Package com.google.auth.oauth2
Class ExternalAccountCredentials.Builder
- java.lang.Object
-
- com.google.auth.oauth2.OAuth2Credentials.Builder
-
- com.google.auth.oauth2.GoogleCredentials.Builder
-
- com.google.auth.oauth2.ExternalAccountCredentials.Builder
-
- Direct Known Subclasses:
AwsCredentials.Builder
,IdentityPoolCredentials.Builder
,PluggableAuthCredentials.Builder
- Enclosing class:
- ExternalAccountCredentials
public abstract static class ExternalAccountCredentials.Builder extends GoogleCredentials.Builder
Base builder for external account credentials.
-
-
Field Summary
Fields Modifier and Type Field Description protected String
audience
protected String
clientId
protected String
clientSecret
protected com.google.auth.oauth2.ExternalAccountCredentials.CredentialSource
credentialSource
protected com.google.auth.oauth2.EnvironmentProvider
environmentProvider
protected Collection<String>
scopes
protected com.google.auth.oauth2.ExternalAccountCredentials.ServiceAccountImpersonationOptions
serviceAccountImpersonationOptions
protected String
serviceAccountImpersonationUrl
protected String
subjectTokenType
protected String
tokenInfoUrl
protected String
tokenUrl
protected HttpTransportFactory
transportFactory
protected String
universeDomain
protected String
workforcePoolUserProject
-
Fields inherited from class com.google.auth.oauth2.GoogleCredentials.Builder
quotaProjectId
-
-
Constructor Summary
Constructors Modifier Constructor Description protected
Builder()
protected
Builder(ExternalAccountCredentials credentials)
-
Method Summary
All Methods Instance Methods Abstract Methods Concrete Methods Modifier and Type Method Description abstract ExternalAccountCredentials
build()
ExternalAccountCredentials.Builder
setAudience(String audience)
Sets the Security Token Service audience, which is usually the fully specified resource name of the workload/workforce pool provider.ExternalAccountCredentials.Builder
setClientId(String clientId)
Sets the optional client ID of the service account from the console.ExternalAccountCredentials.Builder
setClientSecret(String clientSecret)
Sets the optional client secret of the service account from the console.ExternalAccountCredentials.Builder
setCredentialSource(com.google.auth.oauth2.ExternalAccountCredentials.CredentialSource credentialSource)
Sets the external credential source.ExternalAccountCredentials.Builder
setHttpTransportFactory(HttpTransportFactory transportFactory)
Sets the HTTP transport factory, creates the transport used to get access tokens.ExternalAccountCredentials.Builder
setQuotaProjectId(String quotaProjectId)
Sets the optional project used for quota and billing purposes.ExternalAccountCredentials.Builder
setScopes(Collection<String> scopes)
Sets the optional scopes to request during the authorization grant.ExternalAccountCredentials.Builder
setServiceAccountImpersonationOptions(Map<String,Object> optionsMap)
Sets the optional service account impersonation options.ExternalAccountCredentials.Builder
setServiceAccountImpersonationUrl(String serviceAccountImpersonationUrl)
Sets the optional URL used for service account impersonation, which is required for some APIs.ExternalAccountCredentials.Builder
setSubjectTokenType(String subjectTokenType)
Sets the Security Token Service subject token type based on the OAuth 2.0 token exchange spec.ExternalAccountCredentials.Builder
setTokenInfoUrl(String tokenInfoUrl)
Sets the optional endpoint used to retrieve account related information.ExternalAccountCredentials.Builder
setTokenUrl(String tokenUrl)
Sets the Security Token Service token exchange endpoint.ExternalAccountCredentials.Builder
setUniverseDomain(String universeDomain)
Sets the optional universe domain.ExternalAccountCredentials.Builder
setWorkforcePoolUserProject(String workforcePoolUserProject)
Sets the optional workforce pool user project number when the credential corresponds to a workforce pool and not a workload identity pool.-
Methods inherited from class com.google.auth.oauth2.GoogleCredentials.Builder
getQuotaProjectId, setAccessToken
-
Methods inherited from class com.google.auth.oauth2.OAuth2Credentials.Builder
getAccessToken, getExpirationMargin, getRefreshMargin, setExpirationMargin, setRefreshMargin
-
-
-
-
Field Detail
-
audience
protected String audience
-
subjectTokenType
protected String subjectTokenType
-
tokenUrl
protected String tokenUrl
-
tokenInfoUrl
protected String tokenInfoUrl
-
credentialSource
protected com.google.auth.oauth2.ExternalAccountCredentials.CredentialSource credentialSource
-
environmentProvider
protected com.google.auth.oauth2.EnvironmentProvider environmentProvider
-
transportFactory
protected HttpTransportFactory transportFactory
-
scopes
@Nullable protected Collection<String> scopes
-
serviceAccountImpersonationOptions
@Nullable protected com.google.auth.oauth2.ExternalAccountCredentials.ServiceAccountImpersonationOptions serviceAccountImpersonationOptions
-
-
Constructor Detail
-
Builder
protected Builder()
-
Builder
protected Builder(ExternalAccountCredentials credentials)
-
-
Method Detail
-
setHttpTransportFactory
public ExternalAccountCredentials.Builder setHttpTransportFactory(HttpTransportFactory transportFactory)
Sets the HTTP transport factory, creates the transport used to get access tokens.- Parameters:
transportFactory
- theHttpTransportFactory
to set- Returns:
- this
Builder
object
-
setAudience
public ExternalAccountCredentials.Builder setAudience(String audience)
Sets the Security Token Service audience, which is usually the fully specified resource name of the workload/workforce pool provider.- Parameters:
audience
- the Security Token Service audience to set- Returns:
- this
Builder
object
-
setSubjectTokenType
public ExternalAccountCredentials.Builder setSubjectTokenType(String subjectTokenType)
Sets the Security Token Service subject token type based on the OAuth 2.0 token exchange spec. Indicates the type of the security token in the credential file.- Parameters:
subjectTokenType
- the Security Token Service subject token type to set- Returns:
- this
Builder
object
-
setTokenUrl
public ExternalAccountCredentials.Builder setTokenUrl(String tokenUrl)
Sets the Security Token Service token exchange endpoint.- Parameters:
tokenUrl
- the Security Token Service token exchange url to set- Returns:
- this
Builder
object
-
setCredentialSource
public ExternalAccountCredentials.Builder setCredentialSource(com.google.auth.oauth2.ExternalAccountCredentials.CredentialSource credentialSource)
Sets the external credential source.- Parameters:
credentialSource
- theCredentialSource
to set- Returns:
- this
Builder
object
-
setServiceAccountImpersonationUrl
public ExternalAccountCredentials.Builder setServiceAccountImpersonationUrl(String serviceAccountImpersonationUrl)
Sets the optional URL used for service account impersonation, which is required for some APIs. If this URL is not available, the access token from the Security Token Service is used directly.- Parameters:
serviceAccountImpersonationUrl
- the service account impersonation url to set- Returns:
- this
Builder
object
-
setTokenInfoUrl
public ExternalAccountCredentials.Builder setTokenInfoUrl(String tokenInfoUrl)
Sets the optional endpoint used to retrieve account related information. Required for gCloud session account identification.- Parameters:
tokenInfoUrl
- the token info url to set- Returns:
- this
Builder
object
-
setQuotaProjectId
public ExternalAccountCredentials.Builder setQuotaProjectId(String quotaProjectId)
Sets the optional project used for quota and billing purposes.- Overrides:
setQuotaProjectId
in classGoogleCredentials.Builder
- Parameters:
quotaProjectId
- the quota and billing project id to set- Returns:
- this
Builder
object
-
setClientId
public ExternalAccountCredentials.Builder setClientId(String clientId)
Sets the optional client ID of the service account from the console.- Parameters:
clientId
- the service account client id to set- Returns:
- this
Builder
object
-
setClientSecret
public ExternalAccountCredentials.Builder setClientSecret(String clientSecret)
Sets the optional client secret of the service account from the console.- Parameters:
clientSecret
- the service account client secret to set- Returns:
- this
Builder
object
-
setScopes
public ExternalAccountCredentials.Builder setScopes(Collection<String> scopes)
Sets the optional scopes to request during the authorization grant.- Parameters:
scopes
- the request scopes to set- Returns:
- this
Builder
object
-
setWorkforcePoolUserProject
public ExternalAccountCredentials.Builder setWorkforcePoolUserProject(String workforcePoolUserProject)
Sets the optional workforce pool user project number when the credential corresponds to a workforce pool and not a workload identity pool. The underlying principal must still have serviceusage.services.use IAM permission to use the project for billing/quota.- Parameters:
workforcePoolUserProject
- the workforce pool user project number to set- Returns:
- this
Builder
object
-
setServiceAccountImpersonationOptions
public ExternalAccountCredentials.Builder setServiceAccountImpersonationOptions(Map<String,Object> optionsMap)
Sets the optional service account impersonation options.- Parameters:
optionsMap
- the service account impersonation options to set- Returns:
- this
Builder
object
-
setUniverseDomain
public ExternalAccountCredentials.Builder setUniverseDomain(String universeDomain)
Sets the optional universe domain.- Parameters:
universeDomain
- the universe domain to set- Returns:
- this
Builder
object
-
build
public abstract ExternalAccountCredentials build()
- Overrides:
build
in classGoogleCredentials.Builder
-
-