Files
fleet/website/api/helpers/android-proxy/get-android-management-authorization-client.js
Eric 632b4d924b Website: use shared Google API auth client in android proxy endpoints. (#47810)
Closes: https://github.com/fleetdm/fleet/issues/46496

Changes:
- Updated the website's custom hook to create a Google API auth client
and make it available at `sails.googleAuthClient`
- Updated Android proxy endpoints to use the shared Google API auth
client.

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Refactor**
* Optimized Google API authentication handling for Android management
features to improve system performance and reliability.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-07-20 18:38:55 -05:00

62 lines
2.6 KiB
JavaScript
Vendored

module.exports = {
friendlyName: 'Get Android Management authorization client',
description: 'Returns a shared Google API auth client for the Android Management API proxy, creating it if one has not been created yet.',
moreInfoUrl: 'https://github.com/fleetdm/fleet/issues/46496',
exits: {
success: {
outputFriendlyName: 'Android Management authorization client',
outputDescription: 'The shared Google API auth client stored on `sails.androidManagementAuthorization`.',
outputType: 'ref',
},
},
fn: async function () {
require('assert')(sails.config.custom.androidEnterpriseServiceAccountEmailAddress);
require('assert')(sails.config.custom.androidEnterpriseServiceAccountPrivateKey);
// Initialize a Google API auth client for the Android Management API proxy, but only if one has not
// already been created for this server process. The googleapis library caches the OAuth2 access_token
// on a reused client and refreshes it automatically when it expires, so we build a single shared client
// per process (each web dyno is its own process) and reuse it across all Android proxy requests.
if (!sails.androidManagementAuthorization) {
let { google } = require('googleapis');
let googleAuth = new google.auth.GoogleAuth({
// The pubsub scope is included because creating/deleting an Android enterprise also provisions/removes a Pub/Sub topic and subscription.
scopes: [
'https://www.googleapis.com/auth/androidmanagement',
'https://www.googleapis.com/auth/pubsub',
],
credentials: {
client_email: sails.config.custom.androidEnterpriseServiceAccountEmailAddress,// eslint-disable-line camelcase
private_key: sails.config.custom.androidEnterpriseServiceAccountPrivateKey,// eslint-disable-line camelcase
},
});
let androidManagementAuthClient = await googleAuth.getClient();
// Mint an access token now so invalid credentials surface here instead of failing silently on the
// first Android Management API call. This only hits Google's OAuth2 token endpoint, not the Android
// Management API, so it does not count against AMAPI rate limits.
await androidManagementAuthClient.getAccessToken();
// Assign the global last, so that if either step above throws, the global is left unset and the next
// request retries instead of caching a client whose credentials never validated.
sails.androidManagementAuthorization = androidManagementAuthClient;
}
return sails.androidManagementAuthorization;
}
};