Skip to main content

reqsign_google/
lib.rs

1// Licensed to the Apache Software Foundation (ASF) under one
2// or more contributor license agreements.  See the NOTICE file
3// distributed with this work for additional information
4// regarding copyright ownership.  The ASF licenses this file
5// to you under the Apache License, Version 2.0 (the
6// "License"); you may not use this file except in compliance
7// with the License.  You may obtain a copy of the License at
8//
9//   http://www.apache.org/licenses/LICENSE-2.0
10//
11// Unless required by applicable law or agreed to in writing,
12// software distributed under the License is distributed on an
13// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14// KIND, either express or implied.  See the License for the
15// specific language governing permissions and limitations
16// under the License.
17
18//! Google Service Signer
19//!
20//! Generic service-account impersonation accepts any token-only Google source
21//! provider and can feed its output into a signer or Credential Access Boundary
22//! grant.
23//!
24//! Typed server-side Cloud Storage Credential Access Boundary downscoping is
25//! always available. Enable the `credential-access-boundary-client-side`
26//! feature for local client-side token generation.
27
28mod constants;
29
30mod credential;
31pub use credential::{Credential, ServiceAccount, Token};
32
33mod credential_access_boundary;
34#[cfg(feature = "credential-access-boundary-client-side")]
35pub use credential_access_boundary::ClientSideCredentialAccessBoundaryGranter;
36pub use credential_access_boundary::{
37    CredentialAccessBoundaryGrant, CredentialAccessBoundaryPermissions,
38    ServerSideCredentialAccessBoundaryGranter,
39};
40
41mod service_account_impersonation;
42pub use service_account_impersonation::{
43    ServiceAccountImpersonationCredentialProvider, ServiceAccountImpersonationGrant,
44    ServiceAccountImpersonationGranter,
45};
46
47mod sign_request;
48pub use sign_request::RequestSigner;
49
50mod provide_credential;
51pub use provide_credential::{
52    DefaultCredentialProvider, DefaultCredentialProviderBuilder, EnvCredentialProvider,
53    ExternalAccountConfig, ExternalAccountCredentialProvider, FileCredentialProvider,
54    ServiceAccountTokenCredentialProvider, StaticCredentialProvider, TokenCredentialProvider,
55    VmMetadataCredentialProvider, WellKnownCredentialProvider,
56};