Update Google Cloud credential loading
What changed, and why it matters
This commit changes how BTCPay Server loads Google Cloud service-account credentials. It switches from a general Google credential parser to a more specific service-account credential parser. The change is likely a hardening or compatibility fix, but the commit message gives no security context, so we cannot tell whether it fixes a known vulnerability or is just routine maintenance.
Treat as a low-priority maintenance/hardening patch. Review whether the previous `GoogleCredential.FromJson` behavior accepted credential types that should not have been allowed, and verify the new path handles all supported service-account JSON formats correctly. No urgent action is indicated by the diff alone.
Security signals we found
Credential parsing path changed
Narrowing of accepted credential types to ServiceAccountCredential
Potential hardening of Google Cloud authentication flow
Evidence from the diff
The diff replaces GoogleCredential.FromJson(configuration.JsonCredentials) with CredentialFactory.FromJson<ServiceAccountCredential>(configuration.JsonCredentials).ToGoogleCredential(). This narrows accepted credential types to service-account credentials and may avoid behavior of the broader GoogleCredential class (for example, accepting user credentials, compute credentials, or other credential forms). Without the vendor stating a security reason, this is best classified as a credential-loading hardening change with uncertain security relevance.
Changed components
BTCPayServer.Storage.Services.Providers.GoogleCloudStorage.GoogleCloudStorageFileProviderServiceInspect captured patch +1 / −1
### BTCPayServer/Storage/Services/Providers/GoogleCloudStorage/GoogleCloudStorageFileProviderService.cs
@@ -19,7 +19,7 @@ public override StorageProvider StorageProvider()
protected override Task<IStorageProvider> GetStorageProvider(
GoogleCloudStorageConfiguration configuration)
{
- return Task.FromResult<IStorageProvider>(new GoogleStorageProvider(GoogleCredential.FromJson(configuration.JsonCredentials), configuration));
+ return Task.FromResult<IStorageProvider>(new GoogleStorageProvider(CredentialFactory.FromJson<ServiceAccountCredential>(configuration.JsonCredentials).ToGoogleCredential(), configuration));
}
}
}Why this scored 24/100
Community notes
Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.
The AI analysis stands alone for now. Submit a note if you can add evidence or important context.