WIF + Workplace Marketplace service account

Viewed 25

We are trying to build an app which can be installed by a Workspace admin domain-wide. This is possible via the Workspace Marketplace, which allows a single service account, controlled by us, to be given the ability to authenticate as any user in a Workspace org once its admin has installed that Marketplace app. Our app would use this to call the Google Drive APIs.

The 'normal' way of using this service account is via its static private key, but we're not comfortable with this security wise, and would like to authenticate via Workload Identify Federation.

We're using Hacklang, and are strict about not linking in php dependencies. There isn't a Google provided client library for Hacklang, so we're crafting the requests manually.

We've successfully:

  • Set up WIF as described here
  • Set up the Marketplace app and corresponding service account
  • Used WIF to sign into the service account

What we can't figure out is how to take the final step of using the service account to impersonate / act as an individual end user when calling the Google Drive APIs.

First we call the Google STS server, passing it:

{
'audience': //iam.googleapis.com/projects/<project number'>/locations/global/workloadIdentityPools/<wif pool id>/providers/<provider id>,
'grantType': 'urn:ietf:params:oauth:grant-type:token-exchange',
'requestedTokenType': 'urn:ietf:params:oauth:token-type:access_token',
'scope': 'https://www.googleapis.com/auth/cloud-platform',
'subjectToken': <json formatted and url encoded token from AWS>,
'subjectTokenType': 'urn:ietf:params:aws:token-type:aws4_request',
}

This succeeds, and we receive a token.

Now, we believe we need a JWT to allow us to 'act as' an individual member of the Workspace org. We're trying to use the signJWT API for this:

URL: https://iamcredentials.googleapis.com/v1/projects/-/serviceAccounts/<service-account-email-address>:signJwt
Headers: ‘Authorization’: ‘Bearer <token from above request>’
Body:
{
    'delegates':[],
    'payload': {
        'iss': "<service account email address>",
        'sub': "<Workspace user email address>",
        'aud': "https://drive.googleapis.com/",
        'scope': "https://www.googleapis.com/auth/drive",
        'iat': <current time>,
        'exp': <current time + 60 minutes>,
    }
}

This is giving us a 403. Does what we're trying to do here make sense, are we even trying to call the right APIs? And if so, any idea what might be going wrong? Thanks!

0 Answers
Related