【问题标题】:Access Google App Engine endpoint from Firebase cloud function从 Firebase 云功能访问 Google App Engine 端点
【发布时间】:2018-06-24 18:22:47
【问题描述】:

我有一个 firebase 云功能,它会在 firebase 实时数据库发生变化时触发。在云功能中,我想点击我的应用引擎端点。应用引擎端点配置了“管理员”仅访问的安全约束。 (注意:端点部署在与我的firebase云功能项目不同的应用引擎项目中。两个项目都部署在同一个谷歌云帐户中)

我尝试从云函数获取应用程序默认凭据,并在对端点的 HTTP 请求中使用它,但它被重新定向到登录页面。

firebase云功能的应用默认凭证有什么作用?是否有其他方法可以实现这一目标?

Firebase 云功能:

const gal = require('google-auth-library');

exports.makeUppercase = functions.database.ref('/{deviceId}/status')
.onWrite(event => {

      const auth = new gal.GoogleAuth();

      try {         
        auth.getApplicationDefault().then(
            function(res) {
                let client = res.credential;

                if (client.createScopedRequired && client.createScopedRequired()) {         
                    const scopes = ['https://www.googleapis.com/auth/cloud-platform'];
                    client = client.createScoped(scopes);
                }
                console.log(client);

                const url = 'https://my-secure-service-dot-my-project.appspot.com/secureEndPoint';
                client.request({url}).then(
                    function(response) { 
                        console.log(response.data);
                    }
                ).catch(err => {
                    console.error(err);
                    return err; 
                  });                       
            }
        ).catch(err => {
                    console.error(err);
                    return err; 
                  });
    } catch (e) {
        console.error(e);
    } 
});

编辑:我将端点部署在与云功能项目相同的项目中。端点访问仍然失败

编辑:下面是为端点指定安全约束的 web.xml 部分:

	<security-constraint>
        <web-resource-collection>
            <web-resource-name>all</web-resource-name>
            <url-pattern>/*</url-pattern>
        </web-resource-collection>
        <auth-constraint>
            <role-name>admin</role-name>
        </auth-constraint>
        <user-data-constraint>
            <transport-guarantee>CONFIDENTIAL</transport-guarantee>
        </user-data-constraint>
    </security-constraint> 

【问题讨论】:

  • 如果云功能在项目 A 中并且端点在项目 B 中,那么您在项目 A 中用于云功能的服务帐户应该在项目 B 中具有权限。您是否尝试将其添加到 IAM项目 B 的标签?
  • @A.Queue:我尝试将端点和云功能部署在同一个项目中。结果是一样的。 (我已经用这些信息更新了我的问题)
  • 你能分享你的 app.yaml 吗?
  • 我已经用安全约束设置更新了帖子
  • 据我了解 [documentation]() login: admin 适用于连接到端点的真实用户。疯狂的猜测,但that answer 可以解决吗?

标签: firebase google-app-engine google-cloud-functions service-accounts


【解决方案1】:

Here 是使用Identity Aware Proxy(IAP) 访问受保护的 GAE 端点的两个工作示例。 注意:IAP 将限制对整个应用程序的访问,而不是像with login: admin 这样的特定处理程序。

根据app.yaml reference for standardlogin: admin 是真实用户使用浏览器连接到端点的媒介。

【讨论】:

  • 我还没有尝试过这个选项,但从文档看来它可以工作。所以,我会继续接受答案。谢谢!
猜你喜欢
  • 2016-02-15
  • 1970-01-01
  • 1970-01-01
  • 1970-01-01
  • 2013-09-10
  • 2018-06-15
  • 2015-11-05
  • 1970-01-01
  • 2021-10-03
相关资源
最近更新 更多