Skip to content

fix(io): pass GCS token expiry to gcsfs - #4089

Open
amdubovoi wants to merge 1 commit into
apache:mainfrom
amdubovoi:fix/gcs-token-expiry
Open

amdubovoi wants to merge 1 commit into
apache:mainfrom
amdubovoi:fix/gcs-token-expiry

Conversation

@amdubovoi

Copy link
Copy Markdown

Rationale for this change

FsspecFileIO passes the GCS token to gcsfs without its expiry. gcsfs 2026.2.0 and later then look up the expiry at tokeninfo, which fails for down-scoped tokens that REST catalogs vend. Reads fail with Provided token is either not valid, or expired.

A token with gcs.oauth2.token-expires-at now goes to gcsfs as google.oauth2.credentials.Credentials with that expiry.

Are these changes tested?

Yes, with unit tests and against a REST catalog that vends down-scoped GCS tokens.

Are there any user-facing changes?

Yes. Vended GCS credentials work again with gcsfs 2026.2.0 and later.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant