1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219
//! This module provides a token source (`GetToken`) that obtains tokens using workload identity federation
//! for use by software (i.e., non-human actors) to get access to Google services.
//! Resources:
//! - [Workload identity federation](https://cloud.google.com/iam/docs/workload-identity-federation)
//! - [External Account Credentials (Workload Identity Federation)](https://google.aip.dev/auth/4117)
use crate::client::SendRequest;
use crate::error::Error;
use crate::types::TokenInfo;
use http::header;
use http_body_util::BodyExt;
use serde::{Deserialize, Serialize};
use std::collections::HashMap;
use thiserror::Error;
use url::form_urlencoded;
/// JSON schema of external account secret.
/// You can use `helpers::read_external_account_secret()` to read a JSON file
/// into a `ExternalAccountSecret`.
#[derive(Serialize, Deserialize, Debug, Clone)]
pub struct ExternalAccountSecret {
/// audience
pub audience: String,
/// subject_token_type
pub subject_token_type: String,
/// service_account_impersonation_url
pub service_account_impersonation_url: Option<String>,
/// token_url
pub token_url: String,
// TODO: support service_account_impersonation.
/// credential_source
pub credential_source: CredentialSource,
#[serde(rename = "type")]
/// key_type
pub key_type: String,
/// JSON schema of credential source.
#[derive(Serialize, Deserialize, Debug, Clone)]
pub enum CredentialSource {
/// file-sourced credentials
File {
/// File name of a file containing a subject token.
file: String,
/// [Microsoft Azure and URL-sourced credentials](https://google.aip.dev/auth/4117#determining-the-subject-token-in-microsoft-azure-and-url-sourced-credentials)
Url {
/// This defines the local metadata server to retrieve the external credentials from. For
/// Azure, this should be the Azure Instance Metadata Service (IMDS) URL used to retrieve
/// the Azure AD access token.
url: String,
/// This defines the headers to append to the GET request to credential_source.url.
headers: Option<HashMap<String, String>>,
/// See struct documentation.
format: UrlCredentialSourceFormat,
// TODO: executable-sourced credentials
/// JSON schema of URL-sourced credentials' format.
/// This indicates the format of the URL response. This can be either "text" or "json". The default should be "text".
#[derive(Serialize, Deserialize, Debug, Clone)]
#[serde(tag = "type")]
pub enum UrlCredentialSourceFormat {
/// Response is text.
#[serde(rename = "text")]
/// Response is JSON.
#[serde(rename = "json")]
Json {
/// Required for JSON URL responses. This indicates the JSON field name where the subject_token should be stored.
subject_token_field_name: String,
#[derive(Debug, Error)]
/// Errors that can happen when parsing a Credential source
pub enum CredentialSourceError {
/// Parsing credential text source failed
#[error("Failed to parse credential text source: {0}")]
/// Failed to parse JSON
#[error("JSON credential source is invalid: {0}")]
JsonInvalid(#[source] serde_json::Error),
/// JSON is missing this field
#[error("JSON credential source is missing field {0}")]
/// This field of JSON is invalid
#[error("JSON credential source could not convert field {0} to string")]
/// An ExternalAccountFlow can fetch OAuth tokens using an external account secret.
pub struct ExternalAccountFlow {
pub(crate) secret: ExternalAccountSecret,
impl ExternalAccountFlow {
/// Send a request for a new Bearer token to the OAuth provider.
pub(crate) async fn token<T>(
hyper_client: &impl SendRequest,
scopes: &[T],
) -> Result<TokenInfo, Error>
T: AsRef<str>,
let subject_token = match &self.secret.credential_source {
CredentialSource::File { file } => tokio::fs::read_to_string(file).await?,
CredentialSource::Url {
} => {
let request = headers
.fold(hyper::Request::get(url), |builder, (name, value)| {
builder.header(name, value)
log::debug!("requesting credential from url: {:?}", request);
let (head, body) = hyper_client.request(request).await?.into_parts();
let body = body.collect().await?.to_bytes();
log::debug!("received response; head: {:?}, body: {:?}", head, body);
match format {
UrlCredentialSourceFormat::Text => {
String::from_utf8(body.to_vec()).map_err(|e| {
UrlCredentialSourceFormat::Json {
} => serde_json::from_slice::<HashMap<String, serde_json::Value>>(&body)
.map_err(|e| {
.ok_or_else(|| {
.ok_or_else(|| {
let req = form_urlencoded::Serializer::new(String::new())
("audience", self.secret.audience.as_str()),
("subject_token", subject_token.as_str()),
if self.secret.service_account_impersonation_url.is_some() {
} else {
crate::helper::join(scopes, " ")
let request = http::Request::post(&self.secret.token_url)
.header(header::CONTENT_TYPE, "application/x-www-form-urlencoded")
log::debug!("requesting token from external account: {:?}", request);
let (head, body) = hyper_client.request(request).await?.into_parts();
let body = body.collect().await?.to_bytes();
log::debug!("received response; head: {:?}, body: {:?}", head, body);
let token_info = TokenInfo::from_json(&body)?;
if let Some(service_account_impersonation_url) =
} else {