(ctx context.Context, serviceLabel string, email string, scopes []string)
| 171 | } |
| 172 | |
| 173 | func optionsForServiceAccountScopes(ctx context.Context, serviceLabel string, email string, scopes []string) ([]option.ClientOption, error) { |
| 174 | if dependencies, ok := authDependenciesFromContext(ctx); ok && dependencies.Mode == AuthModeADC { |
| 175 | slog.Debug("using Application Default Credentials (GOG_AUTH_MODE=adc)", "serviceLabel", serviceLabel) |
| 176 | |
| 177 | ts, err := dependencies.adcTokenSource(ctx, scopes) |
| 178 | if err != nil { |
| 179 | return nil, err |
| 180 | } |
| 181 | |
| 182 | return tokenSourceClientOptions(ctx, ts), nil |
| 183 | } |
| 184 | |
| 185 | if accessToken := authclient.AccessTokenFromContext(ctx); accessToken != "" { |
| 186 | slog.Debug("using direct access token", "serviceLabel", serviceLabel) |
| 187 | |
| 188 | return tokenSourceClientOptions(ctx, oauth2.StaticTokenSource(&oauth2.Token{AccessToken: accessToken})), nil |
| 189 | } |
| 190 | |
| 191 | dependencies, err := requireAuthDependencies(ctx) |
| 192 | if err != nil { |
| 193 | return nil, err |
| 194 | } |
| 195 | |
| 196 | ts, path, ok, err := tokenSourceForServiceAccountScopes(ctx, dependencies, serviceLabel, email, scopes) |
| 197 | if err != nil { |
| 198 | return nil, fmt.Errorf("service account token source: %w", err) |
| 199 | } |
| 200 | |
| 201 | if !ok { |
| 202 | return nil, &AuthRequiredError{Service: serviceLabel, Email: email} |
| 203 | } |
| 204 | |
| 205 | slog.Debug("using required service account credentials", "email", email, "path", path) |
| 206 | |
| 207 | return tokenSourceClientOptions(ctx, ts), nil |
| 208 | } |
| 209 | |
| 210 | func tokenSourceClientOptions(ctx context.Context, ts oauth2.TokenSource) []option.ClientOption { |
| 211 | return []option.ClientOption{option.WithHTTPClient(&http.Client{ |
no test coverage detected