This repository was archived by the owner on Apr 7, 2026. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 141
Expand file tree
/
Copy pathMutableCredentials.java
More file actions
84 lines (75 loc) · 2.86 KB
/
Copy pathMutableCredentials.java
File metadata and controls
84 lines (75 loc) · 2.86 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
/*
* Copyright 2026 Google LLC
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
* You may obtain a copy of the License at
*
* http://www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing, software
* distributed under the License is distributed on an "AS IS" BASIS,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
* See the License for the specific language governing permissions and
* limitations under the License.
*/
package com.google.cloud.spanner.connection;
import com.google.auth.Credentials;
import com.google.auth.oauth2.ServiceAccountCredentials;
import java.io.IOException;
import java.net.URI;
import java.util.List;
import java.util.Map;
/**
* A mutable {@link Credentials} implementation that delegates authentication behavior to a scoped
* {@link ServiceAccountCredentials} instance.
*
* <p>This class is intended for scenarios where an application needs to rotate or replace the
* underlying service account credentials for a running Spanner Client.
*
* <p>All operations inherited from {@link Credentials} are forwarded to the current delegate,
* including request metadata retrieval and token refresh. Calling {@link
* #updateCredentials(ServiceAccountCredentials)} replaces the delegate with a newly scoped
* credentials instance created from the same scopes that were provided when this object was
* constructed.
*/
public class MutableCredentials extends Credentials {
ServiceAccountCredentials delegate;
List<String> scopes;
public MutableCredentials(ServiceAccountCredentials credentials, List<String> scopes) {
this.scopes = scopes;
delegate = (ServiceAccountCredentials) credentials.createScoped(scopes);
}
/**
* Replaces the current delegate with a newly scoped credentials instance.
*
* <p>The provided {@link ServiceAccountCredentials} is scoped using the same scopes that were
* supplied when this {@link MutableCredentials} instance was created.
*
* @param credentials the new base service account credentials to scope and use for client
* authorization.
*/
public void updateCredentials(ServiceAccountCredentials credentials) {
delegate = (ServiceAccountCredentials) credentials.createScoped(scopes);
}
@Override
public String getAuthenticationType() {
return delegate.getAuthenticationType();
}
@Override
public Map<String, List<String>> getRequestMetadata(URI uri) throws IOException {
return delegate.getRequestMetadata(uri);
}
@Override
public boolean hasRequestMetadata() {
return delegate.hasRequestMetadata();
}
@Override
public boolean hasRequestMetadataOnly() {
return delegate.hasRequestMetadataOnly();
}
@Override
public void refresh() throws IOException {
delegate.refresh();
}
}