gpt4 book ai didi

java - 如何在Java客户端使用通过serviceAccounts.keys.create API生成的Google云平台服务帐户 key ?

转载 作者:行者123 更新时间:2023-11-30 07:04:09 24 4
gpt4 key购买 nike

我使用在客户端的 serviceAccounts.keys.create Google IAM API 在 GAE 中生成的服务帐户 key 将文件上传到 GCS。此 API 返回我在客户端代码中使用的 privateKeyData 字段,如下所示:

public class GCSTest {
public static final String CLOUD_STORAGE_SCOPE =
"https://www.googleapis.com/auth/cloud-platform";
private GoogleCredential credential = null;
private HttpTransport HTTP_TRANSPORT = null;
private Storage storage = null;
private final JsonFactory json_factory = JacksonFactory
.getDefaultInstance();
public String APPLICATION_NAME = "GCSTest";
private String privKeyString =
<copy the privateKeyData from response of serviceAccounts.keys.create>;

public void startTests() {
initStorageService();
writeObject();
}

private void initStorageService() {
List<String> scopeList = new ArrayList<String>();
scopeList.add(CLOUD_STORAGE_SCOPE);
HTTP_TRANSPORT = GoogleNetHttpTransport.newTrustedTransport();

byte[] privKeyBytes = Base64.decodeBase64(privKeyString.getBytes());
PKCS8EncodedKeySpec spec = new PKCS8EncodedKeySpec(privKeyBytes);
KeyFactory kf = KeyFactory.getInstance("RSA");
PrivateKey privateKey = kf.generatePrivate(spec);
credential =
new GoogleCredential.Builder()
.setTransport(HTTP_TRANSPORT)
.setJsonFactory(json_factory)
.setServiceAccountId(
"<service_account_name>@<project-id>.iam.gserviceaccount.com")
.setServiceAccountScopes(scopeList)
.setServiceAccountPrivateKey(privateKey)
.setServiceAccountPrivateKeyId(
"<key_id>")
.build();

storage =
new Storage.Builder(HTTP_TRANSPORT, json_factory,
credential).setApplicationName(APPLICATION_NAME)
.build();
}
private void writeObject() {
String fileName = "StorageSample";
Path tempPath = Files.createTempFile(fileName, ".txt");;
Files.write(tempPath, "Sample file".getBytes());
File tempFile = tempPath.toFile();
tempFile.deleteOnExit();

InputStreamContent contentStream =
new InputStreamContent("text/plain", new FileInputStream(
tempFile));
contentStream.setLength(tempFile.length());
StorageObject objectMetadata = new StorageObject().setName(fileName);
Storage.Objects.Insert insert =
storage.objects().insert(<bucket_name>,
objectMetadata, contentStream);;
insert.setName(fileName);
insert.execute();
}
}

但是,当调用 storage.objects().insert 时,我收到 java.security.InvalidKeyException: invalid key format exception 。这是使用服务帐户 key 生成 GoogleCredential 的正确方法吗?P.S:我知道 JSON 或 P12 key 文件。我不想使用它,因为它不适合我的用例。

最佳答案

默认情况下,serviceAccounts.keys.create 生成一个 GOOGLE_CREDENTIALS_FILE,它是一个描述 key 和其他一些内容的 JSON 文档。客户喜欢 gcloud-java可以读取这些文件,如下所示:

StorageOptions options = StorageOptions.builder().projectId(PROJECT_ID)
.authCredentials(AuthCredentials.createForJson(
new FileInputStream(PATH_TO_JSON_KEY))).build();
Storage service = options.service();

不过,您的代码需要 p12 key 文件。您可以将 JSON 文件中的 key 提取为这样的格式,但更简单的方法可能是调用 serviceAccounts.keys.create 并将 serviceAccountPrivateKey 参数设置为 TYPE_PKCS12_FILE

关于java - 如何在Java客户端使用通过serviceAccounts.keys.create API生成的Google云平台服务帐户 key ?,我们在Stack Overflow上找到一个类似的问题: https://stackoverflow.com/questions/40418859/

24 4 0
Copyright 2021 - 2024 cfsdn All Rights Reserved 蜀ICP备2022000587号
广告合作:1813099741@qq.com 6ren.com