Skip to content

feat(auth): add service-to-service authentication sample - #1909

Merged
amcolin merged 3 commits into
GoogleCloudPlatform:mainfrom
amcolin:add-auth-service-to-service
Oct 1, 2026
Merged

amcolin merged 3 commits into
GoogleCloudPlatform:mainfrom
amcolin:add-auth-service-to-service

Conversation

@amcolin

@amcolin amcolin commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Description

Fixes Internal b/242962361

Checklist

  • Tests pass
  • Lint pass: bundle exec rubocop
  • Please merge this PR for me once it is approved.

@product-auto-label product-auto-label Bot added the samples Issues that are directly related to samples. label Sep 28, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces a Ruby sample for service-to-service authentication using Cloud Functions, adding a Gemfile, a basic HTTP application, a helper to make authenticated GET requests, and integration tests. Feedback highlights critical issues in the implementation: the relay function in app.rb is hardcoded to return success instead of calling the target function, and the deployment script in service_auth_spec.rb uses the wrong entry point for the target function and fails to pass the target URL environment variable to the relay function. Additionally, improvements are recommended in service_auth.rb to validate the presence of the ID token and to configure connection and read timeouts on HTTP requests.

Comment thread auth/service-to-service/app.rb Outdated
Comment thread auth/service-to-service/spec/service_auth_spec.rb Outdated
Comment thread auth/service-to-service/spec/service_auth_spec.rb
Comment thread auth/service-to-service/service_auth.rb Outdated
Comment thread auth/service-to-service/service_auth.rb Outdated
@amcolin
amcolin force-pushed the add-auth-service-to-service branch 2 times, most recently from e49d2ae to bf563f0 Compare September 29, 2026 00:12
@amcolin
amcolin force-pushed the add-auth-service-to-service branch from bf563f0 to a4358ba Compare September 29, 2026 00:21
@amcolin
amcolin force-pushed the add-auth-service-to-service branch 2 times, most recently from d91e7b7 to e3d725f Compare September 29, 2026 23:19
@amcolin
amcolin force-pushed the add-auth-service-to-service branch from e3d725f to 21b2c95 Compare September 29, 2026 23:31

@XrossFox XrossFox left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not versed in ruby, but LG-enough-TM

@amcolin
amcolin marked this pull request as ready for review September 30, 2026 17:33
@amcolin
amcolin requested review from a team as code owners September 30, 2026 17:33
@snippet-bot

snippet-bot Bot commented Sep 30, 2026

Copy link
Copy Markdown

Here is the summary of changes.

You are about to add 1 region tag.

This comment is generated by snippet-bot.
If you find problems with this result, please file an issue at:
https://github.com/googleapis/repo-automation-bots/issues.
To update this comment, add snippet-bot:force-run label or use the checkbox below:

  • Refresh this comment

@amcolin
amcolin merged commit 471161a into GoogleCloudPlatform:main Oct 1, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

samples Issues that are directly related to samples.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants