codekingpro/portable-devtools
114k
1# Copyright (C) 2017 Google Inc.2#3# Licensed under the Apache License, Version 2.0 (the "License");4# you may not use this file except in compliance with the License.5# You may obtain a copy of the License at6#7# http://www.apache.org/licenses/LICENSE-2.08#9# Unless required by applicable law or agreed to in writing, software10# distributed under the License is distributed on an "AS IS" BASIS,11# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.12# See the License for the specific language governing permissions and13# limitations under the License.14 15"""Command-line tool for obtaining authorization and credentials from a user.16 17This tool uses the OAuth 2.0 Authorization Code grant as described in18`section 1.3.1 of RFC6749`_ and implemeted by19:class:`google_auth_oauthlib.flow.Flow`.20 21This tool is intended for assist developers in obtaining credentials22for testing applications where it may not be possible or easy to run a23complete OAuth 2.0 authorization flow, especially in the case of code24samples or embedded devices without input / display capabilities.25 26This is not intended for production use where a combination of27companion and on-device applications should complete the OAuth 2.028authorization flow to get authorization from the users.29 30.. _section 1.3.1 of RFC6749: https://tools.ietf.org/html/rfc6749#section-1.3.131"""32 33import json34import os35import os.path36 37import click38 39import google_auth_oauthlib.flow40 41 42APP_NAME = "google-oauthlib-tool"43DEFAULT_CREDENTIALS_FILENAME = "credentials.json"44 45 46@click.command()47@click.option(48 "--client-secrets",49 metavar="<client_secret_json_file>",50 required=True,51 help="Path to OAuth2 client secret JSON file.",52)53@click.option(54 "--scope",55 multiple=True,56 metavar="<oauth2 scope>",57 required=True,58 help="API scopes to authorize access for.",59)60@click.option(61 "--save",62 is_flag=True,63 metavar="<save_mode>",64 show_default=True,65 default=False,66 help="Save the credentials to file.",67)68@click.option(69 "--credentials",70 metavar="<oauth2_credentials>",71 show_default=True,72 default=os.path.join(click.get_app_dir(APP_NAME), DEFAULT_CREDENTIALS_FILENAME),73 help="Path to store OAuth2 credentials.",74)75def main(client_secrets, scope, save, credentials):76 """Command-line tool for obtaining authorization and credentials from a user.77 78 This tool uses the OAuth 2.0 Authorization Code grant as described79 in section 1.3.1 of RFC6749:80 https://tools.ietf.org/html/rfc6749#section-1.3.181 82 This tool is intended for assist developers in obtaining credentials83 for testing applications or samples.84 85 This is not intended for production use where a combination of86 companion and on-device applications should complete the OAuth 2.087 authorization flow to get authorization from the users.88 89 """90 91 flow = google_auth_oauthlib.flow.InstalledAppFlow.from_client_secrets_file(92 client_secrets, scopes=scope93 )94 95 creds = flow.run_local_server()96 97 creds_data = {98 "token": creds.token,99 "refresh_token": creds.refresh_token,100 "token_uri": creds.token_uri,101 "client_id": creds.client_id,102 "client_secret": creds.client_secret,103 "scopes": creds.scopes,104 }105 106 if save:107 del creds_data["token"]108 109 config_path = os.path.dirname(credentials)110 if config_path and not os.path.isdir(config_path):111 os.makedirs(config_path)112 113 with open(credentials, "w") as outfile:114 json.dump(creds_data, outfile)115 116 click.echo("credentials saved: %s" % credentials)117 118 else:119 click.echo(json.dumps(creds_data))120 121 122if __name__ == "__main__":123 # pylint doesn't realize that click has changed the function signature.124 main() # pylint: disable=no-value-for-parameter125 