[VC-43403] Refactor the CyberArk identity client to take an HTTP client #698
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
I'm refactoring the CyberArk identity client to be less dependent on the service discovery client.
This detangles the those two packages and simplifies things.
The identity client interacts with the CyberArk authentication API.
The discoveryservice client retrieves a list of the services that are enabled for a particular tenant along with the associated API URLs.
The identity client now takes an identityAPI url parameter instead of a discovery client.
So we can test it in isolation.
I'm refactoring the various CyberArk API clients, so that we can more easily pass in a shared and customized HTTP client which will be used by all the of them.
Ultimately, I want to instantiate a single
http_client.NewDefaultClient
(from venafi-connection-lib) and supply it to all the CyberArk API wrappers. That client has a builtin retry mechanism and builtin user-agent header injection.This also makes it easier to pass in a client that is matched to an
httptest.NewTLSServer
; one configured with the CA certificates to connect to the server.Followups
Testing