Page MenuHomePhabricator

[comm-lib] Let BlobServiceClient accept service-to-service token
ClosedPublic

Authored by bartek on Sep 13 2024, 2:28 AM.
Tags
None
Referenced Files
Unknown Object (File)
Sat, Feb 15, 9:29 PM
Unknown Object (File)
Sat, Feb 1, 12:24 AM
Unknown Object (File)
Sat, Feb 1, 12:24 AM
Unknown Object (File)
Sat, Feb 1, 12:22 AM
Unknown Object (File)
Jan 15 2025, 6:16 AM
Unknown Object (File)
Jan 6 2025, 8:19 PM
Unknown Object (File)
Dec 27 2024, 1:42 AM
Unknown Object (File)
Dec 27 2024, 1:42 AM
Subscribers

Details

Summary

Updated BlobServiceClient to accept service-to-service token requests. This means HTTP services that rely on this Blob client, can accept service-to-service token and pass it through to Blob Service.

In short, previously:

  • client -[CSAT]-> backup -[S2SToken]-> blob was possible
  • identity -[S2SToken]-> backup -[S2SToken]-> blob wasn't possible

This diff makes the latter possible too, by overriding the accepts_services_token() for BlobServiceClient.

Test Plan

Ran Backup and Blob locally, supplied Backup request with service-to-service token instead of CSAT, made sure the COMM_SERVICES_DISABLE_CSAT_VERIFICATION is disabled. Request succeeded.

Diff Detail

Repository
rCOMM Comm
Lint
No Lint Coverage
Unit
No Test Coverage