Team Ai
Datasetpublic

codekingpro/portable-devtools

sourceHugging Faceupdated 5mo agoView on Hugging Face
1likes14kdownloads
auth.proto239 linesDownload Raw Back to api
1// Copyright 2026 Google LLC2//3// Licensed under the Apache License, Version 2.0 (the "License");4// you may not use this file except in compliance with the License.5// You may obtain a copy of the License at6//7//     http://www.apache.org/licenses/LICENSE-2.08//9// Unless required by applicable law or agreed to in writing, software10// distributed under the License is distributed on an "AS IS" BASIS,11// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.12// See the License for the specific language governing permissions and13// limitations under the License.14 15syntax = "proto3";16 17package google.api;18 19option go_package = "google.golang.org/genproto/googleapis/api/serviceconfig;serviceconfig";20option java_multiple_files = true;21option java_outer_classname = "AuthProto";22option java_package = "com.google.api";23option objc_class_prefix = "GAPI";24 25// `Authentication` defines the authentication configuration for API methods26// provided by an API service.27//28// Example:29//30//     name: calendar.googleapis.com31//     authentication:32//       providers:33//       - id: google_calendar_auth34//         jwks_uri: https://www.googleapis.com/oauth2/v1/certs35//         issuer: https://securetoken.google.com36//       rules:37//       - selector: "*"38//         requirements:39//           provider_id: google_calendar_auth40//       - selector: google.calendar.Delegate41//         oauth:42//           canonical_scopes: https://www.googleapis.com/auth/calendar.read43message Authentication {44  // A list of authentication rules that apply to individual API methods.45  //46  // **NOTE:** All service configuration rules follow "last one wins" order.47  repeated AuthenticationRule rules = 3;48 49  // Defines a set of authentication providers that a service supports.50  repeated AuthProvider providers = 4;51}52 53// Authentication rules for the service.54//55// By default, if a method has any authentication requirements, every request56// must include a valid credential matching one of the requirements.57// It's an error to include more than one kind of credential in a single58// request.59//60// If a method doesn't have any auth requirements, request credentials will be61// ignored.62message AuthenticationRule {63  // Selects the methods to which this rule applies.64  //65  // Refer to [selector][google.api.DocumentationRule.selector] for syntax66  // details.67  string selector = 1;68 69  // The requirements for OAuth credentials.70  OAuthRequirements oauth = 2;71 72  // If true, the service accepts API keys without any other credential.73  // This flag only applies to HTTP and gRPC requests.74  bool allow_without_credential = 5;75 76  // Requirements for additional authentication providers.77  repeated AuthRequirement requirements = 7;78}79 80// Specifies a location to extract JWT from an API request.81message JwtLocation {82  oneof in {83    // Specifies HTTP header name to extract JWT token.84    string header = 1;85 86    // Specifies URL query parameter name to extract JWT token.87    string query = 2;88 89    // Specifies cookie name to extract JWT token.90    string cookie = 4;91  }92 93  // The value prefix. The value format is "value_prefix{token}"94  // Only applies to "in" header type. Must be empty for "in" query type.95  // If not empty, the header value has to match (case sensitive) this prefix.96  // If not matched, JWT will not be extracted. If matched, JWT will be97  // extracted after the prefix is removed.98  //99  // For example, for "Authorization: Bearer {JWT}",100  // value_prefix="Bearer " with a space at the end.101  string value_prefix = 3;102}103 104// Configuration for an authentication provider, including support for105// [JSON Web Token106// (JWT)](https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-32).107message AuthProvider {108  // The unique identifier of the auth provider. It will be referred to by109  // `AuthRequirement.provider_id`.110  //111  // Example: "bookstore_auth".112  string id = 1;113 114  // Identifies the principal that issued the JWT. See115  // https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-32#section-4.1.1116  // Usually a URL or an email address.117  //118  // Example: https://securetoken.google.com119  // Example: 1234567-compute@developer.gserviceaccount.com120  string issuer = 2;121 122  // URL of the provider's public key set to validate signature of the JWT. See123  // [OpenID124  // Discovery](https://openid.net/specs/openid-connect-discovery-1_0.html#ProviderMetadata).125  // Optional if the key set document:126  //  - can be retrieved from127  //    [OpenID128  //    Discovery](https://openid.net/specs/openid-connect-discovery-1_0.html)129  //    of the issuer.130  //  - can be inferred from the email domain of the issuer (e.g. a Google131  //  service account).132  //133  // Example: https://www.googleapis.com/oauth2/v1/certs134  string jwks_uri = 3;135 136  // The list of JWT137  // [audiences](https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-32#section-4.1.3).138  // that are allowed to access. A JWT containing any of these audiences will139  // be accepted. When this setting is absent, JWTs with audiences:140  //   - "https://[service.name]/[google.protobuf.Api.name]"141  //   - "https://[service.name]/"142  // will be accepted.143  // For example, if no audiences are in the setting, LibraryService API will144  // accept JWTs with the following audiences:145  //   -146  //   https://library-example.googleapis.com/google.example.library.v1.LibraryService147  //   - https://library-example.googleapis.com/148  //149  // Example:150  //151  //     audiences: bookstore_android.apps.googleusercontent.com,152  //                bookstore_web.apps.googleusercontent.com153  string audiences = 4;154 155  // Redirect URL if JWT token is required but not present or is expired.156  // Implement authorizationUrl of securityDefinitions in OpenAPI spec.157  string authorization_url = 5;158 159  // Defines the locations to extract the JWT.  For now it is only used by the160  // Cloud Endpoints to store the OpenAPI extension [x-google-jwt-locations]161  // (https://cloud.google.com/endpoints/docs/openapi/openapi-extensions#x-google-jwt-locations)162  //163  // JWT locations can be one of HTTP headers, URL query parameters or164  // cookies. The rule is that the first match wins.165  //166  // If not specified,  default to use following 3 locations:167  //    1) Authorization: Bearer168  //    2) x-goog-iap-jwt-assertion169  //    3) access_token query parameter170  //171  // Default locations can be specified as followings:172  //    jwt_locations:173  //    - header: Authorization174  //      value_prefix: "Bearer "175  //    - header: x-goog-iap-jwt-assertion176  //    - query: access_token177  repeated JwtLocation jwt_locations = 6;178}179 180// OAuth scopes are a way to define data and permissions on data. For example,181// there are scopes defined for "Read-only access to Google Calendar" and182// "Access to Cloud Platform". Users can consent to a scope for an application,183// giving it permission to access that data on their behalf.184//185// OAuth scope specifications should be fairly coarse grained; a user will need186// to see and understand the text description of what your scope means.187//188// In most cases: use one or at most two OAuth scopes for an entire family of189// products. If your product has multiple APIs, you should probably be sharing190// the OAuth scope across all of those APIs.191//192// When you need finer grained OAuth consent screens: talk with your product193// management about how developers will use them in practice.194//195// Please note that even though each of the canonical scopes is enough for a196// request to be accepted and passed to the backend, a request can still fail197// due to the backend requiring additional scopes or permissions.198message OAuthRequirements {199  // The list of publicly documented OAuth scopes that are allowed access. An200  // OAuth token containing any of these scopes will be accepted.201  //202  //203  // Example:204  //205  //      canonical_scopes: https://www.googleapis.com/auth/calendar,206  //                        https://www.googleapis.com/auth/calendar.read207  string canonical_scopes = 1;208}209 210// User-defined authentication requirements, including support for211// [JSON Web Token212// (JWT)](https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-32).213message AuthRequirement {214  // [id][google.api.AuthProvider.id] from authentication provider.215  //216  // Example:217  //218  //     provider_id: bookstore_auth219  string provider_id = 1;220 221  // NOTE: This will be deprecated soon, once AuthProvider.audiences is222  // implemented and accepted in all the runtime components.223  //224  // The list of JWT225  // [audiences](https://tools.ietf.org/html/draft-ietf-oauth-json-web-token-32#section-4.1.3).226  // that are allowed to access. A JWT containing any of these audiences will227  // be accepted. When this setting is absent, only JWTs with audience228  // "https://[Service_name][google.api.Service.name]/[API_name][google.protobuf.Api.name]"229  // will be accepted. For example, if no audiences are in the setting,230  // LibraryService API will only accept JWTs with the following audience231  // "https://library-example.googleapis.com/google.example.library.v1.LibraryService".232  //233  // Example:234  //235  //     audiences: bookstore_android.apps.googleusercontent.com,236  //                bookstore_web.apps.googleusercontent.com237  string audiences = 2;238}239 
codekingpro/portable-devtools · Team Ai