @@ func TestPolicy(t *testing.T) {
t.Fatal(msg)
}
remove("m2", Owner)
if msg, ok := checkMembers(p, Owner, []string{}); !ok {
if msg, ok := checkMembers(p, Owner, nil); !ok {
t.Fatal(msg)
}
if got, want := p.Roles(), []RoleName{Owner}; !reflect.DeepEqual(got, want) {
if got, want := p.Roles(), []RoleName(nil); !reflect.DeepEqual(got, want) {
t.Fatalf("roles: got %v, want %v", got, want)
}
}