See :ref:`versioning` for our versioning policy.
The :ref:`upgrading <upgrading>` doc is a good reference if you are upgrading to a major new version of the SDK.
TransferClientmethods which are specific to Globus Connect Server v4 are now deprecated and emit deprecation warnings when used. (:pr:`1274`)- The
ComputeClientalias forComputeClientV2is now deprecated. Users of Globus Compute are encouraged to useComputeClientV2orComputeClientV3instead. (:pr:`1278`)
- Recognize
dependent_consent_requirederrors from the Auth API as a Globus Auth Requirements Error (GARE) and support converting them to GAREs. (:pr:`1246`)
- Accept authorization parameters containing dependent scopes
when
app.login()is called with a GARE's authorization parameters. (:pr:`1247`)
- Added the
TransferClient.set_subscription_admin_verified()method. (:pr:`1227`) - Updated
ComputeClientV2.get_endpointswith a newrolekwarg. (:pr:`1238`)
Convert the CHANGELOG to Markdown-compatible headers.
This resolves rendering issues in Dependabot PRs in the CLI, and simplifies compatibility between RST and Markdown.
- Add the
SpecificFlow.validate_run()method. (:pr:`1221`)
- Fix an error which caused the
restrict_transfers_to_high_assurancefield to be malformed when set on a collection payload type. (:pr:`1211`)
- Globus Connect Server collection document classes now support attributes up to document version 1.15.0. (:pr:`1197`)
- Importing scope parsing tools from
globus_sdk.experimentalnow emits a deprecation warning. These names were previously deprecated in documentation only. (:pr:`1201`)
- Remove the badges at the top of the README. (:pr:`1194`)
- Fix the type annotation on
filter_rolesforFlowsClientto allow non-list iterables. (:pr:`1183`)
- Transport objects now provide a
close()method for closing resources which belong to them, primarily the underlying session. (:pr:`1171`) - Add
activity_notification_policyto GuestCollectionDocument, associating it with GCS collection document version 1.14.0. (:pr:`1172`) FlowsClient.list_flowsandFlowsClient.list_runsnow support thefilter_rolesparameter to filter results by one or more roles. (:pr:`1174`)AuthLoginClientnow supports asession_messagewhen constructing an OAuth2 authorization URL. (:pr:`1179`)LoginFlowManagerwill now use asession_messagepresent in the suppliedGlobusAuthorizationParametersas part of the login flow. (:pr:`1179`)
- When parsing GAREs using
to_gareandto_gares, the root document is now considered a possible location for a GARE when subdocument errors are present on aGlobusAPIErrorobject. Previously, the root document would only be considered in the absence of subdocument errors. (:pr:`1173`)
filter_roleparameter forFlowsClient.list_flowsis deprecated. Usefilter_rolesinstead. (:pr:`1174`)
FlowsClient.create_flowandFlowsClient.update_flownow supportrun_managersandrun_monitors. (:pr:`1164`)SpecificFlowClient.run_flow()now supportsactivity_notification_policyas an argument, allowing users to select when their run will notify them. A new helper,RunActivityNotificationPolicy, makes construction of valid policies easier. (:pr:`1167`)
- The initialization of a client with a
GlobusApphas been improved and is now available under the publicattach_globus_appmethod on client classes. Attaching an app is only valid for clients which were initialized without an app or authorizer. (:pr:`1137`) - When a
GlobusAppis used with a client, that client'sapp_scopesattribute will now always be populated with the scopes that it passed back to the app. (:pr:`1137`)
- Added the optional
required_mfafield toAuthClient.create_policy()andAuthClient.update_policy()request bodies. (:pr:`1159`)
- Index listing in Globus Search is now available via
SearchClient.index_list. (:pr:`1155`)
- The
reprforglobus_sdk.gare.GAREhas been enhanced to be more informative. (:pr:`1156`)
- New sections on
Data TransferandSession & Consentshave been added to the User Guide in the docs. Initial docs cover transfer submission, timer creation, deadlines, and reauthentication after session timeouts. (:pr:`1150`, :pr:`1154`, :pr:`1157`)
- The
transportattached to clients now exposesheadersas a readable and writable dict of headers which will be included in every request. Headers provided to the transport'srequest()method overwrite these, as before. (:pr:`1140`)
- Updates to
X-Globus-Client-InfoinRequestsTransport.headersare now synchronized via a callback mechanism. Direct manipulations of theinfoslist will not result in headers being updated -- callers wishing to modify these data should rely only on theadd()andclear()methods of theGlobusClientInfoobject. (:pr:`1140`) globus_sdklogging no longer emits any INFO-level log messages. All INFO messages have been downgraded to DEBUG. (:pr:`1146`)
- The tutorial documentation has been rewritten. (:pr:`1145`)
- Most client classes now have their
__doc__attribute modified at runtime to provide betterhelp()and sphinx documentation. (:pr:`1131`) - Introduce
globus_sdk.IDTokenDecoder, which implementsid_tokendecoding. (:pr:`1136`)- For integration with
GlobusApp, a new builder protocol is defined,IDTokenDecoderProvider. This defines instantiation within the context of an app. - When
OAuthTokenResponse.decode_id_tokenis called, it now internally instantiates anIDTokenDecoderand uses it to perform the decode. IDTokenDecoderobjects cache OpenID configuration data and JWKs after looking them up. If a decoder is used multiple times, it will reuse the cached data.- Token storage constructs can now contain an
IDTokenDecoderin theirid_token_decoderattribute. The decoder is used preferentially when trying to read thesubfield from anid_tokento store. GlobusAppConfigcan now containid_token_decoder, anIDTokenDecoderorIDTokenDecoderProvider. The default isIDTokenDecoder.GlobusAppinitialization will now use the config'sid_token_decoderand attach theIDTokenDecoderto the token storage which is used.
- For integration with
ConnectorTablehas a new classmethod,extendwhich allows users to add new connectors to the mapping.ConnectorTable.extend()returns a new connector table subclass and does not modify the original. (:pr:`1021`)- Add
ComputeClientV3.register_function()method. (:pr:`1142`)
- The SDK now defaults JWT leeway to 300 seconds when decoding
id_tokens; the previous leeway was 0.5 seconds. Users should find that they are much less prone to validation errors when working in VMs or other scenarios which can cause significant clock drift. (:pr:`1135`)
- Subclasses of
BaseClientmay now specifybase_urlas class attribute. (:pr:`1125`)
- Fixed an incorrect URL path in
ComputeClient.get_task_batch. (:pr:`1117`) - Fix a bug in
StorageGatewayDocumentwhich stored anyallowed_domainsargument under an"allow_domains"key instead of the correct key,"allowed_domains". (:pr:`1120`)
- Updated GlobusAppConfig docs to explain how to disable auto-login. (:pr:`1127`)
- Add
filter_entity_typekeyword argument onTransferClient.endpoint_search(). (:pr:`1109`) - Added the
ComputeClientV3.register_endpoint(),ComputeClientV3.update_endpoint()ComputeClientV3.lock_endpoint(), andComputeClientV3.get_endpoint_allowlist()methods. (:pr:`1113`) - Added the
ComputeClientV2.get_version()andComputeClientV2.get_result_amqp_url()methods. (:pr:`1114`)
- Added the
ComputeClientV2.register_endpoint(),ComputeClientV2.get_endpoint()ComputeClientV2.get_endpoint_status(),ComputeClientV2.get_endpoints(),ComputeClientV2.delete_endpoint(), andComputeClientV2.lock_endpoint()methods. (:pr:`1110`)
- Removed identity ID consistency validation from
ClientApp. (:pr:`1111`)
- Fixed a bug that would cause
ClientApptoken refreshes to fail. (:pr:`1111`)
- Add
TimersClient.add_app_transfer_data_access_scopeforTimersClientinstances which are integrated withGlobusApp. This method registers the nested scope dependency for adata_accessrequirement for a transfer timer. (:pr:`1074`) SearchQueryV1is a new class for submitting complex queries replacing the legacySearchQueryclass. A deprecation warning has been added to theSearchQueryclass. (:pr:`1079`)- Created
ComputeClientV2andComputeClientV3classes to support Globus Compute API versions 2 and 3, respectively. The canonicalComputeClientis now a subclass ofComputeClientV2, preserving backward compatibility. (:pr:`1096`) - Added the
ComputeClientV3.submit(),ComputeClientV2.submit(),ComputeClientV2.get_task(),ComputeClientV2.get_task_batch(), andComputeClientV2.get_task_group()methods. (:pr:`1094`)
- Improved error messaging around EOF errors when prompting for code during a command line login flow (:pr:`1093`)
- Deprecated the
ComputeFunctionDocumentandComputeFunctionMetadataclasses. This change reflects an early design adjustment to better align with the existing Globus Compute SDK. (:pr:`1092`)
- Introduce a
toxfile.pyto ensure clean builds during development. (:pr:`1098`) - The lazy importer used for the top-level
globus_sdkmodule has been rewritten. It produces identical results to the previous system. (:pr:`1100`)
- Support Python 3.13. (:pr:`1058`)
- Added an initial Globus Compute client class, :class:`globus_sdk.ComputeClient`.
(:pr:`1071`)
- Application errors are raised as a :class:`globus_sdk.ComputeAPIError`.
- A single method,
ComputeClient.get_functionis included initially to get information about a registered function. - Compute scopes are defined at
globus_sdk.scopes.ComputeScopesorglobus_sdk.ComputeClient.scopes.
- Added the
ComputeClient.register_function()andComputeClient.delete_function()methods. (:pr:`1085`)ComputeClient.register_function()introduces new data model classes:ComputeFunctionDocumentandComputeFunctionMetadata.
- Added the
TransferClient.set_subscription_id()method. (:pr:`1073`) - Added a new error type,
globus_sdk.ValidationError, used in certain cases ofValueErrors caused by invalid content. (:pr:`1044`)
- Removed the
skip_error_handlingoptional kwarg from theGlobusApp.get_authorizer(...)method interface. (:pr:`1060`)
All previously experimental modules have been moved into main module namespaces and are no longer experimental. Aliases will remain in the experimental namespaces with a deprecation warning until SDKv4.
- :ref:`gares` have been moved from
globus_sdk.experimental.auth_requirements_errortoglobus_sdk.gare. (:pr:`1048`)- The primary document type has been renamed from
GlobusAuthRequirementsErrortoGARE. - The functions provided by this interface have been renamed to use
garein their naming:to_gare,is_gare,has_gares, andto_gares.
- The primary document type has been renamed from
- :ref:`globus_apps` have been moved from
globus_sdk.experimental.globus_apptoglobus_sdkandglobus_sdk.globus_app. (:pr:`1085`) - :ref:`login_flow_managers` have been moved from
globus_sdk.experimental.login_flow_managerstoglobus_sdk.login_flows. (:pr:`1057`) - :ref:`token_storages` have been moved from
globus_sdk.experimental.tokenstoragetoglobus_sdk.tokenstorage. (:pr:`1065`) - :ref:`consents` have been moved from
globus_sdk.experimental.consentstoglobus_sdk.scopes.consents. (:pr:`1047`)
- :ref:`gares` have been moved from
The response classes for OAuth2 token grants now vary by the grant type. For example, a
refresh_token-type grant now produces a :class:`globus_sdk.OAuthRefreshTokenResponse`. This allows code handling responses to more easily identify which grant type produced a response. (:pr:`1051`)- The following new classes have been introduced: :class:`globus_sdk.OAuthRefreshTokenResponse`, :class:`globus_sdk.OAuthAuthorizationCodeResponse`, and :class:`globus_sdk.OAuthClientCredentialsResponse`.
- The
RenewingAuthorizerclass is now a generic over the response type which it handles, and the subtypes of authorizers are specialized for their types of responses. e.g.,class RefreshTokenAuthorizer(RenewingAuthorizer[OAuthRefreshTokenResponse]).
The mechanisms of token data validation inside of
GlobusAppare now more modular and extensible. TheValidatingTokenStorageclass does not define built-in validation behaviors, but instead contains a list of validator objects, which can be extended and otherwise altered. (:pr:`1061`)- These changes allow more validation criteria around token data to be
handled within the
ValidatingTokenStorage. This changes error behaviors to avoid situations in which multiple errors are raised serially by different layers of GlobusApp.
- These changes allow more validation criteria around token data to be
handled within the
LoginFlowManagers built withGlobusAppnow generate a more appropriate value forprefill_named_grant, using the current hostname if possible. (:pr:`1075`)Imports of
globus_sdk.excnow defer importingrequestsso as to reduce import-time performance impact the library is not needed. (:pr:`1044`)The following error classes are now lazily loaded even when
globus_sdk.excis imported:GlobusConnectionError,GlobusConnectionTimeoutError,GlobusTimeoutError, andNetworkError.
- Fixed the typing-time attributes of
globus_sdkso thatmypyand other type checkers won't erroneously suppress errors about missing attributes. (:pr:`1052`) - Fixed the handling of Dependent Token and Refresh Token responses in
TokenStorageandValidatingTokenStoragesuch thatid_tokenis only parsed when appropriate. (:pr:`1055`) - Fixed a bug where upgrading from access token to refresh token mode in a
GlobusAppcould result in multiple login prompts. (:pr:`1060`)
- The scope builder for
SpecificFlowClientis now available for direct access and use viaglobus_sdk.scopes.SpecificFlowScopeBuilder. Callers can initialize this class with aflow_idto get a scope builder for a specific flow, e.g.,SpecificFlowScopeBuilder(flow_id).user.SpecificFlowClientnow uses this class internally. (:pr:`1030`) TransferClient.add_app_data_access_scopenow accepts iterables of collection IDs as an alternative to individual collection IDs. (:pr:`1034`)
Experimental
- Added
login(...),logout(...), andlogin_required(...)to the experimentalGlobusAppconstruct. (:pr:`1041`)login(...)initiates a login flow if:- the current entity requires a login to satisfy local scope requirements or
auth_params/force=Trueis passed to the method.
logout(...)remove and revokes the current entity's app-associated tokens.login_required(...)returns a boolean indicating whether the app believes a login is required to satisfy local scope requirements.
Experimental
Made
run_login_flowprivate in the experimentalGlobusAppconstruct. Usage sites should be replaced with eitherapp.login()orapp.login(force=True). (:pr:`1041`)Old Usage
app = UserApp("my-app", client_id="<my-client-id>") app.run_login_flow()
New Usage
app = UserApp("my-app", client_id="<my-client-id>") app.login(force=True)
- The client for Globus Timers has been renamed to
TimersClient. The prior name,TimerClient, has been retained as an alias. (:pr:`1032`)- Similarly, the error and scopes classes have been renamed and aliased:
TimersAPIErrorreplacesTimerAPIErrorandTimersScopesreplacesTimerScopes. - Internal module names have been changed to
timersfromtimerwhere possible. - The
service_nameattribute is left astimerfor now, as it is integrated into URL and_testinglogic.
- Similarly, the error and scopes classes have been renamed and aliased:
Experimental
The experimental
TokenStorageProviderandLoginFlowManagerProviderprotocols have been updated to require keyword-only arguments for theirfor_globus_appmethods. This protects against potential ordering confusion for their arguments. (:pr:`1028`)The
default_scope_requirementsforglobus_sdk.FlowsClienthas been updated to list the Flowsallscope. (:pr:`1029`)The
CommandLineLoginFlowManagernow exposesprint_authorize_urlandprompt_for_codeas methods, which replace thelogin_promptandcode_promptparameters. Users who wish to customize prompting behavior now have a greater degree of control, and can effect this by subclassing theCommandLineLoginFlowManager. (:pr:`1039`)Example usage, which uses the popular
clicklibrary to handle the prompts:import click from globus_sdk.experimental.login_flow_manager import CommandLineLoginFlowManager class ClickLoginFlowManager(CommandLineLoginFlowManager): def print_authorize_url(self, authorize_url: str) -> None: click.echo(click.style("Login here for a code:", fg="yellow")) click.echo(authorize_url) def prompt_for_code(self) -> str: return click.prompt("Enter the code here:")
GlobusApp.token_storageis now a public property, allowing users direct access to theValidatingTokenStorageused by the app to build authorizers. (:pr:`1040`)The experimental
GlobusAppconstruct's scope exploration interface has changed fromapp.get_scope_requirements(resource_server: str) -> tuple[Scope]toapp.scope_requirements. The new property will return a deep copy of the internal requirements dictionary mapping resource server to a list of Scopes. (:pr:`1042`)
TimerScopesis now a deprecated name. UseTimersScopesinstead. (:pr:`1032`)
Experimental
- Container types in
GlobusAppfunction argument annotations are now generally covariant collections likeMappingrather than invariant types likedict. (:pr:`1035`)
- The Globus Timers examples have been significantly enhanced and now leverage more modern usage patterns. (:pr:`1032`)
- Added a reference to the new Flows all scope under
globus_sdk.scopes.FlowsScopes.all. (:pr:`1016`)
Experimental
- Added support for
ScopeCollectionTypeto GlobusApp's__init__andadd_scope_requirementsmethods. (:pr:`1020`)
- Updated
ScopeCollectionTypeto be defined recursively. (:pr:`1020`) TransferClient.add_app_data_access_scopenow raises an error if it is given an invalid collection ID. (:pr:`1022`)
Experimental
- Changed the experimental
GlobusAppclass in the following way (:pr:`1017`):app_nameis no longer required (defaults to "Unnamed Globus App")- Token storage now defaults to including the client id in the path.
- Old (unix) :
~/.globus/app/{app_name}/tokens.json - New (unix):
~/.globus/app/{client_id}/{app_name}/tokens.json - Old (win):
~\AppData\Local\globus\app\{app_name}\tokens.json - New (win):
~\AppData\Local\globus\app\{client_id}\{app_name}\tokens.json
- Old (unix) :
GlobusAppConfig.token_storagenow accepts shorthand string references:"json"to use aJSONTokenStorage,"sqlite"to use aSQLiteTokenStorageand"memory"to use aMemoryTokenStorage.GlobusAppConfig.token_storagealso now accepts aTokenStorageProvider, a class with afor_globus_app(...) -> TokenStorageclass method.- Renamed the experimental
FileTokenStorageattribute.filenameto.filepath.
- Changed the experimental
GlobusAppclass in the following ways (:pr:`1018`):LoginFlowManagersnow insertGlobusApp.app_nameinto any native client login flows as theprefill_named_grant.GlobusAppConfignow accepts alogin_redirect_uriparameter to specify the redirect URI for a login flow.- Invalid when used with a
LocalServerLoginFlowManager. - Defaults to
"https://auth.globus.org/v2/web/auth-code"for native client flows. Raises an error if not set for confidential ones.
- Invalid when used with a
UserAppnow allows for the use of confidential client flows with the use of either aLocalServerLoginFlowManageror a configuredlogin_redirect_uri.GlobusAppConfig.login_flow_managernow accepts shorthand string references"command-line"to use aCommandLineLoginFlowManagerand"local-server"to use aLocalServerLoginFlowManager.GlobusAppConfig.login_flow_manageralso now accepts aLoginFlowManagerProvider, a class with afor_globus_app(...) -> LoginFlowManagerclass method.
- Added a scope normalization function
globus_sdk.scopes.scopes_to_scope_listto translate fromScopeCollectionTypeto a list ofScopeobjects. (:pr:`1020`)
- The
TransferClient.task_listmethod now supportsorderbyas a parameter. (:pr:`1011`)
- The
SQLiteTokenStoragecomponent inglobus_sdk.experimentalhas been changed in several ways to improve its interface. (:pr:`1004`) :memory:is no longer accepted as a database name. Attempts to use it will trigger errors directing users to useMemoryTokenStorageinstead.- Parent directories for a target file are automatically created, and this
behavior is inherited from the
FileTokenStoragebase class. (This was previously a feature only of theJSONTokenStorage.) - The
config_storagetable has been removed from the generated database schema, the schema version number has been incremented to2, and methods and parameters related to manipulation ofconfig_storagehave been removed.
- Added a new experimental "Updated Examples" section which rewrites and reorders many examples to aid in discovery. (:pr:`1008`)
GlobusApp,UserApp`, and ``ClientAppclass reference docs. (:pr:`1013`)- Added a narrative example titled
Using a GlobusAppdetailing the basics of constructing and using a GlobusApp. (:pr:`1013`) - Remove unwritten example updates from toctree. (:pr:`1014`)
- Remove support for Python 3.7. (:pr:`997`)
- Add
globus_sdk.ConnectorTablewhich provides information on supported Globus Connect Server connectors. This object maps names to IDs and vice versa. (:pr:`955`) - Support adding query parameters to
ConfidentialAppAuthClient.oauth2_token_introspectvia aquery_paramsargument. (:pr:`984`) - Add
get_gcs_infoas a helper method toGCSClientfor getting information from a Globus Connect Server'sinfoAPI route. - Add
endpoint_client_idas a property toGCSClient. - Clients will now emit a
X-Globus-Client-Infoheader which reports the version of theglobus-sdkwhich was used to send a request. Users may customize this header further by modifying theglobus_client_infoobject attached to the transport object. (:pr:`990`)
Experimental
Add a new abstract class,
TokenStorage, toexperimental.TokenStorageexpands the functionality ofStorageAdapterbut is not fully backwards compatible. (:pr:`980`)FileTokenStorage,JSONTokenStorage,MemoryTokenStorageandSQLiteTokenStorageare new concrete implementations ofTokenStorage.
Add
ValidatingStorageAdaptertoexperimental, which validates that identity is maintained and scope requirements are met on token storage/retrieval. (:pr:`978`, :pr:`980`)Add a new abstract class,
AuthorizerFactorytoexperimental.AuthorizerFactoryprovides an interface for getting aGlobusAuthorizerfrom aValidatingTokenStorage. (:pr:`985`)AccessTokenAuthorizerFactory,RefreshTokenAuthorizerFactory, andClientCredentialsAuthorizerFactoryare new concrete implementations ofAuthorizerFactory.
Add a new abstract class,
GlobusApptoexperimental. AGlobusAppis an abstraction which allows users to define their authorization requirements implicitly and explicitly, attach that state to their various clients, and drive login flows. (:pr:`986`)UserAppandClientAppare new implementations ofGlobusAppwhich handle authentications for user-login and client-credentials.
GlobusAppConfigis an object which can be used to controlGlobusAppbehaviors.
Add
appas an optional argument toBaseClientwhich will accept aGlobusAppto handle authentication, token validation, and token storage when using the client.Add
default_scope_requirementsas a property toBaseClientfor subclasses to define scopes to automatically be used with aGlobusApp. The default implementation raises aNotImplementedError.Add
add_app_scopetoBaseClientas an interface for adding additional scope requirements to itsapp.AuthClient,FlowsClient,GCSClient,GroupsClient,SearchClient,TimerClient, andTransferClientall addappas an optional argument and definedefault_scope_requirementsso that they can be used with aGlobusApp.Add
add_app_data_access_scopetoTransferClientas an interface for adding a dependent data access scope requirements needed for interacting with standard Globus Connect Server mapped collections to itsapp.Auto-login (overridable in config) GlobusApp login retry on token validation error. (:pr:`994`)
Added the configuration parameter
GlobusAppConfig.environment. (:pr:`1001`)
GCSClientinstances now have a non-Noneresource_serverproperty.GlobusAuthorizationParametersno longer enforces that at least one field is set. (:pr:`989`)- Improved the validation and checking used inside of
globus_sdk.tokenstorage.SimpleJSONFileAdapterandglobus_sdk.experimental.tokenstorage.JSONTokenStorage. (:pr:`997`)
GCSClient.connector_id_to_namehas been deprecated. UseConnectorTable.lookupinstead. (:pr:`955`)
Experimental
- When a
JSONTokenStorageis used, the containing directory will be automatically be created if it doesn't exist. (:pr:`998`) GlobusApp.add_scope_requirementsnow has the side effect of clearing the authorizer cache for any referenced resource servers. (:pr:`1000`)GlobusAuthorizer.scope_requirementswas made private and a new method for accessing scope requirements was added atGlobusAuthorizer.get_scope_requirements. (:pr:`1000`)- A
GlobusAppwill now auto-create an Auth consent client for dependent scope evaluation against consents as a part of instantiation. (:pr:`1000`) - Fixed a bug where specifying dependent tokens in a new
GlobusAppwould cause the app to infinitely prompt for log in. (:pr:`1002`) - Fixed a
GlobusAppbug which would cause LocalServerLoginFlowManager to error on MacOS when versions earlier than Python 3.11. (:pr:`1003`)
- Document how to manage Globus SDK warnings. (:pr:`988`)
- Added a new AuthClient method
get_consentsand supporting local data objects. These allows a client to poll and interact with the current Globus Auth consent state of a particular identity rooted at their client. (:pr:`971`) - Added
LoginFlowManagerandCommandLineLoginFLowManagerto experimental (:pr:`972`) - Added
LocalServerLoginFlowManagerto experimental (:pr:`977`) - Added support to
FlowsClientfor thevalidate_flowoperation of the Globus Flows service. (:pr:`979`)
- Add
globus_sdk.tokenstorage.MemoryAdapterfor the simplest possible in-memory token storage mechanism. (:pr:`964`) ConfidentialAppAuthClient.oauth2_get_dependent_tokensnow supports thescopeparameter as a string or iterable of strings. (:pr:`965`)- Moved scope parsing out of experimental. The
Scopeconstruct is now importable from the top levelglobus_sdkmodule. (:pr:`966`) - Support updating subscriptions assigned to flows in the Flows service. (:pr:`974`)
- Fix concurrency problems in the test suite caused by isort's
.isortedtemporary files. (:pr:`973`)
- Added
TransferClient.operation_stathelper method for getting the status of a path on a collection (:pr:`961`)
IterableGCSResponseandUnpackingGCSResponseare now available as top-level exported names. (:pr:`956`)- Add
GroupsClient.get_group_by_subscription_idfor resolving subscriptions to groups. This also expands the_testingdata forget_groupto include a subscription group case. (:pr:`957`) - Added
promptto the recognized Globus Authorization Requirements Errorauthorization_parametersfields. (:pr:`958`)
- All of the basic HTTP methods of
BaseClientand its derived classes which accept adataparameter for a request body, e.g.TransferClient.postorGroupsClient.put, now allow thedatato be passed in the form of already encodedbytes. (:pr:`951`)
- Update
ensure_datatypeto work with documents that setDATA_TYPEtoMISSINGinstead of omitting it (:pr:`952`)
- Added support for GCS endpoint get & update operations (:pr:`933`)
gcs_client.get_endpoint()gcs_client.update_endpoint(EndpointDocument(...))
TransferClient.endpoint_manager_task_list()now supportsfilter_endpoint_useas a parameter. (:pr:`948`)FlowsClient.create_flownow supportssubscription_idas a parameter. (:pr:`949`)
- Added a
session_required_mfaparameter to theAuthorizationParameterInfoerror info object andoauth2_get_authorize_urlmethod (:pr:`939`)
- The argument specification for
AuthClient.create_policywas incorrect. The corrected method will emit deprecation warnings if called with positional arguments, as the corrected version uses keyword-only arguments. (:pr:`936`)
TransferClient.operation_symlinkis now officially deprecated and will emit aRemovedInV4Warningif used. (:pr:`942`)
- Included documentation in
AuthorizationParameterInfoforsession_required_policies(:pr:`939`)
- Add the
delete_protectedfield toMappedCollectionDocument. (:pr:`920`)
- Minor improvements to handling of paths and URLs. (:pr:`922`)
- Request paths which start with the
base_pathof a client are now normalized to avoid duplicating thebase_path. - When a
GCSClientis initialized with an HTTPS URL, if the URL does not end with the/apisuffix, that suffix will automatically be appended. This allows thegcs_manager_urlfield from Globus Transfer to be used verbatim as the address for aGCSClient.
- Request paths which start with the
NativeAppAuthClient.oauth2_validate_tokenandConfidentialAppAuthClient.oauth2_validate_tokenhave been deprecated, as their usage is discouraged by the Auth service. (:pr:`921`)
- Migrate from a CHANGELOG symlink to the RST
.. includedirective. (:pr:`918`) - Tutorial endpoint references are removed from tests and replaced with bogus values. (:pr:`919`)
- Remove references to the Tutorial Endpoints from documentation. (:pr:`915`)
Support custom CA certificate bundles. (:pr:`903`)
Previously, SSL/TLS verification allowed only a boolean
TrueorFalsevalue. It is now possible to specify a CA certificate bundle file using the existingverify_sslparameter orGLOBUS_SDK_VERIFY_SSLenvironment variable.This may be useful for interacting with Globus through certain proxy firewalls.
- Fix the type annotation for
globus_sdk.IdentityMapinit, which incorrectly rejectedConfidentialAppAuthClient. (:pr:`912`)
Note
These changes pertain to methods of the client objects in the SDK which interact with Globus Auth client registration. To disambiguate, we refer to the Globus Auth entities below as "Globus Auth clients" or specify "in Globus Auth", as appropriate.
- Globus Auth clients objects now have methods for interacting with client and
project APIs. (:pr:`884`)
NativeAppAuthClient.create_native_app_instancecreates a new native app instance in Globus Auth for a client.ConfidentialAppAuthClient.create_child_clientcreates a child client in Globus Auth for a confidential app.AuthClient.get_projectlooks up a project.AuthClient.get_policylooks up a policy document.AuthClient.get_policieslists all policies in all projects for which the current user is an admin.AuthClient.create_policycreates a new policy.AuthClient.update_policyupdates an existing policy.AuthClient.delete_policydeletes a policy.AuthClient.get_clientlooks up a Globus Auth client by ID or FQDN.AuthClient.get_clientslists all Globus Auth clients for which the current user is an admin.AuthClient.create_clientcreates a new client in Globus Auth.AuthClient.update_clientupdates an existing client in Globus Auth.AuthClient.delete_clientdeletes a client in Globus Auth.AuthClient.get_client_credentialslists all client credentials for a given Globus Auth client.AuthClient.create_client_credentialcreates a new client credential for a given Globus Auth client.AuthClient.delete_client_credentialdeletes a client credential.AuthClient.get_scopelooks up a scope.AuthClient.get_scopeslists all scopes in all projects for which the current user is an admin.AuthClient.create_scopecreates a new scope.AuthClient.update_scopeupdates an existing scope.AuthClient.delete_scopedeletes a scope.
- A helper object has been defined for dependent scope manipulation via the
scopes APIs,
globus_sdk.DependentScopeSpec(:pr:`884`)
- When serializing
TransferTimerdata, do not convert to UTC if the input was a valid datetime with an offset. (:pr:`900`)
- Add support for the new Transfer Timer creation method, in the form of a
client method,
TimerClient.create_timer, and a payload builder type,TransferTimer(:pr:`887`)create_timeronly supports dict data andTransferTimer, not the previousTimerJobtype- Additional helper classes,
RecurringTimerScheduleandOneceTimerSchedule, are provided to help build theTransferTimerpayload
- Request encoding in the SDK will now automatically convert any
uuid.UUIDobjects into strings. Previously this was functionality provided by certain methods, but now it is universal. (:pr:`892`)
- Creation of timers to run transfers using
TimerJobis now deprecated (:pr:`887`)
TransferClient.operation_lsnow supports thelimitandoffsetparameters (:pr:`868`)- A new sentinel value,
globus_sdk.MISSING, has been introduced. It is used for method calls which need to distinguish missing parameters from an explicitNoneused to signifynull(:pr:`885`)globus_sdk.MISSINGis now supported in payload data for all methods, and will be automatically removed from the payload before sending to the server
GroupPoliciesobjects now treat an explicit instantiation withhigh_assurance_timeout=Noneas setting the timeout tonull(:pr:`885`)
- The inheritance structure used for Globus Auth client classes has changed.
(:pr:`849`)
- A new class,
AuthLoginClient, is the base forNativeAppAuthClientandConfidentialAppAuthClient. These classes no longer inherit fromAuthClient, and therefore no longer inherit certain methods which would never succeed if called. AuthClientis now the only class which provides functionality for accessing Globus Auth APIs.AuthClientno longer includes methods for OAuth 2 login flows which would only be valid to call onAuthLoginClientsubclasses.
- A new class,
- Several features of Auth client classes are now deprecated. (:pr:`849`)
- Setting
AuthClient.client_idor accessing it as an attribute is deprecated and will emit a warning. ConfidentialAppAuthClient.get_identitieshas been preserved as a valid call, but will emit a warning. Users wishing to access this API via client credentials should prefer to get an access token using a client credential callout, and then use that token to callAuthClient.get_identities().
- Setting
- The
AuthClient.oauth2_userinfomethod has been deprecated in favor ofAuthClient.userinfo. Callers should prefer the new method name. (:pr:`865`)
- Add support for Python 3.12. (:pr:`808`)
Add a
promptkeyword parameter toAuthClient.oauth2_get_authorize_url(). (:pr:`813`)Setting this parameter requires users to authenticate with an identity provider, even if they are already logged in. Doing so can help avoid errors caused by unexpected session required policies, which would otherwise require a second, follow-up login flow.
promptcould previously only be set via thequery_paramskeyword parameter. It is now more discoverable.Add
TimerClient.pause_jobandTimerClient.resume_jobfor pausing and resuming timers. (:pr:`827`)
- Add an example script which handles creating and running a flow. (:pr:`826`)
- Added responses to
_testingreflecting an inactive Timers job (:pr:`828`)
- Add a
FlowsClient.get_run_definition()method. (:pr:`799`)
FlowsClient.get_run_logs()now uses anIterableRunLogsResponse. (:pr:`797`)
- New components are introduced to the experimental subpackage. See the SDK
Experimental documentation for more details.
- Add tools which manipulate Globus Auth Requirements error data.
globus_sdk.experimental.auth_requirements_errorprovides a data container class,GlobusAuthRequirementsError, and functions for converting and validating data against this shape. (:pr:`768`) - Introduce an experimental Globus Auth scope parser in
globus_sdk.experimental.scope_parser(:pr:`752`)
- Add tools which manipulate Globus Auth Requirements error data.
- The
scopesclass attribute ofSpecificFlowClientis now specialized to ensure that type checkers will allow access toSpecificFlowClientscopes andresource_servervalues withoutcasting. The value used is a specialized stub which raises useful errors when class-based access is performed. Thescopesinstance attribute is unchanged. (:pr:`793`)
- The
jwt_paramsargument todecode_id_token()now allows"leeway"to be included to pass aleewayparameter to pyjwt. (:pr:`790`)
decode_id_token()defaulted to having no tolerance for clock drift. Slight clock drift could lead to JWT claim validation errors. The new default is 0.5s which should be sufficient for most cases. (:pr:`790`)
- New scripts in the example gallery demonstrate usage of the Globus Auth Developer APIs to List, Create, Delete, and Update Projects. (:pr:`777`)
- Add
FlowsClient.list_runsas a method for listing all runs for the current user, with support for pagination. (:pr:`782`) - Add
SearchClientmethods for managing search index lifecycle:create_index,delete_index, andreopen_index(:pr:`785`)
- The enforcement logic for URLs in
BaseClientinstantiation has been improved to only require thatservice_namebe set ifbase_urlis not provided. (:pr:`786`)- This change primarily impacts subclasses, which no longer need to set the
service_nameclass variable if they ensure that thebase_urlis always passed with a non-null value. - Direct instantiation of
BaseClientis now possible, although not recommended for most use-cases.
- This change primarily impacts subclasses, which no longer need to set the
- Add
AuthClientmethods to support the Projects APIs for listing, creating, updating, and deleting projects. globus_sdk._testingnow exposes a method,construct_errorwhich makes it simpler to explicitly construct and return a Globus SDK error object for testing. This is used in the SDK's own testsuite and is available for_testingusers. (:pr:`770`)AuthClient.oauth2_get_authorize_urlnow supports the following parameters for session management:session_required_identities,session_required_single_domain, andsession_required_policies. Each of these accept list inputs, as returned byErrorInfo.authorization_parameters. (:pr:`773`)
AuthClient,NativeAppAuthClient, andConfidentialAppAuthClienthave had their init signatures updated to explicitly list available parameters. (:pr:`764`)- Type annotations for these classes are now more accurate
- The
NativeAppAuthClientandConfidentialAppAuthClientclasses do not acceptauthorizerin their init signatures. Previously this was accepted but raised aGlobusSDKUsageError. Attempting to pass anauthorizerwill now result in aTypeError.
session_required_policiesparsing inAuthorizationParameterInfonow supports the policies being returned as alist[str]in addition to supportingstr(:pr:`769`)
AuthorizationParameterInfois now more type-safe, and will not return parsed data from a response without checking that the data has correct types (:pr:`769`)- Adjust the
FlowsClient.get_run()include_flow_descriptionparameter so it is submitted only when it has a value. (:pr:`778`)
- The
_testingdocumentation has been expanded with a dropdown view of the response contents for each method. In support of this, client method testing docs have been reorganized into a page per service. (:pr:`767`)
- Add support for
AuthClient.get_identity_providersfor looking up Identity Providers by domain or ID in Globus Auth (:pr:`757`) - Add a method to the Globus Search client,
SearchClient.batch_delete_by_subject(:pr:`760`) - Add
AuthScopes.manage_projectsto scope data. This is also accessible asAuthClient.scopes.manage_projects(:pr:`761`)
- Alpha features of globus-sdk are now documented in the "Unstable" doc section (:pr:`753`)
AuthAPIErrorwill now parse a uniqueidfound in the error subdocuments as therequest_idattribute (:pr:`749`)- Add a
FlowsClient.update_run()method. (:pr:`744`) - Add a
FlowsClient.delete_run()method. (:pr:`747`) - Add a
FlowsClient.cancel_run()method. (:pr:`747`) - Add an
experimentalsubpackage. (:pr:`751`)
- Fix
TransferClient.operation_mkdirandTransferClient.operation_renameto no longer send nulllocal_userby default (:pr:`741`)
- Implemented
FlowsClient.get_run(...)(:pr:`721`) - Implemented
FlowsClient.get_run_logs(...)(:pr:`722`) - Implemented
SpecificFlowClient.resume_run(...)(:pr:`723`) ConsentRequiredInfonow acceptsrequired_scope(singular) containing a single string as an alternative torequired_scopes. However, it will parse both formats into arequired_scopeslist. (:pr:`726`)FlowsClient.list_flowsnow supports passing a non-string iterable of strings toorderbyin order to indicate multiple orderings (:pr:`730`)- Support
pathlib.Pathobjects as filenames for the JSON and sqlite token storage adapters. (:pr:`734`) - Several
TransferClientmethods,TransferData, andDeleteDatanow support thelocal_user,source_local_user, anddestination_local_userparameters (:pr:`736`)
- Behavior has changed slightly specifically for
TimerAPIError. When parsing fails, thecodewill beErrorand themessageswill be empty. Thedetailfield will be treated as theerrorsarray for these errors when it is present and contains an array of objects. - Error parsing in the SDK has been enhanced to better support JSON:API and
related error formats with multiple sub-errors. Several attributes are
added or changed. For most SDK users, the changes will be completely
transparent or a minor improvement. (:pr:`725`)
- Error parsing now attempts to detect the format of the error data and will parse JSON:API data differently from non-JSON:API data. Furthermore, parsing is stricter about the expectations about fields and their types. JSON:API parsing now has its own distinct parsing path, followed only when the JSON:API mimetype is present.
- A new attribute is added to API error objects,
errors. This is a list of subdocuments parsed from the error data, especially relevant for JSON:API errors and similar formats. See the :ref:`ErrorSubdocument documentation <error_subdocuments>` for details. - A new attribute is now present on API error objects,
messages. This is a list of messages parsed from the error data, for errors with multiple messages. When there is only one message,messageswill only contain one item. - The
messagefield is now an alias for a joined string ofmessages. Assigning a string tomessageis supported for error subclasses, but is deprecated. messagewill now beNonewhen no messages can be parsed from the error data. Previously, the default formessagewould be an alias fortext.- All error types now support
request_idas an attribute, but it will default toNonefor errors which do not include arequest_id. - An additional field is checked by default for error message data,
title. This is useful when errors containtitlebut nodetailfield. The extraction of messages from errors has been made stricter, especially in the JSON:API case. - The
codefield of errors will no longer attempt to parse only the firstcodefrom multiple sub-errors. Instead,codewill first parse a top-levelcodefield, and then fallback to checking if all sub-errors have the samecodevalue. The result is that certain errors which would populate a non-defaultcodevalue no longer will, but thecodewill also no longer be misleading when multiple errors with different codes are present in an error object. - The
codefield of an error may now beNone. This is specifically possible when the error format is detected to be known as JSON:API and there is nocodepresent in any responses.
- The TransferRequestsTransport will no longer automatically retry errors with a code of EndpointError
- Fix pagination on iterable gcs client routes (:pr:`738`, :pr:`739`)
GCSClient.get_storage_gateway_listGCSClient.get_role_listGCSClient.get_collection_listGCSClient.get_user_credential_list
- Added
FlowsClient.update_flow(...)(:pr:`710`) - Support passing "include" as a transfer
filter_rulemethod (:pr:`712`) - Make the request-like interface for response objects and errors more uniform. (:pr:`715`)
- Both
GlobusHTTPResponseandGlobusAPIErrorare updated to ensure that they have the following properties in common:http_status,http_reason,headers,content_type,text GlobusHTTPResponseandGlobusAPIErrorhave both gained a new property,binary_content, which returns the unencoded response data as bytes
- Both
GlobusAPIError.raw_textis deprecated in favor oftext
- The return type of
AuthClient.get_identitiesis now correctly annotated as an iterable type,globus_sdk.GetIdentitiesResponse(:pr:`716`)
- Documentation for client methods has been improved to more consistently format and display examples and other information (:pr:`714`)
ConfidentialAppAuthClient.oauth2_get_dependent_tokensnow supports therefresh_tokensparameter to enable requests for dependent refresh tokens (:pr:`698`)
- Behaviors which will change in version 4.0.0 of the
globus-sdknow emit deprecation warnings. TransferData.add_itemnow defaults to omittingrecursiverather than setting its value toFalse. This change better matches new Transfer API behaviors which treat the absence of therecursiveflag as meaning autodetect, rather than the previous default ofFalse. Setting the recursive flag can still have beneficial behaviors, but should not be necessary for many use-cases (:pr:`696`)
- Omitting
requested_scopesor specifying it asNoneis now deprecated and will emit a warning. In version 4, users will always be required to specify their scopes when performing login flows. This applies to the following methods:ConfidentialAppAuthClient.oauth2_client_credentials_tokensAuthClient.oauth2_start_flow
SearchClient.update_entryandSearchClient.create_entryare officially deprecated and will emit a warning. These APIs are aliases ofSearchClient.ingest, but their existence has caused confusion. Users are encouraged to switch toSearchClient.ingestinstead (:pr:`695`)
- When users input empty
requested_scopesvalues, these are now rejected with a usage error instead of being translated into the default set ofrequested_scopes - Fix the type annotation for
max_sleepon client transports to allowfloatvalues (:pr:`697`)
- Remove support for python3.6 (:pr:`681`)
MutableScopeobjects can now be used in theoauth2_start_flowandoauth2_client_credentials_tokensmethods ofAuthClientclasses as part ofrequested_scopes(:pr:`689`)
- Make
MutableScope.scope_stringa public instance attribute (was_scope_string) (:pr:`687`) - Globus Groups methods which required enums as arguments now also accept
a variety of
Literalstrings in their annotations as well. This is coupled with changes to ensure that strings and enums are always serialized correctly in these cases. (:pr:`691`)
- Fix a typo in
TransferClient.endpoint_manager_task_successful_transferswhich prevented calls from being made correctly (:pr:`683`)
- Allow UUID values for the
client_idparameter toAuthClientand its subclasses (:pr:`676`)
- Improved GCS Collection datatype detection to support
collection#1.6.0andcollection#1.7.0documents (:pr:`675`)guest_auth_policy_idis now supported onMappedCollectionDcoumentuser_messagestrings over 64 characters are now supported
- The
session_required_policiesattribute ofAuthorizationInfois now parsed as a list of strings when present, andNonewhen absent. (:pr:`678`) globus_sdk.ArrayResponseandglobus_sdk.IterableResponseare now available as names. Previously, these were only importable fromglobus_sdk.response(:pr:`680`)
ArrayResponseandIterableResponsehave better error behaviors when the API data does not match their expected types (:pr:`680`)
- Fix the Timer code example (:pr:`672`)
- New documentation examples for Transfer Task submission in the presence of
ConsentRequirederrors (:pr:`673`)
- AuthorizationParameterInfo now exposes session_required_policies (:pr:`658`)
- Fix a bug where
TransferClient.endpoint_manager_task_listdidn't handle thelast_keyargument when paginated (:pr:`662`)
- Scope Names can be set explicitly in a
ScopeBuilder(:pr:`641`) - Introduced
ScopeBuilder.scope_namesproperty (:pr:`641`) - Add support for
interpret_globsandignore_missingtoDeleteData(:pr:`646`) - A new object,
globus_sdk.LocalGlobusConnectServercan be used to inspect the local installation of Globus Connect Server (:pr:`647`)- The object supports properties for
endpoint_idanddomain_name - This only supports Globus Connect Server version 5
- The object supports properties for
- The filter argument to TransferClient.operation_ls now accepts a list to pass multiple filter params (:pr:`652`)
- Improvements to
MutableScopeobjects (:pr:`654`)MutableScope(...).serialize()is added, andstr(MutableScope(...))uses itMutableScope.add_dependencynow supportsMutableScopeobjects as inputsScopeBuilder.make_mutablenow accepts a keyword argumentoptional. This allows, for example,TransferScopes.make_mutable("all", optional=True)
- Improve the
__str__implementation forOAuthTokenResponse(:pr:`640`) - When
GlobusHTTPResponsecontains a list, calls toget()will no longer fail with anAttributeErrorbut will return the default value (Noneif unspecified) instead (:pr:`644`)
- The
optionalargument toadd_dependencyis deprecated.MutableScope(...).add_dependency(MutableScope("foo", optional=True))can be used to add an optional dependency
- Fixed SpecificFlowClient scope string (:pr:`641`)
- Fix a bug in the type annotations for transport objects which restricted the size of status code tuples set as classvars (:pr:`651`)
- Python 3.11 is now officially supported (:pr:`628`)
- Add support for
FlowsClient.get_flowandFlowsClient.delete_flow(:pr:`631`, :pr:`626`) - Add a
close()method toSQLiteAdapterwhich closes the underlying connection (:pr:`628`)
- Add
connect_paramstoSQLiteAdapter, enabling customization of the sqlite connection (:pr:`613`) - Add
FlowsClient.create_flow(...)(:pr:`614`) - Add
globus_sdk.SpecificFlowClientto manage interactions performed against a specific flow (:pr:`616`) - Add support to
FlowsClient.list_flowsfor pagination and theorderbyparameter (:pr:`621`, :pr:`622`)
- Fix rst formatting for a few nested bullet points in existing changelog (:pr:`619`)
- Add Mapped Collection policy helper types for constructing
policiesdata. (:pr:`607`) The following new types are introduced:CollectionPolicies(the base class for these types)POSIXCollectionPoliciesPOSIXStagingCollectionPoliciesGoogleCloudStorageCollectionPolicies
- Fix bug where
UserCredentialpolicies were being converted to a string (:pr:`608`) - Corrected the Flows service
resource_serverstring toflows.globus.org(:pr:`612`)
- Implement
__dir__for the lazy importer inglobus_sdk. This enables tab completion in the interpreter and other features with rely upondir(globus_sdk)(:pr:`603`) - Add an initial Globus Flows client class,
globus_sdk.FlowsClient(:pr:`604`)globus_sdk.FlowsAPIErroris the error class for this clientFlowsClient.list_flowsis implemented as a method for listing deployed flows, with some of the filtering parameters of this API supported as keyword arguments- The scopes for the Globus Flows API can be accessed via
globus_sdk.scopes.FlowsScopesorglobus_sdk.FlowsClient.scopes
- Adjust behaviors of
TransferDataandTimerJobto makeTimerJob.from_transfer_datawork and to defer requesting thesubmission_iduntil the task submission call (:pr:`602`)TransferDataavoids passingnullfor several values when they are omitted, ranging from optional parameters toadd_itemtoskip_activation_checkTransferDataandDeleteDatanow support usage in which thetransfer_clientparameters isNone. In these cases, ifsubmission_idis omitted, it will be omitted from the document, allowing the creation of a partial task submsision document with nosubmission_idTimerJob.from_transfer_datawill now raise aValueErrorif the input document containssubmission_idorskip_activation_checkTransferClient.submit_transferandTransferClient.submit_deletenow check to see if the data being sent contains asubmission_id. If it does not,get_submission_idis called automatically and set as thesubmission_idon the payload. The newsubmission_idis set on the object passed to these methods, meaning that these methods are now side-effecting.
The newly recommended usage for TransferData and DeleteData is to pass
the endpoints as named parameters:
# -- for TransferData --
# old usage
transfer_client = TransferClient()
transfer_data = TransferData(transfer_client, ep1, ep2)
# new (recommended) usage
transfer_data = TransferData(source_endpoint=ep1, destination_endpoint=ep2)
# -- for DeleteData --
# old usage
transfer_client = TransferClient()
delete_data = TransferData(transfer_client, ep)
# new (recommended) usage
delete_data = DeleteData(endpoint=ep)- Use
setattrin the lazy-importer. This makes attribute access after imports faster by several orders of magnitude. (:pr:`591`)
- Add guest collection example script to docs (:pr:`590`)
- Remove nonexistent
monitor_ongoingscope fromTransferScopes(:pr:`583`)
- Add User Credential methods to
GCSClient(:pr:`582`)get_user_credential_listget_user_credentialcreate_user_credentialupdate_user_credentialdelete_user_credential
- Add
connector_id_to_namehelper toGCSClientto resolve GCS Connector UUIDs to human readable Connector display names (:pr:`582`)
- Add helper objects and methods for interacting with Globus Connect Server
Storage Gateways (:pr:`554`)
- New methods on
GCSClient:create_storage_gateway,get_storage_gateway,get_storage_gateway_list,update_storage_gateway,delete_storage_gateway - New helper classes for constructing storage gateway documents.
StorageGatewayDocumentis the main one, but alsoPOSIXStoragePoliciesandPOSIXStagingStoragePoliciesare added for declaring the storage gatewaypoliciesfield. More policy helpers will be added in future versions.
- New methods on
- Add support for more
StorageGatewayPoliciesdocuments. (:pr:`562`) The following types are now available:BlackPearlStoragePoliciesBoxStoragePoliciesCephStoragePoliciesGoogleDriveStoragePoliciesGoogleCloudStoragePoliciesOneDriveStoragePoliciesAzureBlobStoragePoliciesS3StoragePoliciesActiveScaleStoragePoliciesIrodsStoragePoliciesHPSSStoragePolicies
- Add
httpsscope toGCSCollectionScopeBuilder(:pr:`563`) ScopeBuilderobjects now implement__str__for easy viewing. For example,print(globus_sdk.TransferClient.scopes)(:pr:`568`)- Several improvements to Transfer helper objects (:pr:`573`)
- Add
TransferData.add_filter_rulefor adding filter rules (exclude rules) to transfers - Add
skip_activation_checkas an argument toDeleteDataandTransferData - The
sync_levelargument toTransferDatais now annotated more accurately to reject bad strings
- Add
- Update the fields used to extract
AuthAPIErrormessages (:pr:`566`) - Imports from
globus_sdkare now evaluated lazily via module-level__getattr__on python 3.7+ (:pr:`571`)- This improves the performance of imports for almost all use-cases, in some cases by over 80%
- The method
globus_sdk._force_eager_imports()can be used to force non-lazy imports, for latency sensitive applications which wish to control when the time cost of import evaluation is paid. This method is private and is therefore is not covered under theglobus-sdk's SemVer guarantees, but it is expected to remain stable for the foreseeable future.
- Improve handling of array-style API responses (:pr:`575`)
- Response objects now define
__bool__asbool(data). This means thatbool(response)could beFalseif the data is{},[],0, or other falsey-types. Previously,__bool__was not defined, meaning it was alwaysTrue globus_sdk.response.ArrayResponseis a new class which describes responses which are expected to hold a top-level array. It satisfies the sequence protocol, allowing indexing with integers and slices, iteration over the array data, and length checking withlen(response)globus_sdk.GroupsClient.get_my_groupsreturns anArrayResponse, meaning the response data can now be iterated and otherwise used
- Response objects now define
- Several changes expose more details of HTTP requests (:pr:`551`)
GlobusAPIErrorhas a new propertyheaderswhich provides the case-insensitive mapping of header values from the responseGlobusAPIErrorandGlobusHTTPResponsenow includehttp_reason, a string property containing the "reason" from the responseBaseClient.requestandRequestsTransport.requestnow have options for setting boolean optionsallow_redirectsandstream, controlling how requests are processed
- New tools for working with optional and dependent scope strings (:pr:`553`)
- A new class is provided for constructing optional and dependent scope
strings,
MutableScope. Import as infrom globus_sdk.scopes import MutableScope ScopeBuilderobjects provide a method,make_mutable, which converts from a scope name to aMutableScopeobject. See documentation on scopes for usage details
- A new class is provided for constructing optional and dependent scope
strings,
- Add a client for the Timer service (:pr:`548`)
- Add
TimerClientclass, along withTimerJobfor constructing data to pass to the Timer service for job creation, andTimerAPIError - Modify
globus_sdk.configutilities to provide URLs for Actions and Timer services
- Add
- Fix annotations to allow request data to be a string. This is supported at runtime but was missing from annotations. (:pr:`549`)
ScopeBuilderobjects now supportknown_url_scopes, and known scope arguments to aScopeBuildermay now be of typestrin addition tolist[str](:pr:`536`)- Add the
RequestsTransport.tunecontextmanager to the transport layer, allowing the settings on the transport to be set temporarily (:pr:`540`)
globus_sdk.IdentityMapcan now take a cache as an input. This allows multipleIdentityMapinstances to share the same storage cache. Any mutable mapping type is valid, so the cache can be backed by a database or other storage (:pr:`500`)- Add support for
includeas a parameter toGroupsClient.get_group.includecan be a string or iterable of strings (:pr:`528`) - Add a new method to tokenstorage,
SQLiteAdapter.iter_namespaces, which iterates over all namespaces visible in the token database (:pr:`529`)
- Add
TransferRequestsTransportclass that does not retry ExternalErrors. This fixes cases in which theTransferClientincorrectly retried requests (:pr:`522`) - Use the "reason phrase" as a failover for stringified API errors with no body (:pr:`524`)
- Enhance documentation for all of the parameters on methods of
GroupsClient
- Fix the pagination behavior for
TransferClientontask_skipped_errorsandtask_successful_transfers, and apply the same fix to the endpoint manager variants of these methods. Prior to the fix, paginated calls would return a single page of results and then stop (:pr:`520`)
- The
typing_extensionsrequirement in package metadata now sets a lower bound of4.0, to force upgrades of installations to get a new enough version (:pr:`518`)
- Support pagination on
SearchClient.post_search(:pr:`507`) - Add support for scroll queries to
SearchClient.SearchClient.scrollandSearchClient.paginated.scrollare now available as methods, and a new helper class,SearchScrollQuery, can be used to easily construct scrolling queries. (:pr:`507`) - Add methods to
SearchClientfor managing index roles.create_role,delete_role, andget_role_list(:pr:`507`) - Add
mapped_collectionandfilterquery arguments toGCSClient.get_collection_list(:pr:`510`) - Add role methods to
GCSClient(:pr:`513`)GCSClient.get_role_listlists endpoint or collection rolesGCSClient.create_rolecreates a roleGCSClient.get_rolegets a single roleGCSClient.delete_roledeletes a role
- The response from
AuthClient.get_identitiesnow supports iteration, returning results from the"identities"array (:pr:`514`)
- Packaging bugfix.
globus-sdkis now built with pypa'sbuildtool, to resolve issues with wheel builds.
- Add
update_groupmethod toGroupsClient(:pr:`506`) - The
TransferDataandDeleteDatahelper objects now accept the following parameters:notify_on_succeeded,notify_on_failed, andnotify_on_inactive. All three are boolean parameters with a default ofTrue. (:pr:`502`) - Add
Paginator.wrapas a method for getting a paginated methods. This interface is more verbose than the existingpaginatedmethods, but correctly preserves type annotations. It is therefore preferable for users who are usingmypyto do type checking. (:pr:`494`)
Paginatorobjects are now generics over a type var for their page type. The page type is bounded byGlobusHTTPResponse, and most type-checker behaviors will remain unchanged (:pr:`495`)
- Several minor bugs have been found and fixed (:pr:`504`)
- Exceptions raised in the SDK always use
raise ... fromsyntax where appropriate. This corrects exception chaining in the local endpoint and several response objects. - The encoding of files opened by the SDK is now always
UTF-8 TransferDatawill now reject unsupportedsync_levelvalues with aValueErroron initialization, rather than erroring at submission time. Thesync_levelhas also had its type annotation fixed to allow forintvalues.- Several instances of undocumented parameters have been discovered, and these are now rectified.
- Exceptions raised in the SDK always use
- Document
globus_sdk.config.get_service_urlandglobus_sdk.config.get_webapp_url(:pr:`496`)- Internally, these are updated to be able to default to the
GLOBUS_SDK_ENVIRONMENTsetting, so specifying an environment is no longer required
- Internally, these are updated to be able to default to the
- Update to avoid deprecation warnings on python 3.10 (:pr:`499`)
- Add
iter_itemsas a method onTransferDataandDeleteData(:pr:`488`) - Add the
resource_serverproperty to client classes and objects. For example,TransferClient.resource_serverandGroupsClient().resource_serverare now usable to get the resource server string for the relevant services.resource_serveris documented as part ofglobus_sdk.BaseClientand may beNone. (:pr:`489`) - The implementation of several properties of
GlobusHTTPResponsehas changed (:pr:`497`)- Responses have a new property,
headers, a case-insensitive dict of headers from the response - Responses now implement
http_statusandcontent_typeas properties without setters
- Responses have a new property,
- ClientCredentialsAuthorizer now accepts
Union[str, Iterable[str]]as the type for scopes (:pr:`498`)
- Fix type annotations on client methods with paginated variants (:pr:`491`)
- Add
filteras a supported parameter toTransferClient.task_list(:pr:`484`) - The
filterparameter toTransferClient.task_listandTransferClient.operation_lscan now be passed as aDict[str, str | List[str]]. Documentation on theTransferClientexplains how this will be formatted, and is linked from the param docs forfilteron each method (:pr:`484`)
- Adjust package metadata for
cryptographydependency, specifyingcryptography>=3.3.1and no upper bound. This is meant to help mitigate issues in which an oldercryptographyversion is installed gets used in spite of it being incompatible withpyjwt[crypto]>=2.0(:pr:`486`)
- Fix several internal decorators which were destroying type information about decorated functions. Type signatures of many methods are therefore corrected (:pr:`485`)
- Produce more debug logging when SDK logs are enabled (:pr:`480`)
- Update the minimum dependency versions to lower bounds which are verified to work with the testsuite (:pr:`482`)
ScopeBuilderobjects now define the type of__getattr__formypyto know that dynamic attributes are strings (:pr:`472`)
- Fix malformed PEP508
python_versionbound in dev dependencies (:pr:`474`)
- Fix remaining
type: ignoreusages in globus-sdk (:pr:`473`)
- Remove support for
bytesvalues for fields consuming UUIDs (:pr:`471`)
- Add
filter_is_errorparameter to advanced task list (:pr:`467`) - Add a
LocalGlobusConnectPersonal.get_owner_info()for looking up local user information from gridmap (:pr:`466`) - Add support for GCS collection create and update. This includes new data
helpers,
MappedCollectionDcoumentandGuestCollectionDocument(:pr:`468`) - Add support for specifying
config_dirtoLocalGlobusConnectPersonal(:pr:`470`)
- Remove
BaseClient.qjoin_path(:pr:`452`)
- Add a new
GCSClientclass for interacting with GCS Manager APIs (:pr:`447`) GCSClientsupportsget_collectionanddelete_collection.get_collectionuses a newUnpackingGCSResponseresponse type (:pr:`451`, :pr:`464`)- Add
delete_destination_extraparam toTransferData(:pr:`456`) TransferClient.endpoint_manager_task_listnow takes filters as named keyword arguments, not only inquery_params(:pr:`460`)
- Rename
GCSScopeBuildertoGCSCollectionScopeBuilderand addGCSEndpointScopeBuilder. TheGCSClientincludes helpers for instantiating these scope builders (:pr:`448`) - The
additional_paramsparameter toAuthClient.oauth2_get_authorize_urlhas been renamed toquery_paramsfor consistency with other methods (:pr:`453`) - Enforce keyword-only arguments for most SDK-provided APIs (:pr:`453`)
- All type annotations for
Sequencewhich could be relaxed toIterablehave been updated (:pr:`465`)
- Minor fix to wheel builds: do not declare wheels as universal (:pr:`444`)
- Fix annotations for
server_idonTransferClientmethods (:pr:`455`) - Fix
visibilitytypo inGroupsClient(:pr:`463`)
- Ensure all
TransferClientmethod parameters are documented (:pr:`449`, :pr:`454`, :pr:`457`, :pr:`458`, :pr:`459`, :pr:`461`, :pr:`462`)
- Flesh out the
GroupsClientand add helpers for interacting with the Globus Groups service, including enumerated constants, payload builders, and a high-level client for doing non-batch operations called theGroupsManager(:pr:`435`, :pr:`443`) - globus-sdk now provides much more complete type annotations coverage,
allowing type checkers like
mypyto catch a much wider range of usage errors (:pr:`442`)
- Add scope constants and scope construction helpers. See new documentation on :ref:`scopes and ScopeBuilders <scopes>` for details (:pr:`437`, :pr:`440`)
- API Errors now have an attached
infoobject with parsed error data where applicable. See the :ref:`ErrorInfo documentation <error_info>` for details (:pr:`441`)
- Improve the rendering of API exceptions in stack traces to include the method, URI, and authorization scheme (if recognized) (:pr:`439`)
- Payload helper objects (
TransferData,DeleteData, andSearchQuery) now inherit from a custom object, notdict, but they are still dict-like in behavior (:pr:`438`)
- Add support for
TransferClient.get_shared_endpoint_list(:pr:`434`)
- Passthrough parameters to SDK methods for query params and body params are no
longer accepted as extra keyword arguments. Instead, they must be passed
explicitly in a
query_params,body_params, oradditional_fieldsdictionary, depending on the context (:pr:`433`) - The interface for retry parameters has been simplified.
RetryPolicyobjects have been merged into the transport object, and retry parameters likemax_retriesmay now be supplied directly astransport_params(:pr:`430`)
- Add
BaseClientto the top-level exports ofglobus_sdk, so it can now be accessed under the nameglobus_sdk.BaseClient
- Fix several paginators which were broken in
3.0.0a3(:pr:`431`)
- Autodocumentation of paginated methods (:pr:`432`)
- Pagination has changed significantly. (:pr:`418`)
- Methods which support pagination like
TransferClient.endpoint_searchno longer return an iterablePaginatedResourcetype. Instead, these client methods returnGlobusHTTPResponseobjects with a single page of results. - Paginated variants of these methods are available by renaming a call from
client.<method>toclient.paginated.<method>. So, for example, aTransferClientnow supportsclient.paginated.endpoint_search(). The arguments to this function are the same as the original method. client.paginated.<method>calls returnPaginatorobjects, which support two types of iteration: bypages()and byitems(). To replicate the same behavior as SDK v1.x and v2.xPaginatedResourcetypes, useitems(), as inclient.paginated.endpoint_search("query").items()
- Methods which support pagination like
- A new subpackage is available for public use,
globus_sdk.tokenstorage(:pr:`405`) - Add client for Globus Groups API,
globus_sdk.GroupsClient. Includes a dedicated error class,globus_sdk.GroupsAPIError
- Refactor response classes (:pr:`425`)
- Remove
allowed_authorizer_typesrestriction fromBaseClient(:pr:`407`) - Remove
auth_client=...parameter toOAuthTokenResponse.decode_id_token(:pr:`400`)
globus-sdknow provides PEP561 typing data (:pr:`420`)OAuthTokenResponse.decode_id_tokencan now be provided a JWK and openid configuration as parameters.AuthClientimplements methods for fetching these data, so that they can be fetched and stored outside of this call. There is no automatic caching of these data. (:pr:`403`)
- The interface for
GlobusAuthorizernow definesget_authorization_headerinstead ofset_authorization_header, and additional keyword arguments are not allowed (:pr:`422`) - New Transport layer handles HTTP details, variable payload encodings, and automatic request retries (:pr:`417`)
- Instead of
json_body=...andtext_body=..., usedata=...combined withencoding="json",encoding="form", orencoding="text"to format payload data.encoding="json"is the default whendatais a dict. - By default, requests are retried automatically on potentially transient
error codes (e.g.
http_status=500) and network errors with exponential backoff globus_sdk.BaseClientand its subclasses defineretry_policyandtransport_classclass attributes which can be used to customize the retry behavior used- The JWT dependency has been updated to
pyjwt>=2,<3(:pr:`416`) - The config files in
~/.globus.cfgand/etc/globus.cfgare no longer used. Configuration can now be done via environment variables (:pr:`409`) BaseClient.app_nameis a property with a custom setter, replacingset_app_name(:pr:`415`)
- Update documentation site style and layout (:pr:`423`)
Note
globus-sdk version 2.0.0 was yanked due to a release issue. Version 2.0.1 is the first 2.x version.
- Add support for task skipped errors via
TransferClient.task_skipped_errorsandTransferClient.endpoint_manager_task_skipped_errors(:pr:`393`)
- Add support for pyinstaller installation of globus-sdk (:pr:`387`)
- Fix
GlobusHTTPResponseto handle responses with noContent-Typeheader (:pr:`375`)
- Add
globus_sdk.IdentityMap, a mapping-like object for Auth ID lookups (:pr:`367`) - Add
external_checksumandchecksum_algorithmtoTransferData.add_item()named arguments (:pr:`365`)
- Don't append trailing slashes when no path is given to a low-level client method like
get()(:pr:`364`)
- Add a property to paginated results which shows if more results are available (:pr:`346`)
- Fix
RefreshTokenAuthorizerto handle a newrefresh_tokenbeing sent back by Auth (:pr:`359`) - Fix typo in endpoint_search log message (:pr:`355`)
- Fix Globus Web App activation links in docs (:pr:`356`)
- Update docs to state that Globus SDK uses semver (:pr:`357`)
- Allow arbitrary keyword args to
TransferData.add_item()andDeleteData.add_item(), which passthrough to the item bodies (:pr:`339`)
- Replace egg distribution format with wheels (:pr:`314`)
- Internal maintenance
- Officially add support for python 3.7 (:pr:`300`)
- RenewingAuthorizer and its subclasses now expose the check_expiration_time method (:pr:`309`)
- Allow parameters to be passed to customize the request body of ConfidentialAppAuthClient.oauth2_get_dependent_tokens (:pr:`308`)
- Add the patch() method to BaseClient and its subclasses, sending an HTTP PATCH request (:pr:`302`)
- Use sha256 hashes of tokens (instead of last 5 chars) in debug logging (:pr:`305`)
- Make pickling SDK objects safer (but still not officially supported!) (:pr:`284`)
- Malformed SDK usage may now raise GlobusSDKUsageError instead of ValueError. GlobusSDKUsageError inherits from ValueError (:pr:`281`)
- Correct handling of environment="production" as an argument to client construction (:pr:`307`)
- Add support for retrieving a local Globus Connect Personal endpoint's UUID (:pr:`276`)
- Fix bug in search client parameter handling (:pr:`274`)
- Support connection timeouts. Default timeout of 60 seconds (:pr:`264`)
- Send
Content-Type: application/jsonon requests with JSON request bodies (:pr:`266`)
- Access token response data by way of scope name (:pr:`261`)
- Add (beta) SearchClient class (:pr:`259`)
- Make
cryptographya strict requirement, globus-sdk[jwt] is no longer necessary (:pr:`257`, :pr:`260`) - Simplify OAuthTokenResponse.decode_id_token to not require the client as an argument (:pr:`255`)
- Improve error message when installation onto python2.6 is attempted (:pr:`245`)
- Raise errors on client instantiation when
GLOBUS_SDK_ENVIRONMENTappears to be invalid, supportGLOBUS_SDK_ENVIRONMENT=preview(:pr:`247`)
- Allow client classes to accept
base_urlas an argument to_init__()(:pr:`241`)
- Fix packaging to not include testsuite (:pr:`232`)
- Use PyJWT instead of python-jose for JWT support (:pr:`227`)
- Add Transfer symlink support (:pr:`218`)
- Doc Updates & Minor Improvements
- Use correct paging style when making
endpoint_manager_task_listcalls (:pr:`210`)
- Add python 3.6 to supported platforms (:pr:`180`)
- Add endpoint_manager methods to TransferClient (:pr:`191`, :pr:`199`, :pr:`200`, :pr:`201`, :pr:`203`)
- Support iterable requested_scopes everywhere (:pr:`185`)
- Change "identities_set" to "identity_set" for token introspection (:pr:`163`)
- Update dev status classifier to 5, prod (:pr:`178`)
- Numerous improvements to testsuite
- Adds
AuthAPIErrorwith more flexible error payload handling (:pr:`175`)
- Add
AuthClient.validate_token(:pr:`172`)
- Bugfix for
on_refreshusers ofRefreshTokenAuthorizerandClientCredentialsAuthorizer(:pr:`173`)
- Remove deprecated
oauth2_start_flow_*methods (:pr:`170`)
- Add the
ClientCredentialsAuthorizer(:pr:`164`) - Add
jwtextra install target.pip install "globus_sdk[jwt]"installspython-jose(:pr:`169`)
- Remove all properties of
OAuthTokenResponseother thanby_resource_server(:pr:`162`)
- Make
OAuthTokenResponse.decode_id_token()respectssl_verify=noconfiguration (:pr:`161`)
- Add
deadlinesupport toTransferDataandDeleteData(:pr:`159`)
- Opt out of the Globus Auth behavior where a
GETof an identity username will provision that identity (:pr:`145`) - Wrap some
requestsnetwork-related errors in custom exceptions (:pr:`155`)
- Fixup OAuth2 PKCE to be spec-compliant (:pr:`154`)
- Add support for the
prefill_named_grantoption to the Native App authorization flow (:pr:`143`)