-
Notifications
You must be signed in to change notification settings - Fork 0
/
main.go
125 lines (89 loc) · 3.19 KB
/
main.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
package main
import "context"
import "fmt"
import "io/ioutil"
import "log"
import "cloud.google.com/go/storage"
import "google.golang.org/api/option"
import "golang.org/x/oauth2/google"
import "google.golang.org/api/iterator"
func list_bucket(client *storage.Client, bucketName string) {
// List the objects in the bucket
fmt.Println("Listing bucket ", bucketName)
fmt.Println("--------------------------------------------------")
ctx := context.Background()
it := client.Bucket(bucketName).Objects(ctx, nil)
for {
attrs, err := it.Next()
if err == iterator.Done {
break;
}
if err != nil {
fmt.Println(err)
break
}
fmt.Println(attrs.Name)
}
}
func main() {
ctx := context.Background()
first_sa := "first-service-account.json"
bucketName := "replace-with-your-bucket-name"
objectName := "second-service-account.json"
// **********************************************************************
// Phase 1
// In this phase we will use the local service account JSON file
// "first-service-account.json" to create a Cloud Storage client
// This method loads credentials from a file
// **********************************************************************
fmt.Println("Phase 1")
client, err := storage.NewClient(ctx, option.WithCredentialsFile(first_sa))
if err != nil {
log.Fatalf("Failed to create client: %v", err)
}
// **********************************************************************
// Phase 2
// Try to list the objects in the bucket.
// This should fail
// **********************************************************************
fmt.Println("Phase 2")
list_bucket(client, bucketName)
// **********************************************************************
// Phase 3
// Read the second service account stored in the bucket
// **********************************************************************
fmt.Println("Phase 3")
rc, err := client.Bucket(bucketName).Object(objectName).NewReader(ctx)
if err != nil {
log.Fatalf("Failed to read object: %v", err)
}
defer rc.Close()
data, err := ioutil.ReadAll(rc)
if err != nil {
log.Fatalf("Failed to read object: %v", err)
}
// fmt.Println("Data:", string(data))
// **********************************************************************
// Phase 4
// Create credentials from second-service-account.json (in-memory data)
// This method loads credentials from memory
// **********************************************************************
fmt.Println("Phase 4")
creds, err := google.CredentialsFromJSON(ctx, data, storage.ScopeFullControl)
// **********************************************************************
// Phase 5
// Create a new client from the second service account
// **********************************************************************
fmt.Println("Phase 5")
client2, err := storage.NewClient(ctx, option.WithCredentials(creds))
if err != nil {
log.Fatalf("Failed to create client: %v", err)
}
// **********************************************************************
// Phase 6
// Try to list the objects in the bucket.
// This should succeed
// **********************************************************************
fmt.Println("Phase 6")
list_bucket(client2, bucketName)
}