Skip to content

Commit 0dbc9d3

Browse files
committed
add tls_client_auth docs
1 parent ef1b354 commit 0dbc9d3

1 file changed

Lines changed: 20 additions & 4 deletions

File tree

‎pulsar/__init__.py‎

Lines changed: 20 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -507,14 +507,17 @@ def __init__(self, auth_params_string: str):
507507
508508
.. code-block:: python
509509
510-
auth = AuthenticationOauth2('{"issuer_url": "xxx", "private_key": "yyy"}')
510+
auth = AuthenticationOauth2('{"issuer_url": "xxx", "private_key": "yyy", "audience": "zzz"}')
511511
512512
The valid JSON fields are:
513513
514-
* issuer_url (required)
514+
* tokenEndpointAuthMethod (optional, default="client_secret_post")
515+
The authentication method used by the OAuth 2.0 token endpoint. Supported values are
516+
``client_secret_post`` and ``tls_client_auth``.
517+
* issuer_url (required for both authentication methods)
515518
The URL of the authentication provider which allows the Pulsar client to obtain an
516519
access token.
517-
* private_key (required)
520+
* private_key (required for ``client_secret_post``)
518521
The URL to the JSON credentials file. It supports the following pattern formats:
519522
520523
* ``/path/to/file``
@@ -527,10 +530,23 @@ def __init__(self, auth_params_string: str):
527530
528531
* ``client_id``
529532
* ``client_secret``
530-
* audience
533+
* audience (required for ``client_secret_post``, optional for ``tls_client_auth``)
531534
The OAuth 2.0 "resource server" identifier for a Pulsar cluster.
532535
* scope
533536
The scope of an access request.
537+
* tls_cert_file (required for ``tls_client_auth``, optional for ``client_secret_post``)
538+
Path to the TLS client certificate file.
539+
* tls_key_file (required for ``tls_client_auth``, optional for ``client_secret_post``)
540+
Path to the TLS client private key file. ``tls_cert_file`` and ``tls_key_file`` must
541+
be specified together.
542+
* client_id (optional for ``tls_client_auth``)
543+
The OAuth 2.0 client identifier. If omitted, ``pulsar-client`` is used. For
544+
``client_secret_post``, set this field in the JSON credentials file referenced by
545+
``private_key``.
546+
547+
For ``client_secret_post``, ``issuer_url``, ``private_key``, and ``audience`` are required.
548+
For ``tls_client_auth``, ``private_key`` is not required and ``tls_cert_file`` and
549+
``tls_key_file`` are required.
534550
535551
Parameters
536552
----------

0 commit comments

Comments
 (0)