|
14 | 14 | ] |
15 | 15 |
|
16 | 16 |
|
| 17 | +def _token_call_credentials(token: str) -> grpc.CallCredentials: |
| 18 | + """Return gRPC call credentials that inject a Bearer token.""" |
| 19 | + |
| 20 | + def _callback(context: object, callback: object) -> None: # type: ignore[type-arg] |
| 21 | + assert callable(callback) |
| 22 | + callback([("authorization", f"Bearer {token}")], None) |
| 23 | + |
| 24 | + return grpc.metadata_call_credentials(_callback) |
| 25 | + |
| 26 | + |
17 | 27 | def create_channel( |
18 | 28 | target: str, |
19 | 29 | *, |
20 | 30 | insecure: bool = True, |
21 | 31 | credentials: grpc.ChannelCredentials | None = None, |
| 32 | + token: str | None = None, |
22 | 33 | ) -> grpc.Channel: |
23 | | - """Create a gRPC channel with sensible defaults.""" |
24 | | - if credentials is not None: |
25 | | - return grpc.secure_channel(target, credentials, options=_DEFAULT_OPTIONS) |
26 | | - if insecure: |
27 | | - return grpc.insecure_channel(target, options=_DEFAULT_OPTIONS) |
28 | | - return grpc.secure_channel(target, grpc.ssl_channel_credentials(), options=_DEFAULT_OPTIONS) |
| 34 | + """Create a gRPC channel with sensible defaults. |
| 35 | +
|
| 36 | + When *token* is provided and TLS is active (``insecure=False`` or |
| 37 | + *credentials* is given), the token is embedded via |
| 38 | + ``composite_channel_credentials`` so it is protected by the TLS layer. |
| 39 | + On an insecure channel the token is sent as a raw header — callers should |
| 40 | + warn the user before allowing this. |
| 41 | + """ |
| 42 | + channel_creds: grpc.ChannelCredentials | None = credentials |
| 43 | + if channel_creds is None and not insecure: |
| 44 | + channel_creds = grpc.ssl_channel_credentials() |
| 45 | + |
| 46 | + if channel_creds is not None: |
| 47 | + if token: |
| 48 | + channel_creds = grpc.composite_channel_credentials( |
| 49 | + channel_creds, _token_call_credentials(token) |
| 50 | + ) |
| 51 | + return grpc.secure_channel(target, channel_creds, options=_DEFAULT_OPTIONS) |
| 52 | + |
| 53 | + return grpc.insecure_channel(target, options=_DEFAULT_OPTIONS) |
29 | 54 |
|
30 | 55 |
|
31 | 56 | def create_aio_channel( |
32 | 57 | target: str, |
33 | 58 | *, |
34 | 59 | insecure: bool = True, |
35 | 60 | credentials: grpc.ChannelCredentials | None = None, |
| 61 | + token: str | None = None, |
36 | 62 | ) -> grpc.aio.Channel: |
37 | | - """Create an async gRPC channel with sensible defaults.""" |
38 | | - if credentials is not None: |
39 | | - return grpc.aio.secure_channel(target, credentials, options=_DEFAULT_OPTIONS) |
40 | | - if insecure: |
41 | | - return grpc.aio.insecure_channel(target, options=_DEFAULT_OPTIONS) |
42 | | - return grpc.aio.secure_channel(target, grpc.ssl_channel_credentials(), options=_DEFAULT_OPTIONS) |
| 63 | + """Create an async gRPC channel with sensible defaults. |
| 64 | +
|
| 65 | + When *token* is provided and TLS is active (``insecure=False`` or |
| 66 | + *credentials* is given), the token is embedded via |
| 67 | + ``composite_channel_credentials`` so it is protected by the TLS layer. |
| 68 | + On an insecure channel the token is sent as a raw header — callers should |
| 69 | + warn the user before allowing this. |
| 70 | + """ |
| 71 | + channel_creds: grpc.ChannelCredentials | None = credentials |
| 72 | + if channel_creds is None and not insecure: |
| 73 | + channel_creds = grpc.ssl_channel_credentials() |
| 74 | + |
| 75 | + if channel_creds is not None: |
| 76 | + if token: |
| 77 | + channel_creds = grpc.composite_channel_credentials( |
| 78 | + channel_creds, _token_call_credentials(token) |
| 79 | + ) |
| 80 | + return grpc.aio.secure_channel(target, channel_creds, options=_DEFAULT_OPTIONS) |
| 81 | + |
| 82 | + return grpc.aio.insecure_channel(target, options=_DEFAULT_OPTIONS) |
0 commit comments