Conversation
|
Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA). View this failed invocation of the CLA check for more information. For the most up to date status, view the checks section at the bottom of the pull request. |
There was a problem hiding this comment.
Code Review
This pull request updates the TokenHandler to ensure that tokenOptions.iss is correctly set using the client email from credentials when available, and adds corresponding unit tests to verify this behavior. The feedback suggests wrapping the temporary directory cleanup in a try...finally block in the new JWT test to prevent directory leaks in case of test failures.
GoogleToken copies `email` into `iss` in its constructor, before the key file is read. TokenHandler then set `email` from the file but not `iss`, so a JWT client given only a keyFile signed its assertion without `iss` and Google answered "invalid_grant: account not found" (10.6.1 onwards). Restores gtoken's `iss = clientEmail || iss`. Also adds the license header to gtoken/tokenHandler.ts, which the header check flags. Fixes googleapis#9469
b1697cd to
47dcde1
Compare
Fixes #9469
Description
Since 10.6.1, a
JWTclient given only a JSONkeyFilesigns its token assertion withoutiss, and Google rejects it withinvalid_grant: account not found.GoogleTokencopiesemailintoissin its constructor, before the key file has been read.TokenHandler.processCredentials()then setsemailfrom the file, but notiss, which is the claim that gets signed. This change restores the standalone gtoken behaviour:iss = clientEmail || iss. Anisspassed in explicitly is kept when the key file has no email, for example a PEM file.Changelist
src/gtoken/tokenHandler.ts: settokenOptions.issfrom the key file'sclient_email.test/gtoken/test.tokenHandler.ts: assert thatissis set from the key file, and that a givenissis kept when the file has no email.test/test.jwt.ts: end to end, a JSONkeyFilewith noemailoption signsiss = client_email. Every existingkeyFiletest also passedemail, which is why this wasn't caught.Both new assertions fail without the fix and pass with it. The gtoken and jwt suites pass: 131 tests.
🤖 Generated with Claude Code