Have an app running in GCP using App Engine and secured by IAP. To the best of my knowledge IAP uses OAuth, but when I open the app in the browser and inspect the outgoing XHR requests I don't see the HTTP Authorization header on any of them. There does appear to be a token in the cookies though, something named GCP_IAAP_AUTH_TOKEN. Just wondering if this is still considered OAuth or is it some other form of authentication?
Does OAuth always use the HTTP Authorization header?
589 views Asked by Dandan At
1
There are 1 answers
Related Questions in OAUTH
- Lambda endpoint for the Google OAuth callback does not recieve the access_token
- Miro oauth api throws error 401 Invalid authorization code
- Error from Identity Provider - OIDC Scope Error
- get refresh token in axios interceptor
- How would single sign-on work for my multi-tenant application?
- How to get OAuth2 Access token from Postman
- How to use Oauth in order to log‑in on .googleapis.com on almost any arbitrary endpoints domains from the web browser?
- How to fix common 500 internal server error when use POST method on NEXTJS
- How to use a different account for OAuth with dbt-core and profiles.yml?
- ASP.NET Core Google external login issue
- Implementing IDP Initiated Flow Using OIDC
- Migration of UseOAuthAuthorizationServer from .Net Framework to .Net8
- Django Allauth Bad Request Error, Error Retrieving Access Token: Invalid Grant
- angular oauth 2 oidc doesn't work with github idp
- Handling oauth in flutter app without browser
Related Questions in GOOGLE-CLOUD-PLATFORM
- Why do I need to wait to reaccess to Firestore database even though it has already done before?
- Unable to call datastore using GCP service account key json
- Troubleshooting Airflow Task Failures: Slack Notification Timeout
- GoogleCloud Error: Not Found The requested URL was not found on this server
- Kubernetes cluster on GCE connection refused error
- Best way to upload images to Google Cloud Storage?
- Permission 'storage.buckets.get' denied on resource (or it may not exist)
- Google Datastream errors on larger MySQL tables
- Can anyone explain the output of apache-beam streaming pipeline with Fixed Window of 60 seconds?
- Parametrizing backend in terraform on gcp
- Nonsense error using a Python Google Cloud Function
- Unable to deploy to GAE from Github Actions
- Assigned A record for Subdomain in Cloud DNS to Compute Engine VM instance but not propagated/resolved yet
- Task failure in DataprocCreateClusterOperator when i add metadata
- How can I get the long running operation with google.api_core.operations_v1.AbstractOperationsClient
Related Questions in GOOGLE-CLOUD-IAM
- Permission 'storage.buckets.get' denied on resource (or it may not exist)
- Is it possible to integrate Looker Studio with websites without keeping it public, to preserve data?
- Problem with Vertex AI's prediction endpoint
- GCP Monitoring Metrics Scope for RBAC
- Access Control for Google Cloud Logging
- How to lock down a firebase function using principle of least-privilege
- Firebase remote config : create role "Viewer" and" Editor Remote Config"
- How to connect GKE to Google Object Storage
- New to Google Storage, Cannot create a storage bucket as storage admin
- App Engine Deployer Role/ insufficent GCP permissions
- Access Control for Google Cloud Monitoring Dashboards
- Configuring `GOOGLE_APPLICATION_CREDENTIALS` for Multiple Projects in Docker
- GCP Cloud Build failed with error: Caller does not have permission or the resource may not exist
- GAE deploy via Github Actions : Failed to create cloud build: IAM authority does not have the permission 'cloudbuild.builds.create' action CreateBuild
- Cannot Impersonate service account using PHP google/apiclient library
Related Questions in GOOGLE-IAP
- Server Sent Events on Cloud Run with IAP
- Securing GAE/Cloud Run app with IAP but excluding static content
- Accessing IAP protected endpoint using service account via Python leads to 401 (azp/sub mismatch)
- Managing Identity-Aware Proxy users with glcoud and/or Terraform
- Connecting to GCE instance using service account and IAP
- Why does Google IAP require iap.googleapis.com to be in the list of redirect URIs?
- How to setup Google IAP between 2 Google App Engine Apps
- What can I do to solve Google Cloud vm instance network problem
- Compute Engine and IAP without load balancer
- How to make through Google's IAP in Cypress?
- Airflow-2 custom api auth_backend
- Google Cloud Pub/Sub: push subscription doesn't call IAP-protected GAE app
- Sporadic redirects by IAP despite valid cookie (recent development, started on Friday 14th January 2022)
- GCP ssh via identity access proxy fails locally but not via cloud shell
- GCloud ssh cannot connect when called
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Cloud IAP can use either the cookie
GCP_IAAP_AUTH_TOKENorAuthorization: Bearer. Both are derived from OAuth2.Authenticating with OpenID Connect