Browse Source

Renaming to endpointUrl for OauthBearerProviderOptions

pull/15670/head
Andrii Landiak 4 months ago
parent
commit
a519e720f8
  1. 2
      msa/js-executor/queue/kafkaTemplate.ts
  2. 12
      msa/js-executor/queue/oAuthBearerProvider.ts

2
msa/js-executor/queue/kafkaTemplate.ts

@ -134,7 +134,7 @@ export class KafkaTemplate implements IQueue {
oauthBearerProvider: oauthBearerProvider({ oauthBearerProvider: oauthBearerProvider({
clientId: optionalOauthStr('kafka.confluent.oauth.client_id'), clientId: optionalOauthStr('kafka.confluent.oauth.client_id'),
clientSecret: optionalOauthStr('kafka.confluent.oauth.client_secret'), clientSecret: optionalOauthStr('kafka.confluent.oauth.client_secret'),
host: optionalOauthStr('kafka.confluent.oauth.endpoint_url'), endpointUrl: optionalOauthStr('kafka.confluent.oauth.endpoint_url'),
refreshThresholdMs, refreshThresholdMs,
scope, scope,
}) })

12
msa/js-executor/queue/oAuthBearerProvider.ts

@ -20,7 +20,7 @@ import { _logger } from '../config/logger';
interface OauthBearerProviderOptions { interface OauthBearerProviderOptions {
clientId: string; clientId: string;
clientSecret: string; clientSecret: string;
host: string; endpointUrl: string;
refreshThresholdMs: number; refreshThresholdMs: number;
// Optional OAuth2 scope. Required by some IdPs for client-credentials (e.g. Azure AD's "api://<id>/.default"). // Optional OAuth2 scope. Required by some IdPs for client-credentials (e.g. Azure AD's "api://<id>/.default").
scope?: string; scope?: string;
@ -35,11 +35,11 @@ const EXPIRY_SAFETY_MS = 5000;
export const oauthBearerProvider = (options: OauthBearerProviderOptions) => { export const oauthBearerProvider = (options: OauthBearerProviderOptions) => {
const logger = _logger('oauthBearerProvider'); const logger = _logger('oauthBearerProvider');
if (!options.clientId || !options.clientSecret || !options.host) { if (!options.clientId || !options.clientSecret || !options.endpointUrl) {
throw new Error('Kafka OAUTHBEARER requires kafka.confluent.oauth.client_id, client_secret and endpoint_url to be set'); throw new Error('Kafka OAUTHBEARER requires kafka.confluent.oauth.client_id, client_secret and endpoint_url to be set');
} }
if (!/^https:\/\//i.test(options.host)) { if (!/^https:\/\//i.test(options.endpointUrl)) {
logger.warn('Kafka OAuth token endpoint URL is not HTTPS (%s); client credentials will be sent unencrypted', options.host); logger.warn('Kafka OAuth token endpoint URL is not HTTPS (%s); client credentials will be sent unencrypted', options.endpointUrl);
} }
const refreshThresholdMs = Number(options.refreshThresholdMs); const refreshThresholdMs = Number(options.refreshThresholdMs);
if (!Number.isFinite(refreshThresholdMs) || refreshThresholdMs < 0) { if (!Number.isFinite(refreshThresholdMs) || refreshThresholdMs < 0) {
@ -48,9 +48,9 @@ export const oauthBearerProvider = (options: OauthBearerProviderOptions) => {
const scope = options.scope && options.scope.trim().length > 0 ? options.scope.trim() : undefined; const scope = options.scope && options.scope.trim().length > 0 ? options.scope.trim() : undefined;
let tokenUrl: URL; let tokenUrl: URL;
try { try {
tokenUrl = new URL(options.host); tokenUrl = new URL(options.endpointUrl);
} catch { } catch {
throw new Error(`Kafka OAuth endpoint_url is not a valid URL: ${options.host}`); throw new Error(`Kafka OAuth endpoint_url is not a valid URL: ${options.endpointUrl}`);
} }
const client = new ClientCredentials({ const client = new ClientCredentials({
client: { client: {

Loading…
Cancel
Save