From e40af7d47727bad7b2d3d13e5deadf0b55a49e51 Mon Sep 17 00:00:00 2001 From: Sijun Liu Date: Mon, 10 Apr 2023 12:38:51 -0700 Subject: [PATCH] fix: add useEmailAzp claim for id token iam flow --- google/oauth2/_client.py | 2 +- google/oauth2/service_account.py | 5 ++--- system_tests/secrets.tar.enc | Bin 10324 -> 10323 bytes tests/oauth2/test__client.py | 1 + 4 files changed, 4 insertions(+), 4 deletions(-) diff --git a/google/oauth2/_client.py b/google/oauth2/_client.py index 74e769fa1..03f6e8f03 100644 --- a/google/oauth2/_client.py +++ b/google/oauth2/_client.py @@ -331,7 +331,7 @@ def call_iam_generate_id_token_endpoint(request, signer_email, audience, access_ Returns: Tuple[str, datetime]: The ID token and expiration. """ - body = {"audience": audience, "includeEmail": "true"} + body = {"audience": audience, "includeEmail": "true", "useEmailAzp": "true"} response_data = _token_endpoint_request( request, diff --git a/google/oauth2/service_account.py b/google/oauth2/service_account.py index 152e05814..37e1e568a 100644 --- a/google/oauth2/service_account.py +++ b/google/oauth2/service_account.py @@ -743,10 +743,9 @@ def _refresh_with_iam_endpoint(self, request): request to IAM generateIdToken endpoint. The request body is: { "audience": self._target_audience, - "includeEmail": "true" + "includeEmail": "true", + "useEmailAzp": "true", } - TODO: add "set_azp_to_email": "true" once it's ready from server side. - https://github.com/googleapis/google-auth-library-python/issues/1263 If the request is succesfully, it will return {"token":"the ID token"}, and we can extract the ID token and compute its expiry. diff --git a/system_tests/secrets.tar.enc b/system_tests/secrets.tar.enc index bdea3fdb79c69af52c062bb9b0eb378fc1da793b..ba6703d1de2b9978a91017a79244a4106cbf5064 100644 GIT binary patch literal 10323 zcmV-ZD6H2CB>?tKRTIudLN2=K+UV3r&s{HAIxWU$w3sEnyl^2&BB6`(1DF!2PypAf zZW9;WnMC#UJ-AvPpE4r{ZaONup8UbVRF;~2B)D^{JbHFXm3Qx9sN1SzeH7?l)L%Co%kGcYBwdfM=hStcz?iU>ITV%46{54|M( zBXUAOrJFR!Tvh;E3~>?T$OlT!hmp>+vdE4E0W&dbLWN z1zFcA0Gych&Uq-X*`h9Ktks7UGNhBz2YMB8FC~`cf^rkeW%_&*0_*W2v&TN3jo3Q` zwgj_cP#I!;`8ogeaW%Xr#H!Djpi)#ia3g*Ll? zRW%#|I!uJZ!9%l$6ar^M-m}-)Z$K|59@IV&1Bsv;;7~zCvX3pm7gp+9Iga$Fwa5#= zL}EDbjMIqK71I*fW*?wsx&UA=)IWSm6m3UH*2q zleVBv%W%L^cL(WzPQt^+5!gc)30*0sl&9R~hD86}qKfQLyc1m+Q1QQ^3#!hDg(=`3 z(!ji&UAZBZ6i&e68Z7Hiy{1JNr)!?Mo%p!VXk+QGP+B8yE1E@OyRlO4$JLCwTw zhTi-C`_lA&#nO3%typzMlGIWw4(4IjhkvLWI8S30a~_rx`?4cXVz!zFuOj=WEB!|J zHrn&8SQo-rV;Bc9BrW%&pVdA{mB&}aH7N@Paa1_qRxTNHv~Uv{IPwu=Coj_8J#+v1 z4(7*Sx0Y}kC67^6x4sn_Wb=rqaFpzIVngI`O|m(`Xiy5!*S}N{T33l(u3UIr#94Y4 z@z!3%L&juqLuE$?XBujoQm`h^AtHJx_dzW&W%y~S3&8`MTHV8A+{voqD^KfUrGI6y z%!G~FM4*{clw;!W$Y>~jBO}vYq;(2p5i%WYD(<=qby%r3^>T-N>a47}Goclmm`rxz z0@w%DMD^y5W}X%KBfI#+Zl--7_nuU-1d4^=e^ZKSWozoY@fCgu`K`!pOv_QxT$gw~ zLGrg*HKLA{EZ99$HR6tnB44l!WXeR$zVegXq)j! z7>s*s{5{oVgOWM#D@E+A!j)<}ntyDRf?HN>_1IYgZMf5Rtz!>1Nf6eD9pus%w>0Mt zBMEvPjdy%}69EQZV-MI)PqX3-4L2NUl9eP^WaOBPSNpngzq zg%lsfvlU*-mc~BT!?9p=uyOEBc+9e6Mi=S=S7$;*d-c=QH5MiF={j6NPsvbqrnSkF z`bqwRV1(t0aXX&h<4vTN2AltxwV$zPg!-j*WtH<_WT72!R`*qZiZqq*`QRze>W}rQ zi>vC}{^gR9PLl^gILJyX;7aP)64)mw8G#6IWBLFBln_^-#E0<_XG|i799^X#3-_`q zi%3k4Yw$J{PY#dBoW}(U87*iLy<#p7A_m!=wKhGYb8Kp4{^OB?NPFi; z&OnE1R@^!Ylji%}hL}gT(<94N>NhHYVkEO*?NNwT{XAQqvLmqm@5*d!%C-OgQmkr| zV({tzs0z){Br(QmE`6{)B<97AB5o-glPof6`$C?4=-o-VV1I*Xq&C{aM%i1YJ>nfL zRPOo5=EB*lav{%wkQ?HCEEk{iUI+N1ULB}em?!+KwArFDu5t{~q@k});P;*_iWlP> z;?Ea&O?_L6gnEau>KgWSD2)*c+gE z_)nHSN>-ior%}U;&V;(se`m$LPa6k0t;m$);TK-c3(7=-+1~n<(xcm+TFT@ryVu47 z7*)T#ZFsrUQ0?mAoik?}E7lu}~vtW!ROzSAgVm1WeH1xO7?hHa~H= zP97E4yV;6)m-zsW_n{bHxYI$cw;Xvhb(7&;V0wzt7cC|kV(`HtLDUu-o{ET(7DjN zJ2~DsF6mZ(?2ypp0`#Hzj^89te&*rj4N<>hD1-nJU=I%Ns2-C+If^p1wD9xZsHY~6 z6RRHlW5`vA#!BSiXCd7k4&r1dch0ud7iE|-940y&thIoxs^uk&2%ZDO0yb`S4 zIa91equuxy4IN7ZSZ{7;Cvfpe`C(K4M6JBZ+|Pc*Ssd5b40+-7kSxKn4&{ioJ&u0` zA{ui7$OYIA9ez0DRVQ$4fN$Cn&-hxJi)8}A>< znS8szrtAB3MGM5d^I6}uElEMRddWz8@ZpdF{C7a3_{~lkuj{@6Y5i`zp`_HR^d5M& z_(P0cW1d>{MPd;cD>cxgkdM}WYaT>fN{`z&Zeto`&Y`#iAGsF;>vw1dSOljkYglfl z);(x~AKL}1HU=AK@FtFiL3Y2w{1QxTDs=~$@3CeiH<;VV?vJ#7{Dkb9KK*@xb}kE- zK(sbAN5a#WT`C1{F*dlT9bf$qnNG3+ z*qn`zL{~~yd zhYR`DJ67>u`NKU? z(c$lz2b_42n;|OAbczy<+GDR98fyPMyr3YEn+q|w9GDQq#T37E^6Je?RM4|-ja|D^ zaPr-X#-P4#&uu;+9Maujv<@3T$tciSjoEgu=7_9mcib^tvpcd00V1Aa{1MU~H)zY< zI$LM)nQo4ylSytN4RXRQm}^_wLxd!l;_DMGf&ueOdcRT#mB^ivAP}veVmrAJQ@R(p z#K$6oNKs}q0^$%hk__dZ%7wcV|~jc7_bi1`dowNd(|Z1B(#Ry5Kh# zHD8cu)Q!SZ^;p!r3LDA{wmG$OS(XXFY*q42z3g*UBXU$$pIX|;k~nnD+7|qK*%~}o z!#tpF=}>+ttohuX>&|>vnP%kZXdyr{C23`=oO1!|wSE~Nq|#D4lmP;n>4l7O@y1Utv z$GUTo0XVg`d=i7W?$BQ#P;*)uHaW9`%cHI)?_(_$B?p+_#r-)hL`^4`;0-_)%gU8w zbvS!6dQr)EAde?f{;--XcW9u+x&UQ3*cynt78%a{>)M_f-Cbq}*{avsp=v{AT5buz zfc@=r5JKOKWX1W{vCr>?`gJ13(36LMBPS!M0n(2HJWq}|Z)%@6IUD7X*EopW{HW{s z7jO%ArqBW`^(zm7`i*M!=~-HJJMS>wk#EHF*Hfn3mVz1ofoIY0f;d)Tj9Rw?L<%9g z@R+~}@N~PVnKTr9Dt!_|jNsj)^FAoGjoQD{Zs2}ppxF+?B}22^Y-;#+yb%W9gcrPo zk;{I8eU=*V#=7cSkGshmSED&>PaGUFN%G}%)tHIdSt0G z@bYT=w(2oZ^sHF|YEdgekQ*Vo^OW5Jv^W$VF@C5He?|u1&Tc#qx#AQ=Sz9`Dy@I$6 zA_^;s6UieyLh1>~ETqUFAi+kXT#dmvAj3NVe8&m*9GJvqIT$9_ClC11}R51&M5ZM8jTD3h#w`^>WTUBP*47_BYBx%VU2 z!8GV9VdLUEN$wbQwOFyoYWn!LzJ`P}AWE;v*SjZYd}Q?i&&lck-+Ihw~FaP+R4q;XHy5 z#D_nbxg}oNeVt@t@rFK{mVOdn$|~z~<1+JsjB>LCbVbLvZL;T@-vB$TgS)VxOhGo+ zYelPH&`)}V65@2Ki@QKG1evbCAYb%M2Cc$bl#BzS>|HL{V=bmr^5#D`&Grt{_q`i% z(M@2hrI^6F82}Uzb`AlPg*)Tj4>z#T2@&Edrin35$rLv(#d<$tnPyg4Pq6{^8k4u= zT1=g7pLD|S|FBdBsyRz+(Z%Y@?CKO_AQdYL9T!`f9M^&@i+YZb z{wjvDn^CtjO~v7`1Vun9KN~~JY;o~wK8*~sw|wxgKL7AE(0Q7aFI`we$HX@Qcb&gp z^anX=VV<8KEH_?K_*6AwyyK*&0PYT`vgR6V56&1#f9F)V>JI}3O?Gwrr7f!0X6S*l zIUKIt5A;oXw>2h(7GF%a2ZY0%P^9T5#G;g0!1)mlSQeXl?I5?K>$4yBeC0sv2-Beu zdmRHJA4g5$3IzZWm}>Kd@2bqew5XD8(mj^cm87mEp!apOL8Izy)-Jem@ty*&MU&G^ zOnBn;%7x4r{)>rVH2`|-@>A!LQv7;O?G>RVtayhO>iZrwD+stTl!@r<_WUk?Ip`xN zSH4nvNG@-`w(1)=8GCXmKMg-&;h!id=l`<^Dg&J=Xxw;qgG2a3@@=@rdxPGx!XGWu zs$_V-{}3 z$z{T;#_?CGw`S6xq3p1PZAZtoFaa}X9a=s?e{Nr~nw$3(9SCQzg({u;$|0im)cw44 zn+~j81v@MWL)~C-`w7Pprkt6mIT+(Tu0tXtBym34_Xgul^tZp$gA&0PV0Mr=db>&P z#ao1x8Kx4;f5}p{FHP$ zIZ)N(RF2@XxcPV+Dvtg+qpDvNeJV;lLeo$s$Y5iQpvhY!p|HXG*Yft~5#jLDk0>mN z9Yf@Ff6cqoYiEC$*k~`KMSUqEzx#d~k{9C{J(vE8gj3QfAmQ*#A$oz;b@oG8M+gPN zp;~(ZzP&s^u`I5~XZ}wV@W|I@A^dD9s-2`3QJ8Td;PK8U^tt*~f0@}>rVhBE_1o;LvpoEl0b|{0c-rctG6)PmVO|R&vd2GGA&?CrcfiS&*7&mxEFTeT5n` ze2=CPPXpEPRe1SM>r<-)GtzgvsM2+mB_hKe^ovyWjH2cu6E%jP?(XxT#gAGkVbHW8 zy){5VcHi?UlXzoQ>JBq8Iu9!d;k}2-xqa0{P)V`RJ9((@svOH}ahDInHfS?&W)m3{CVL zC)S4QBGyI?R6mA~lRJ*fJq5+U*GU;SV#hascg87N{*+>AvQN(lqEfQ$J_Ln6h@A`L zElV`f%e@ZQy>qy>UQVA14I>n@PJ|pNvH3{LeH|#%fTkK0>K>31)iH%Z@C>vBq=%k< zF1_1CPZgMZkpcjg=x`zfmP4i5!~xxWY33i*hrX{S|IWvuK4e)B_R@bzXaiumN>tz( z4By-+&U}0qH1b}capB2s9e2L(hLh5QzSd267*zD_u6Pt**)20G$V3)J@#as<^T^;^ z-q$`pKo|(MCZyPl+*b*kj>JF_e~DBt5~mahk~b3&yAU3)BYOwQSgV)a zb}4}o_?b$H){f!xdC_W9XO?samWIX^6I}Qs2NtXRCuQo88p+*qa}9aSh{l0~8cg`% z|ME1TvW)ano@8#tR!7W{q`d8CYibnq!}%zwWQv==^TE7Y&WM!PZ!YSIT8R3lzUS;V z2M@=HMrWg}1rj~vblb}7`~Q|!Se+oPCtZzSO9paN0noAi0{mB(%x$zs)eWfqHOr+B z7;${q4ymY$%ltA;V;(9c56s@H9UGKfopqy8nU6F!qYz_ed*wZXgl3wim*O0x3u-cz z7I|18BmpkQ48zsp46S{T{-^su(<)ZoyPSGW1egS4XZaBsET70XkdQ90?rK(zlY5n) zWhU{0O@^P&S~W&8ru;_QV5LEol3jp2(+ z(KxvgZ&A^~c;y#ij}KximfK(K<4D&;fHNbKO!-6jaMXG>4=gBK_s6UJ>xSY!T;Bdb zL8_1Xom`uH)0}7I5QdnM0fB=_3|Cqj@8y9s%=8of0*=Tu+DQt;0lwQC#y%PAbVbcU zAQ_4!6C=Xs8O3Wa6}Rf=qd&wVKfSXJ6TcEcoB zM)B-K3@-efbI!tc10^SbMFN<5t%eJN-L=h`9xJcBDyo1Y=JNUHP0ybbfG7t(2*7=Z zwFQ}_FVcK6@-0eaLpW~% zWS1i9k&sevEkC_#*nsE#nDCF6{&+g|gaCKh!RL^Hmolz@>~GRaz+=1S8ae{GWV`-F zG1+IzMUI-Q0a}0XF`fBo!wz%`Q(%$|0asuaT`!Ri0Ut>( z2B))J>9TTp{{=1eP{a797ZCcCoApHs5rdh2kV<2!1sor18Fg<9C8yvuv!Geuiv$Iy{T zOkn|0VKCBQtn%uBQO5!${i*(cus>aAwNeBsf(#KEkft-v4=1dAYqki~bACt(Gu&+?+q%@OSY>^AUA>Mw`Yc^nZ| zcFn*e`ujMIeNfJQedOnx$Ly@f343J|g(#9HD0pgM2|7IumPV#3eTjMQbuXQ~r-a`{ z9HU4~4?G-8+SG1L67pum;AvT@Un;k$MCQ2~A(`?7z1*uhUs47r*qRb$mPQtW{S*ZX z{h9k^M`m1uj9kFcnSRdj{oj=ZIlT$H zhYmXrNsq_#Z6t$!q`}wd7n*y=Rn@O9V9|&|`P4vwh8(nPYP3{~2Hxiu?)pVCXf~UP z%TUb7%-#=p2+fR}x@q^kihZa|T%FD{W~?3Ew91ll-V2C_k**e$MZnbR5HC<4fCLtF zf%dxbhlnb5G}G51noudi6Se!FR#-<2A0cFg6uHxsqo4WZpZpXsAAylsR z@!~?#C8jL!SpeHQ74zz2yPKkt@)bR^QAiPFHIh{ z3WGOia~kNKH@zXoe#5fcdBMiZE^o(wln(7cwxH#Q+W3DJGy2ZuV5RYvWm(~$Uv=Zp zGC4?!z_l6w@*1J66sNkD;P9gDwr5+}U&brz$;xTup~~`XJ?U=k3h2|!fT*gU$r@l% zi|DEJVeB$|-3zn8QIjdTxGnf!W4VNv7lOK992QEdYi(Iuw3jJ+`C8Ua2WtM$!X4ac zCR<>MgnYCRVWk3p>pQG-$APVvYC94)AEC&9^3Hyw&MpVP6^*qi4QD>B-*Ku1KFpa< zoVJV*Waj}sEURxpPafY@)&VXcW@FkoUTm^lDBgMEzk7xhd+q5`Im0trIy&g421eft z-8~JB3bT)Wr`EATp&j#yln1#?M@NgXf`EG$n}R-)hA6Wu3H2;(*|qPs7-TGLb9#8P zCr(1EH?!|FAv4A-7@;z}7qxDjaYqP8?xk|}_`RK6(M|YQ$q5Di$xmMxo|Gf{BH-^p zy2E(Y?dpO7r>$mwBes3y=3wF?Kg`bkO(jAqP zwOU^}*AWGnBh|+I#(*lu;4AZVZiZc}>UcGzYehEVpKc&(BsNT=nLh|nR({qADk4b{ z$t9@^%9BXB5(EFQvE1jOnUh2}Z`TN=r5O6^m(1Z06$*eynQKW;yU4j@LzQ=ciDY(j zyH9mA+UYG=(U%q#(Ou&PQZI$hCUp-_^th# z$36=#93FjsC^J7h6imw=pLvD}slTK6m}5%nt*=oq`fqzF=!xdK`O;}&2bS3C&knz%cPR$NmWOL6&cq@nG!OTSqyKf zZHIvsWm>I*6ZVlq703IMd>^eoJ^Pq>=!D4VqB}H(rT~f*EBKwsW=Y? zNG%%vlLM>HF>Cw7lPbfn7x*EPN*JuvOI(d@STqmGRUufJmkFWBcFRJ4Bh#hmj$fut zd?LG6*x1fPK@TTP2t;rYFpx7`m@|XGfaQp1DbCytx4Uv7tk?-5Yi{BErtpyWb*dr( zKz3B4Ar}9+&=X}tJNpit2~u3sKPpH*qUZxf$y~Rb0Pua+29|Ry!M`B)`{probTRtT zU*Wj_^JY?E<7jUL$zhBN6Hr(?giDjtl<=7?cf9B_qMnR$m~HOIGf{9PIDKE8w1*6Q%r?Y&i> z061~=3Js~5106mm#%b@IDDc)0`_6Z8Vw52I5auh_?Cc=xj9pm9($ULod%8&5V{Lo8 z!&P@cGFfY3dd-O|3)1{~z|st<9-UDnj}+-2KLK9Uvld40yj?FvM%Pmzg@{Ab#A)&q zS$DX}q%qq;UnnVV*Y2H@jrq}LQn>+K#9YaQC7B75aqPK+^J4Xs>6bBtY zpm~qY^`u~LiZAx4b(Xl=l_g9_1VmhVdpwSVYf`?OpHFI_a~gDMbyTf8 zDePTImadDX7PnEf=$vO)4%}CX7NwB^y@m zREUW9KvtGFVWkmrrehxQ#F00Mb%w7R5_EBDdU?~d>NZQ4j{`#owdn|*i|AQup8zta ze)vROwo^p=`>eQZ1Cva>o|z&hBvdXn`mo`t(#pdp$HCfJ?`Hjkfac;CNR1tD$7` z?KB-)07I~Bd=lc^_h5MDkhG3#CL-SC>e!JOKN&j{XK3}oB%S#Bu*@6+lc~xs379;s zXABG*KOVO5GpZ#Fx#ZMYg+Bmq5m7hHKbFkwvkwnxD&{q`PSYb~#cw~ii1;_G2@@swSF@a6R-d&itW^>=xp-qr8<&N?hA@Mb&&rS@+ zk3+eszyfa9D{F*w2sv7pd+Lqz25y_~xBIp%340CjjdJoH69g8|iUypc%YtXC>%aQe zg%~dk>0HE4uGmNeYj{x<`1N)L40|Bat+=!l1Az`FtR7-db3JX_pJ~A0n1Y!c(n2w$ z*`X2xQ literal 10324 zcmV-aD67{BB>?tKRTEupW4gXU4CAfnu5=1LZa1-vy!xdxIDwU5$$q|Tza|o@PypAf zZWHt8Nqzgi%oPLgg!{OaqSxOt?dtP9fI=H#Y1e9;h){*Nm_bG2%n6XQCsVll#g06f zYhZ9v+IT8m;Wj7ga6&q*G?98vc|XS+#*t95^WoW zn_ZI^me`~|xb8!53`KD0DtjViF5F4k9~U7=#l zrX^Gp#f}f640-nFg$U~6p|>X#-fnwRsyaoGnT2*NV2|x2do&Whgi5UV!jocdG-ZKZ zX!^3^wz4t}yZFqZbZ%Bn6}QtsKHqX<6`Axm@8Z#6yy!Ip-xoF~i4b`XJg3P?5fO^! zAGK7r;r<3`5hC~;G^SG>wUZV?h{XI?Jgl{H3|Hif#24r?9P|ISMaG8iZ;XJ3>MhVB z@}K>)Is&15oos`?`r&JU7Nn>FUvL)*jfkqI#wG^GOONQ_01`}naQv%1gQK#noR1fc zs8Cr+=c zmuEU6UQ3}K^KyTx8JR!t^gM~}^no-8$|SAvp;w*SQzjuhA{(_tO8Pm`H z2k*6Y86M2A8J(|xOQa`4lnOz>vT$Q9(HIhh`ee`N7-Wab!1Q9p7Ve#+`lYnl>hGkT zR7ZA0y8(8drbCfC7kI9ZD%aA_$s1du?EftWC(YGLNQzaXz2>kU+`IR~i$Fa8UexKv zxOHmWvolv+QX@z`2c=)#sw1O|S6reLrk>s1DRL5flv3yYqMUy*@0h|=Ji7Ae! zsR@!4(-=JD17z6DPmH>{L+oOmJ>vY^JugMhQydWV+Pt?h=xD~Bfg-K~ae&6DqVRW3 zG^R+Q{#*p&SZL` zf6}A}3e{C*FvJ(b1L8Ff-(_+qn5tf07*!5%H1%_1+^da{)(~pAHBHPczvFnm*822+ z10mWkSd!v2-xzVxw{bAd(fTf6+2M?X)?@=A49pV@y(6))_CU-kY7>uyCfD+`9c4*r z7~yKxEqEDirlRhx3U)pZ*23VGdnsFCf4>-(n{+Ca3k~HHCB!%SS!09IyErCB;mA@M ze2c&!x7dMb}vX8k&Sjdqla<$f9 zrdyS3)b3zM1=NlBPqy7>fSa%nI5n+}!dm|3Cv#(zLlr3DzIwwo{Z6POB4^-)gH~v% zHt!`@KxE{lg%~{Q^?XNVC^Htu1Z1+yWPT4S>mW0-rv~j=vH+^+H%!$ZcKGsUh$M9z zC5r<4=tF%06qO-+9+fb^5Jbl}A3kehtR@iTh(Sn>>zmolFUR`PhH%RHlEt?^7nb%6Qb@2 zn~+@H*&})lu$JWlm9f0L@}4teXR)N%je1FX;GIgp2l3K>k>Y&<<1SY68HG_Q0QBOj zwUe}e(3OLb2Psn$M`-|UNMnU_(R1)%c^g8$))Qy1^km0oTrV%|f5UbEN{H05&3m)v zx|m0hoFJ=@%l6}@pK4#PHh1;4?x_@j;8aCZ)wuxcX+yYM9;w>~Bti?7xl~={={`OA zvf_kL25FeBHoyk^xU(`!u^{yg9@#M$FB6Ts<;$89Q4|}bhDRjP?{a!v^hijCdbl=1 zRK3CNG>2Whk~GAs+}9hz8Z`pM8=mG_C0vMU)6nv!d*@!8ftp5b+p_P!KaU~)<`@yK zhU_qwW&o%~GHiA2%DXSSii7H@DIFcx9cZ~kojFWkj)j-A&^P|U3#g)Y?~|L_=x4h} z2=B^!{{NwxsZfA4yKLKDuo=oUZ>J)uq_YvpRB|uiNN8iXf5;zfn`|$h*4~Kdn3lbu zGJE^@i!Ds2SoxW{_{m2xiBgY}B+8$XggqMuFooTH68}f12YqK`D=9A6gX6u7~PJ60LAb|e>k4z@SJI?`VYQ%OFZ%7lee%We_U#C;WG#l9Twtd%m!s1Y) z*1N!Qpc3~)EoVxo&CW3Ntj#%Nb#X}$LeUzfK#)Xm2;3~h0xCA%8=d)Gt32gY7Z2;) z8%2Q;0#5GYk5<|rV)OP83_^*dy=MgjWi-0JJ-r#sqAGnX=VaMKYKk2?1My^%21&rq zzPKj9V;Eeapj9Qext{xFu=Mh8=nbXw85{PGF-ol17@1nv3^6NV4@udZf;z|+GIJdI ztgS79;K?5^s&CM7p_LOty!*O(p>JH}^YnJyx_@W~+`L!;+l?BkNG$Pl&Y+4MV-l#! zk;a1}h9AeL2g?6*g-BW1V~OH|cT6@wt3dUdcj_1dw)PbWY z=SxRy`-jge@Vd0Vwp-+I>9vuOogcPXU=otklYsRvp-cahAnF_%G2jR6ybTL{L2l=H z7Po;~RCKG{P%IzLKUEo2(tw87M=DbTy(s(|Z&jGAbbnA;prkt_MuWxigir>pG~GSI z#hGzllsP7i4)!&;?k^BKwj13-KHjUms7@qjG#ZyIHtNCWX~y)d7BdR=!h>Vc+q*xj zL;)`#u(@F4AYevCLoAffxBGCv3f~WoRkWASYgtffWsd#bjI3E>gx=gHqu6bfvG1Q+ z$!RW|GXC?!0+4|FV);MT_<^eF#iIsO0Z@5H3`PxLV;QL&aLRzi#oTx$YIcJwbMzd*X}F1_8EvpzshnTOkJF3R zc`UG)zo!&nrcVcV$BM;TyTn=^Y2Uc09hNMRFv8$Z`iW^ejHv8H*6q;k2ey&}3_>n7 zmAiNHO8VgoWn?w$ahAz>m$2eS0lFyAm?aevW60(U#;OuWgg2KL6SFw`2!Kt!5Q?Z{ zcNX&+tcWyDScF}zeaA-lwACE$^*fLT$IB|hGLV$zQiJ$xubKZ>33P$CimnA3DRcS_ zKiiOe>xoSe@vz!_&l24(4eVu@?bRl1cI;p)lwiO=Lmq!eFtDZwzH%l}5SctNy5FAs*rRQ!_w zAN8F9-)%n+Lhaun%@sayOW-?!iyp`kA)?D+{3rru77u|?71io+I7)sdbSFD0n7o88 zc@t|C3y`j`0D`EK{%%J)e^Q7w0Y;BvglIhIU!IurX6$&m596|Je3TgsFeip)8L`O3 z`EEkSTE5$VZ7M;Q1^}MPr_;e-Nt>4pisd)MlasbohSlF=^hi@32cGDFVWf&<2s(?en!AfYyy`AOVxEB$t#N)`Kr93g_(Hs^P3BF$ zjF(VB*m{X4YOp3-6@Sb&M*|GG=eRA5au8-aWG<$e4OUO!8QptWC^J>-o4SHmj&v#G zq(|`aPNTBd^Hz95iYNRdL%yS()yv5`C_WZZzr89~xG*Xp1!Ga8R1AUCsHYSSQkm4sg zy7T(aV^>PVBwtU-`)dEFl>3lVNjV_{5tB*6K8rO1D2il744P}sE{OU?$eT$nGhHFc z`xrS7hD0SX;BG&^OeqdCCYgimU@^3-vwlQwdRAODl|G6dMI$XQz-dFHA_wosS^ymC zxDP9wZIrzW@DE~Fyt#praAg^qwbx14?BnCZU{zAF7lCH60(IQ0zqA}#mKk!Bx#+mRTpH+eaMBjg=(78`Y+^QW!)+%VW5nD+oOp|a9J25h` zBU8Ad27HxeB(@nP{e!puw0x~6&XZkpl+@&l;<2FiwPSU8O@g}44yVgFdo z!0oLi;coO-3P1*R%ipHA=Q~)vS#MG|QSQaI{{a}cSa z$0R<^>N<}vn3^8rv*O3zq0dBI!h)^PpVpDew23Fl#dD+wqiI#gw6^8l+@iss)dKw} z9%EKoGec8|z4T2bpgK*zg8WEIlTr9mMks&fWWlLV`In{*R>9O`qe!3fT0l3P`hq1{ znBIcu?N<1&caN5dhT#(OT%Ez~Malp%*f8^_F!1lbuHb~uZ0ourNEpU3u*Oa@a{Ygz z0Z9k2SIR3C1v)b|^k328CG@zDoKB;Dn5hbflIQxT05&IuDccPq`~L(QAhBTaV)k^5 z@TDPTa2MkVb631B{rrQkT}rw0&T|TW&F~WZmq>bua0~)cFq-2pTm21;5Q3p9QfEQl z3a%dO6&mG14tm~c3GbtYB5@cyca9Wr<@8I5m+9fgMbRe?h_j{^-l!G6hqWSsN798q ze*B%x-0!)gqupfvbx`bg^kSd*U z;g6zB!3JFT!sKkEKSPEZ(%PeXaF?w6aCw_uf2XF?2HXv#n&DwIC$Auzs3*~08_Qug_yRC-0lTy(JYN|!bU*FS38nSN(&FDH zWA8aJ78e??nb;y5eOrc9`xyJs(@}`xB74z{>U}XDYsUjxLi>>KgnE%E!^6$QH%IDU zSqme)RQ3qDeNL4?R8=K-h({gmGWFjnVNkE4aLjuV-l^RsWBEqp^Soyk2V02`M@wf0 z$~2JZ69g8gke2DSTa>h7d854_ZBM2Z>@&~M7I7IIJ{uvr>=oZg*BbGt&6mF{E?rRK zZIa=XXT<t?U+ObEg{~6v2H;ftmGA-a@8G838cvqd}0dH zYF~V-mcU6V!4pfeD2=q1VaObsR2YcxsT`VW;g;j3(w85T2uS&+?Awf6z0XLhnxFV9`$?Jk(c=s3G@P}3V1z@XhBUr8xSHP=r&zkX0`tBqP2fB z5%z=xNf6NG2|>(My^dnLdvMv|QxYRnu-=;lDV7V$I+}+_X9qoCrxSrrnEn&+=q2gEMinxV5Z?c8p<2+?cz_l z34ajDN!5_zH~zypqWKa;#iiWJN>sHFoCFWwjidA|rcLfAttkQi{VtOIIYCBVF(?|K zD{sFBi`&i##KyL~XUUdY>IiID^^y)BVDz2do9L_wl05E(qDe7r`X10#H_QGmwGw;Z zEl{bvv$!c|YE;%=K)?-?k=Gbf6X-x%mc3B&)J5ePbIpF`qh#&s&(bNyrnb8o=I+iG zNDpg~WAzD+Q)R#v2P*+vf3btXJ@SwKarCZI-K>UqRkd|!#u*+zA3W&6OK)Umj6Yl! zL-@B%!xCRqln(IGrzK?a}iUb~P-t<|QiADu3`|CM0jL#$Z+6Bd8B=US5l%;mKOd+Y7nC z0A!B$QVq3Aj9OPCW7xI?oiZvS#3;3uK64#)Wc49h+G64z@Lw~(S|*cp8HoLs{Hak5y86~ z0jT|#cl@xLG(aELNUY=})O_0OCQH@GX#CL?)SQe51}kLj5O($k$N>T4kp2C!Vxgfu z3J>KVt9lP&(h9Sd&kFky27m3V(tB5krKzToJ!4kR5XkUPgO8&k`S0%Y!=Bz{MMmBN z(G94<#&%pxOpR}#rNLc}4?S z&zQp*)W8XaF-N?uTqnW~XfHYjwKeVzS~JqI33@1-8*G8kA8vf%5GYzRRquilZ_+YpY(1Q;2W2xMn+)6Zu}Ft2WU!MdCDb7; z849(L(wU0%Syd?>E43;ihF$hGpcXP=nlmz@S@wexW1z24w9XF)%j-lAF|WxJudjl% zZ5vK%5RvS>ad<>>04Aa~3MfBvrvGFQ+T0`lhooS3kgXc~8!mVwL^f-Gl}%J#-f^qv zvPIr>X9S691`ZHD1z86sRU*_$G&DTb%&dm(-Suur;hmv#9$w)ahMD4Z35!-E9+YXP zVd`T8P6D-^SfJ#5$vc5&njok7sOR@r+EA1y zaQ8coo1a#Af)tn^Z?c?xjaatiwb_cNuZOZw`^w@QRME?DH2#w6`V6qyZ#8Ey89mn7yR>oi))z! zk}Kp*WCI_QCpHdx`=ev(R-stqdM?5YDzgi!Rpmt)xwC!x!8#CVMlRihhxt1_Jf2L1!d3+^Yth*Y39ETJ)(H;9V!;!y;=R8~ta)MVa^ zCo3x4Vt5*6gwu~R((G@%VLfA2Y;O=>9k9#=C|NcOe=HdXqwz)9jh+ieLWx@>xn~EI4A_nh_t~9nU3XEPD(I-ujJ)TaO9E zwiWu<)Bg_o zP>tx;&KUxQY^5+!lfGEvtV@g=XR!$|UT94BVk%m82#&Y5i+#f8HxZRcJ1M4+(2$To zlbhY>3>TwRLLI30E1ab!ZkSvhW78)EZdBRb9Pwzs-Tc4_;ox%BTT+ldpM|9C*Lo;z z6_d!psR#hX%c144mfoqrP?kr;_qmDjq8{cUo|n3YC_U3;9I1qku|_Jyg<0buwst>D z{=gfK-r)BU4Y>0iAA%UPHtaJO7OD=oVq_^PEn9*=;A3KB(l5fy>-^F` z4ucIlf;$|vrcB#A2OqeS4Zz~HC9CR6Th){t4@80&Amg_FmMM!AR{ri%rhbi8Oq|Fy zKF>=AZ>`Owm;9=xa8j4Lb>lDCs%$Nai!`@R$DYegqro9DxuDjgn|q+<`N$|?@iY7) zzH4`8e?V~>nc^wY@w=rH2mqK?AU8eYpUp(56TRC22UIlFMjORswxNHn1-2XRzV62o5MKz!2XpC3l z+Kguk^>(ouE%}{xQ-%G%kL8P2-~HjVNE>q;9uvfH4n4wR4Wu%#6npR~o4mJ9ke$Qn z0#am5_5_VACJjLwpKDGTjzHws((BM$zxpKaB%ti2*%gFn^@X{IC|s-fEBK));$4@*QzFF($63D!cg5T#cm{Qt}&0=;7D>0LnNtHphB z9b9do zBgK!~b~tEe*g2R3%AwWE$G30KTg15~E$AiOn&CROhZ5dY7wN|iC1il{U3EdfG%K$E z;cVxT7@FQLSG{+8K;G#x#=U|6+1^>5x04&VS;UVkXCDF%-r+PF0N=7$wTC!zJFrt6 zEaz{)`o}-Ym$tn(N<`SOPAHP*No$?PZBxJYI$T~P?sH=$)DjV62;RFzIVn;+F^&z~2_z$;iE4+YLjv#8VqDCL_LV3%(5Ln>35Zru39dL3O|$0Ouo!WRxA!)KAsg z%tlg+l^iLdVbfW@Yc8`##No#ADa9kD<~Igy$m!?XGmwNflH&Pw+0Ao#6339%3tKg z_C*unkoS#z{{qad)e=R`*f|v}tCfYr;Ks-4LBIxWyiC?}IzKtt1>qv()hzQsBzAEI zH6)c%)_zO)>Q3}stL|6V27$ZNu~q0o@OSwl?ud-Ri&A|1H)m(KwpZ(jl3n$PPcgAE zOMCjxHc>Et{LB(4=YY2D{(9od`0L{28r+z=~{qY%fS3emq(ZS5^7g`KJ z8s!65lXUp;z81UL$TMabbP4~)hW0LnPOaNq*kkEclt(LpBdx!ov8|#h-t5X z?;aUM75PHV$6Qxf1lF8sl51={fMo}jIFNT}%Yt&XNgi9lT4(;Uy67E3qFjnk+n1|_ zKWKLVMR`4Opq^HK-K7wM#y%Je$NLBGqa45i7_3{-M9nPZJ8~_tYkR1jWT0O?oS5kc zLTWW?t`x->-BR1~;B4&I`~lNV%c-pqWg^^aJYhMVbzp3^20j(*TT02V+r+`ma?^|V z%K3BK0OI45P!r5>(xC`Oh0RPl%gM2PW+v9~CREMHxY@m(-pO%h_QW$wCQ`^3S zo05bGkb#hbf30K$;_lWWwY`sNZqeZ%Yd0psug4N@UK&e>`Y2K{>Mb)<5$|_bty`yj zGP%ZWW=#hWo4i8Hv>(0lQ~{NXyq(oyN)x>Yh33ru{OT72VEdT3Z?3qJ6|ee}(7%ju z9DgbA_Q6u@vkwHrOCSjnlkPgl0;7}!9v}Zb!|}fN`3yrOs|Dpi2 z_E>iP!^5%Mf%2tQbhOr9eE8H&ors=)#EkyDMOL0wZHfc1gTH zW7Yg2IIGF6IdO_&)`4#4)? zh$}FCCq#-~riiISQ^c$31yE=dpF##}WZ3ayluK*+?5&X=C`gN=#E5kmRW`>w7wg>p zUV*lqkJXo`jD<_8Z(JNEw41Tak>Ejf{XtVQ=S-w4wZ|OAhu)tOxsv^^`kieKswD&2 zK;k030)ZUueW&RSTLR3)^9ySD!E|+aP)e^4f^&792Z{rkAMOVpYpz$s;9_eN+L8`% z8Pi;Ww2=HYAH|uKv*eYUpzXCs(*_%CM7K4UJiqSp&!^!t$pG->)Fvl6zQ=6y%wkp^ z0RO0UQd>tl9Ja`Sh~Kbc0X00q5mfR0z*qqid+J~VGeSj6O#=9}mL;qhHMzv360XN#B(Z4A@NZA1oxy1q5%|}g zDyvhL@|~M9#$eL#yA<7uQWzWF&X_#U$q{R~_so#wMrGJeBJ}g(c>ga^aR?d;rfC*k zT2ml=z!O`Y50(bSp_Fqql@hT9%xG8TN%CJw&2ZgRbIdR)UW2KzVjn$23v4MgU;eTH zdwKa65{nxAGgXTBgDm5Q)Kt6yv&7@WcC^fUt7V|2A?A4vA=}57k033fc{E4w-9kb zZ}ZcdfVQWXlj=$=QLvH1w9RK1^WkL;=t5u?gB{E? zoP{^i%N3b@mD7L!{}z}OK0Srq^B?XDuVqut86pw$wN6ZZuLNrDg6j;>A~#=b+1b2 diff --git a/tests/oauth2/test__client.py b/tests/oauth2/test__client.py index 4997d2401..b34d2eb35 100644 --- a/tests/oauth2/test__client.py +++ b/tests/oauth2/test__client.py @@ -326,6 +326,7 @@ def test_call_iam_generate_id_token_endpoint(): response_body = json.loads(request.call_args[1]["body"]) assert response_body["audience"] == "fake_audience" assert response_body["includeEmail"] == "true" + assert response_body["useEmailAzp"] == "true" # Check result assert token == id_token