Skip to content

Conversation

lantoli
Copy link
Member

@lantoli lantoli commented Oct 14, 2025

Description

Enable OAuth token test

Link to any related issue(s): CLOUDP-347669

Type of change:

  • Bug fix (non-breaking change which fixes an issue). Please, add the "bug" label to the PR.
  • New feature (non-breaking change which adds functionality). Please, add the "enhancement" label to the PR. A migration guide must be created or updated if the new feature will go in a major version.
  • Breaking change (fix or feature that would cause existing functionality to not work as expected). Please, add the "breaking change" label to the PR. A migration guide must be created or updated.
  • This change requires a documentation update
  • Documentation fix/enhancement

Required Checklist:

  • I have signed the MongoDB CLA
  • I have read the contributing guides
  • I have checked that this change does not generate any credentials and that they are NOT accidentally logged anywhere.
  • I have added tests that prove my fix is effective or that my feature works per HashiCorp requirements
  • I have added any necessary documentation (if appropriate)
  • I have run make fmt and formatted my code
  • If changes include deprecations or removals I have added appropriate changelog entries.
  • If changes include removal or addition of 3rd party GitHub actions, I updated our internal document. Reach out to the APIx Integration slack channel to get access to the internal document.

Further comments

@lantoli lantoli marked this pull request as ready for review October 14, 2025 17:02
@lantoli lantoli requested a review from a team as a code owner October 14, 2025 17:02
@Copilot Copilot AI review requested due to automatic review settings October 14, 2025 17:02
Copy link
Contributor

@Copilot Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull Request Overview

This PR enables OAuth token testing by adding infrastructure to generate OAuth2 access tokens and running the previously skipped TestAccAccessToken_basic test in CI. The change removes the CI skip condition and adds the necessary tooling to generate valid access tokens during test execution.

  • Removes CI skip for OAuth token test that was previously disabled due to token validity constraints
  • Adds OAuth2 token generation tool for creating access tokens from service account credentials
  • Integrates token generation into the CI workflow to enable automated OAuth testing

Reviewed Changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 1 comment.

File Description
tools/generate-oauth2-token/main.go New utility to generate OAuth2 access tokens from service account credentials
internal/provider/provider_authentication_test.go Removes CI skip condition for OAuth token test
Makefile Adds target for OAuth2 token generation
.github/workflows/acceptance-tests-runner.yml Integrates token generation and OAuth test execution in CI workflow

Tip: Customize your code reviews with copilot-instructions.md. Create the file or learn how to get started.

exit 1
fi
{
echo "access_token<<EOF"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Interesting way of creating multiline variable. I guess access token spans multiple lines?

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

it's not because multi-line but because characters that need to be escaped so heredoc is used

Copy link
Collaborator

@EspenAlbert EspenAlbert left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nice

Copy link
Collaborator

@marcosuma marcosuma left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just making sure we're not accidentally exposing tokens/secrets

exit 1
fi
{
echo "access_token<<EOF"
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

just double checking: no token will be output in the console, right?

Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can check last run logs: link - all good 👌

Copy link
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

correct, it'll show the typical ***

@lantoli lantoli merged commit 939d512 into CLOUDP-334161-service-accounts-dev Oct 15, 2025
51 checks passed
@lantoli lantoli deleted the CLOUDP-347669_token_test branch October 15, 2025 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants