added service account in google drive credentials for dwd support (#4596)

This commit is contained in:
Shahzad Haider
2025-12-10 20:50:10 +05:00
committed by GitHub
parent 702bbefa35
commit a90798cfbb
6 changed files with 740 additions and 472 deletions
+98 -3
View File
@@ -828,6 +828,77 @@ func (x *SlackTokens) GetClientToken() string {
return ""
}
type GoogleDriveDWD struct {
state protoimpl.MessageState
sizeCache protoimpl.SizeCache
unknownFields protoimpl.UnknownFields
ServiceAccountJson string `protobuf:"bytes,1,opt,name=service_account_json,json=serviceAccountJson,proto3" json:"service_account_json,omitempty"`
AdminEmail string `protobuf:"bytes,2,opt,name=admin_email,json=adminEmail,proto3" json:"admin_email,omitempty"`
IncludeUsers []string `protobuf:"bytes,3,rep,name=include_users,json=includeUsers,proto3" json:"include_users,omitempty"`
ExcludeUsers []string `protobuf:"bytes,4,rep,name=exclude_users,json=excludeUsers,proto3" json:"exclude_users,omitempty"`
}
func (x *GoogleDriveDWD) Reset() {
*x = GoogleDriveDWD{}
if protoimpl.UnsafeEnabled {
mi := &file_credentials_proto_msgTypes[14]
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
ms.StoreMessageInfo(mi)
}
}
func (x *GoogleDriveDWD) String() string {
return protoimpl.X.MessageStringOf(x)
}
func (*GoogleDriveDWD) ProtoMessage() {}
func (x *GoogleDriveDWD) ProtoReflect() protoreflect.Message {
mi := &file_credentials_proto_msgTypes[14]
if protoimpl.UnsafeEnabled && x != nil {
ms := protoimpl.X.MessageStateOf(protoimpl.Pointer(x))
if ms.LoadMessageInfo() == nil {
ms.StoreMessageInfo(mi)
}
return ms
}
return mi.MessageOf(x)
}
// Deprecated: Use GoogleDriveDWD.ProtoReflect.Descriptor instead.
func (*GoogleDriveDWD) Descriptor() ([]byte, []int) {
return file_credentials_proto_rawDescGZIP(), []int{14}
}
func (x *GoogleDriveDWD) GetServiceAccountJson() string {
if x != nil {
return x.ServiceAccountJson
}
return ""
}
func (x *GoogleDriveDWD) GetAdminEmail() string {
if x != nil {
return x.AdminEmail
}
return ""
}
func (x *GoogleDriveDWD) GetIncludeUsers() []string {
if x != nil {
return x.IncludeUsers
}
return nil
}
func (x *GoogleDriveDWD) GetExcludeUsers() []string {
if x != nil {
return x.ExcludeUsers
}
return nil
}
var File_credentials_proto protoreflect.FileDescriptor
var file_credentials_proto_rawDesc = []byte{
@@ -912,7 +983,18 @@ var file_credentials_proto_rawDesc = []byte{
0x18, 0x02, 0x20, 0x01, 0x28, 0x09, 0x52, 0x08, 0x62, 0x6f, 0x74, 0x54, 0x6f, 0x6b, 0x65, 0x6e,
0x12, 0x21, 0x0a, 0x0c, 0x63, 0x6c, 0x69, 0x65, 0x6e, 0x74, 0x5f, 0x74, 0x6f, 0x6b, 0x65, 0x6e,
0x18, 0x03, 0x20, 0x01, 0x28, 0x09, 0x52, 0x0b, 0x63, 0x6c, 0x69, 0x65, 0x6e, 0x74, 0x54, 0x6f,
0x6b, 0x65, 0x6e, 0x42, 0x3f, 0x5a, 0x3d, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f,
0x6b, 0x65, 0x6e, 0x22, 0xad, 0x01, 0x0a, 0x0e, 0x47, 0x6f, 0x6f, 0x67, 0x6c, 0x65, 0x44, 0x72,
0x69, 0x76, 0x65, 0x44, 0x57, 0x44, 0x12, 0x30, 0x0a, 0x14, 0x73, 0x65, 0x72, 0x76, 0x69, 0x63,
0x65, 0x5f, 0x61, 0x63, 0x63, 0x6f, 0x75, 0x6e, 0x74, 0x5f, 0x6a, 0x73, 0x6f, 0x6e, 0x18, 0x01,
0x20, 0x01, 0x28, 0x09, 0x52, 0x12, 0x73, 0x65, 0x72, 0x76, 0x69, 0x63, 0x65, 0x41, 0x63, 0x63,
0x6f, 0x75, 0x6e, 0x74, 0x4a, 0x73, 0x6f, 0x6e, 0x12, 0x1f, 0x0a, 0x0b, 0x61, 0x64, 0x6d, 0x69,
0x6e, 0x5f, 0x65, 0x6d, 0x61, 0x69, 0x6c, 0x18, 0x02, 0x20, 0x01, 0x28, 0x09, 0x52, 0x0a, 0x61,
0x64, 0x6d, 0x69, 0x6e, 0x45, 0x6d, 0x61, 0x69, 0x6c, 0x12, 0x23, 0x0a, 0x0d, 0x69, 0x6e, 0x63,
0x6c, 0x75, 0x64, 0x65, 0x5f, 0x75, 0x73, 0x65, 0x72, 0x73, 0x18, 0x03, 0x20, 0x03, 0x28, 0x09,
0x52, 0x0c, 0x69, 0x6e, 0x63, 0x6c, 0x75, 0x64, 0x65, 0x55, 0x73, 0x65, 0x72, 0x73, 0x12, 0x23,
0x0a, 0x0d, 0x65, 0x78, 0x63, 0x6c, 0x75, 0x64, 0x65, 0x5f, 0x75, 0x73, 0x65, 0x72, 0x73, 0x18,
0x04, 0x20, 0x03, 0x28, 0x09, 0x52, 0x0c, 0x65, 0x78, 0x63, 0x6c, 0x75, 0x64, 0x65, 0x55, 0x73,
0x65, 0x72, 0x73, 0x42, 0x3f, 0x5a, 0x3d, 0x67, 0x69, 0x74, 0x68, 0x75, 0x62, 0x2e, 0x63, 0x6f,
0x6d, 0x2f, 0x74, 0x72, 0x75, 0x66, 0x66, 0x6c, 0x65, 0x73, 0x65, 0x63, 0x75, 0x72, 0x69, 0x74,
0x79, 0x2f, 0x74, 0x72, 0x75, 0x66, 0x66, 0x6c, 0x65, 0x68, 0x6f, 0x67, 0x2f, 0x76, 0x33, 0x2f,
0x70, 0x6b, 0x67, 0x2f, 0x70, 0x62, 0x2f, 0x63, 0x72, 0x65, 0x64, 0x65, 0x6e, 0x74, 0x69, 0x61,
@@ -931,7 +1013,7 @@ func file_credentials_proto_rawDescGZIP() []byte {
return file_credentials_proto_rawDescData
}
var file_credentials_proto_msgTypes = make([]protoimpl.MessageInfo, 14)
var file_credentials_proto_msgTypes = make([]protoimpl.MessageInfo, 15)
var file_credentials_proto_goTypes = []interface{}{
(*Unauthenticated)(nil), // 0: credentials.Unauthenticated
(*SSHAuth)(nil), // 1: credentials.SSHAuth
@@ -947,6 +1029,7 @@ var file_credentials_proto_goTypes = []interface{}{
(*SES)(nil), // 11: credentials.SES
(*GitHubApp)(nil), // 12: credentials.GitHubApp
(*SlackTokens)(nil), // 13: credentials.SlackTokens
(*GoogleDriveDWD)(nil), // 14: credentials.GoogleDriveDWD
}
var file_credentials_proto_depIdxs = []int32{
10, // 0: credentials.SES.creds:type_name -> credentials.AWS
@@ -1131,6 +1214,18 @@ func file_credentials_proto_init() {
return nil
}
}
file_credentials_proto_msgTypes[14].Exporter = func(v interface{}, i int) interface{} {
switch v := v.(*GoogleDriveDWD); i {
case 0:
return &v.state
case 1:
return &v.sizeCache
case 2:
return &v.unknownFields
default:
return nil
}
}
}
type x struct{}
out := protoimpl.TypeBuilder{
@@ -1138,7 +1233,7 @@ func file_credentials_proto_init() {
GoPackagePath: reflect.TypeOf(x{}).PkgPath(),
RawDescriptor: file_credentials_proto_rawDesc,
NumEnums: 0,
NumMessages: 14,
NumMessages: 15,
NumExtensions: 0,
NumServices: 0,
},
@@ -1562,3 +1562,107 @@ var _ interface {
Cause() error
ErrorName() string
} = SlackTokensValidationError{}
// Validate checks the field values on GoogleDriveDWD with the rules defined in
// the proto definition for this message. If any rules are violated, the first
// error encountered is returned, or nil if there are no violations.
func (m *GoogleDriveDWD) Validate() error {
return m.validate(false)
}
// ValidateAll checks the field values on GoogleDriveDWD with the rules defined
// in the proto definition for this message. If any rules are violated, the
// result is a list of violation errors wrapped in GoogleDriveDWDMultiError,
// or nil if none found.
func (m *GoogleDriveDWD) ValidateAll() error {
return m.validate(true)
}
func (m *GoogleDriveDWD) validate(all bool) error {
if m == nil {
return nil
}
var errors []error
// no validation rules for ServiceAccountJson
// no validation rules for AdminEmail
if len(errors) > 0 {
return GoogleDriveDWDMultiError(errors)
}
return nil
}
// GoogleDriveDWDMultiError is an error wrapping multiple validation errors
// returned by GoogleDriveDWD.ValidateAll() if the designated constraints
// aren't met.
type GoogleDriveDWDMultiError []error
// Error returns a concatenation of all the error messages it wraps.
func (m GoogleDriveDWDMultiError) Error() string {
var msgs []string
for _, err := range m {
msgs = append(msgs, err.Error())
}
return strings.Join(msgs, "; ")
}
// AllErrors returns a list of validation violation errors.
func (m GoogleDriveDWDMultiError) AllErrors() []error { return m }
// GoogleDriveDWDValidationError is the validation error returned by
// GoogleDriveDWD.Validate if the designated constraints aren't met.
type GoogleDriveDWDValidationError struct {
field string
reason string
cause error
key bool
}
// Field function returns field value.
func (e GoogleDriveDWDValidationError) Field() string { return e.field }
// Reason function returns reason value.
func (e GoogleDriveDWDValidationError) Reason() string { return e.reason }
// Cause function returns cause value.
func (e GoogleDriveDWDValidationError) Cause() error { return e.cause }
// Key function returns key value.
func (e GoogleDriveDWDValidationError) Key() bool { return e.key }
// ErrorName returns error name.
func (e GoogleDriveDWDValidationError) ErrorName() string { return "GoogleDriveDWDValidationError" }
// Error satisfies the builtin error interface
func (e GoogleDriveDWDValidationError) Error() string {
cause := ""
if e.cause != nil {
cause = fmt.Sprintf(" | caused by: %v", e.cause)
}
key := ""
if e.key {
key = "key for "
}
return fmt.Sprintf(
"invalid %sGoogleDriveDWD.%s: %s%s",
key,
e.field,
e.reason,
cause)
}
var _ error = GoogleDriveDWDValidationError{}
var _ interface {
Field() string
Reason() string
Key() bool
Cause() error
ErrorName() string
} = GoogleDriveDWDValidationError{}
File diff suppressed because it is too large Load Diff
+41
View File
@@ -3276,6 +3276,47 @@ func (m *GoogleDrive) validate(all bool) error {
}
}
case *GoogleDrive_Dwd:
if v == nil {
err := GoogleDriveValidationError{
field: "Credential",
reason: "oneof value cannot be a typed-nil",
}
if !all {
return err
}
errors = append(errors, err)
}
if all {
switch v := interface{}(m.GetDwd()).(type) {
case interface{ ValidateAll() error }:
if err := v.ValidateAll(); err != nil {
errors = append(errors, GoogleDriveValidationError{
field: "Dwd",
reason: "embedded message failed validation",
cause: err,
})
}
case interface{ Validate() error }:
if err := v.Validate(); err != nil {
errors = append(errors, GoogleDriveValidationError{
field: "Dwd",
reason: "embedded message failed validation",
cause: err,
})
}
}
} else if v, ok := interface{}(m.GetDwd()).(interface{ Validate() error }); ok {
if err := v.Validate(); err != nil {
return GoogleDriveValidationError{
field: "Dwd",
reason: "embedded message failed validation",
cause: err,
}
}
}
default:
_ = v // ensures v is used
}
+7
View File
@@ -77,3 +77,10 @@ message SlackTokens {
string bot_token = 2;
string client_token = 3;
}
message GoogleDriveDWD {
string service_account_json = 1;
string admin_email = 2;
repeated string include_users = 3;
repeated string exclude_users = 4;
}
+1
View File
@@ -311,6 +311,7 @@ message GoogleDrive {
string refresh_token = 1;
bool use_token_service = 2;
credentials.Oauth2 oauth = 3; // on-prem scanning
credentials.GoogleDriveDWD dwd = 4; // Domain-Wide Delegation
}
}