Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Latest commit

 

History

History
History
112 lines (95 loc) · 3.46 KB

File metadata and controls

112 lines (95 loc) · 3.46 KB
Copy raw file
Download raw file
Open symbols panel
Edit and raw actions
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
# Copyright 2019 Google LLC All Rights Reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
# [START getting_started_auth_all]
import sys
from flask import Flask
app = Flask(__name__)
CERTS = None
AUDIENCE = None
# [START getting_started_auth_certs]
def certs():
"""Returns a dictionary of current Google public key certificates for
validating Google-signed JWTs. Since these change rarely, the result
is cached on first request for faster subsequent responses.
"""
import requests
global CERTS
if CERTS is None:
response = requests.get(
'https://www.gstatic.com/iap/verify/public_key'
)
CERTS = response.json()
return CERTS
# [END getting_started_auth_certs]
# [START getting_started_auth_metadata]
def get_metadata(item_name):
"""Returns a string with the project metadata value for the item_name.
See https://cloud.google.com/compute/docs/storing-retrieving-metadata for
possible item_name values.
"""
import requests
endpoint = 'http://metadata.google.internal'
path = '/computeMetadata/v1/project/'
path += item_name
response = requests.get(
'{}{}'.format(endpoint, path),
headers = {'Metadata-Flavor': 'Google'}
)
metadata = response.text
return metadata
# [END getting_started_auth_metadata]
# [START getting_started_auth_audience]
def audience():
"""Returns the audience value (the JWT 'aud' property) for the current
running instance. Since this involves a metadata lookup, the result is
cached when first requested for faster future responses.
"""
global AUDIENCE
if AUDIENCE is None:
project_number = get_metadata('numeric-project-id')
project_id = get_metadata('project-id')
AUDIENCE = '/projects/{}/apps/{}'.format(
project_number, project_id
)
return AUDIENCE
# [END getting_started_auth_audience]
# [START getting_started_auth_validate_assertion]
def validate_assertion(assertion):
"""Checks that the JWT assertion is valid (properly signed, for the
correct audience) and if so, returns strings for the requesting user's
email and a persistent user ID. If not valid, returns None for each field.
"""
from jose import jwt
try:
info = jwt.decode(
assertion,
certs(),
algorithms=['ES256'],
audience=audience()
)
return info['email'], info['sub']
except Exception as e:
print('Failed to validate assertion: {}'.format(e), file=sys.stderr)
return None, None
# [END getting_started_auth_validate_assertion]
# [START getting_started_auth_front_controller]
@app.route('/', methods=['GET'])
def say_hello():
from flask import request
assertion = request.headers.get('X-Goog-IAP-JWT-Assertion')
email, id = validate_assertion(assertion)
page = "<h1>Hello {}</h1>".format(email)
return page
# [END getting_started_auth_front_controller]
# [END getting_started_auth_all]
Morty Proxy This is a proxified and sanitized view of the page, visit original site.