feat: support custom token endpoint from service account credentials#6277
Open
stackitcarlos wants to merge 2 commits intostackitcloud:mainfrom
Open
feat: support custom token endpoint from service account credentials#6277stackitcarlos wants to merge 2 commits intostackitcloud:mainfrom
stackitcarlos wants to merge 2 commits intostackitcloud:mainfrom
Conversation
- Extended `KeyFlowConfig` with a `GetCredentialsTokenEndpoint` helper to safely extract custom token URLs from service account credentials. - Updated `KeyFlow.Init` to use the new helper, allowing the flow to fallback to the default `tokenAPI` gracefully if no custom endpoint is provided. - Added standard Go doc comments for KeyFlow methods. - Expanded `TestKeyFlowInit` to assert the resolved TokenUrl and added a new test scenario to verify the custom endpoint logic.
JorTurFer
reviewed
Apr 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
This PR introduces the ability to override the default token URL by reading a custom token endpoint directly from the Service Account Key credentials.
To implement this cleanly and avoid deeply nested conditional logic during initialization, a new helper function was added. This safely resolves the token URL while guaranteeing the default fallback behavior if the credentials or endpoint are missing.
Note: This PR serves as a preliminary step toward implementing Architecture Decision Record (ADR) 0025.
Key Changes:
KeyFlowConfigwith aGetCredentialsTokenEndpointhelper to safely extract custom token URLs from service account credentials.KeyFlow.Initto use the new helper, allowing the flow to fallback to the defaulttokenAPIgracefully if no custom endpoint is provided.KeyFlowmethods to improve code readability.TestKeyFlowInitto assert the resolvedTokenUrland added a new table-driven test scenario to verify the custom endpoint logic.Checklist
make fmtexamples/directory)make test(will be checked by CI)make lint(will be checked by CI)