Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -28,6 +28,8 @@ namespace Aws
}
namespace Auth
{
class CredentialsCachingProvider;

constexpr int REFRESH_THRESHOLD = 1000 * 60 * 5;

constexpr int AWS_CREDENTIAL_PROVIDER_EXPIRATION_GRACE_PERIOD = 5 * 1000;
Expand Down Expand Up @@ -73,6 +75,12 @@ namespace Aws
*/
virtual AWSCredentials GetAWSCredentials() = 0;

/**
* Called when a target service rejected the credentials that signed a request. Caching providers
* override this to mark theirs for refresh; an override must not discard them.
*/
virtual void Invalidate(const Aws::String& /*rejectedAccessKeyId*/) {}

protected:
/**
* The default implementation keeps up with the cache times and lets you know if it's time to refresh your internal caching
Expand Down Expand Up @@ -227,15 +235,14 @@ namespace Aws
*/
AWSCredentials GetAWSCredentials() override;

protected:
void Reload() override;
// Marks the cached credentials for refresh, only if they are the ones that were rejected.
void Invalidate(const Aws::String& accessKeyId) override;

private:
bool ExpiresSoon() const;
void RefreshIfExpired();
// Fetch-only provider composed into m_cachingProvider; defined in the .cpp.
class InstanceProfileFetchOnlyProvider;

std::shared_ptr<Aws::Config::AWSProfileConfigLoader> m_ec2MetadataConfigLoader;
long m_loadFrequencyMs;
std::shared_ptr<CredentialsCachingProvider> m_cachingProvider;
};

/**
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
/**
* Copyright Amazon.com, Inc. or its affiliates. All Rights Reserved.
* SPDX-License-Identifier: Apache-2.0.
*/

#pragma once

#include <aws/core/Core_EXPORTS.h>
#include <aws/core/auth/AWSCredentialsProvider.h>
#include <aws/core/utils/DateTime.h>
#include <memory>

namespace Aws
{
namespace Internal { class CredentialsCachingStateImpl; }
namespace Auth
{
/**
* Caches an AWSCredentialsProvider's credentials: advisory/mandatory refresh windows, jittered
* backoff, a single in-flight fetch, and serving the last-good credentials when a fetch fails.
* Empty credentials from the wrapped provider mark a failed fetch.
*/
class AWS_CORE_API CredentialsCachingProvider final : public AWSCredentialsProvider
{
public:
explicit CredentialsCachingProvider(std::shared_ptr<AWSCredentialsProvider> delegate);
~CredentialsCachingProvider() override;

AWSCredentials GetAWSCredentials() override;

// Marks the cached credentials for refresh, only if they are the ones that were rejected.
void Invalidate(const Aws::String& accessKeyId) override;

private:
std::shared_ptr<AWSCredentialsProvider> m_delegate;
std::unique_ptr<Aws::Internal::CredentialsCachingStateImpl> m_cachingState;
};
} // namespace Auth
} // namespace Aws
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,8 @@ class Credentials;

namespace Aws {
namespace Auth {
class CredentialsCachingProvider;

/**
* A utility class for wrapping a cached crt credentials provider.
*/
Expand All @@ -37,20 +39,21 @@ class AWS_CORE_API CrtCredentialsProvider : public AWSCredentialsProvider {
*/
AWSCredentials GetAWSCredentials() override;

void Invalidate(const Aws::String& accessKeyId) override;

private:
enum class STATE {
INITIALIZED,
NOT_INITIALIZED,
};

static AWSCredentials ExtractCredentialsFromCrt(const Aws::Crt::Auth::Credentials& crtCredentials);
void Reload() override;
void RefreshIfExpired();

// Nested so it can call the private ExtractCredentialsFromCrt(); defined in the .cpp.
class CrtFetchOnlyProvider;

std::shared_ptr<Aws::Crt::Auth::ICredentialsProvider> m_credentialsProvider;
AWSCredentials m_credentials;
std::chrono::milliseconds m_providerFuturesTimeoutMs;
Aws::Client::UserAgentFeature m_userAgentFeature;
std::shared_ptr<CredentialsCachingProvider> m_cachingProvider;
Aws::String m_providerName;
STATE m_state{STATE::NOT_INITIALIZED};
};
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,8 @@ namespace Aws
{
namespace Auth
{
class CredentialsCachingProvider;

/**
* General HTTP Credentials Provider (previously known as ECS credentials provider)
* implementation that loads credentials from an arbitrary HTTP(S) endpoint specified by the environment
Expand Down Expand Up @@ -89,6 +91,9 @@ namespace Aws
*/
AWSCredentials GetAWSCredentials() override;

// Marks the cached credentials for refresh, only if they are the ones that were rejected.
void Invalidate(const Aws::String& accessKeyId) override;

static const char AWS_CONTAINER_AUTHORIZATION_TOKEN_FILE[];
static const char AWS_CONTAINER_CREDENTIALS_RELATIVE_URI[];
static const char AWS_CONTAINER_CREDENTIALS_FULL_URI[];
Expand All @@ -98,20 +103,15 @@ namespace Aws
static const char AWS_EKS_CONTAINER_HOST[];
static const char AWS_EKS_CONTAINER_HOST_IPV6[];

protected:
void Reload() override;

private:
bool ExpiresSoon() const;
void RefreshIfExpired();

Aws::String LoadTokenFromFile() const;

// Fetch-only provider composed into m_cachingProvider; defined in the .cpp.
class GeneralHTTPFetchOnlyProvider;

std::shared_ptr<Aws::Internal::ECSCredentialsClient> m_ecsCredentialsClient;
Aws::String m_authTokenFilePath;

long m_loadFrequencyMs = REFRESH_THRESHOLD;
Aws::Auth::AWSCredentials m_credentials;
std::shared_ptr<CredentialsCachingProvider> m_cachingProvider;
};

// GeneralHTTPCredentialsProvider was previously known as TaskRoleCredentialsProvider or "ECS credentials provider"
Expand Down
31 changes: 10 additions & 21 deletions src/aws-cpp-sdk-core/include/aws/core/auth/SSOCredentialsProvider.h
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,8 @@

namespace Aws {
namespace Auth {
class CredentialsCachingProvider;

/**
* To support usage of SSO credentials
*/
Expand All @@ -22,33 +24,20 @@ namespace Aws {
SSOCredentialsProvider();
explicit SSOCredentialsProvider(const Aws::String& profile);
explicit SSOCredentialsProvider(const Aws::String& profile, std::shared_ptr<const Aws::Client::ClientConfiguration> config);

/**
* Retrieves the credentials if found, otherwise returns empty credential set.
*/
AWSCredentials GetAWSCredentials() override;

// Marks the cached credentials for refresh, only if they are the ones that were rejected.
void Invalidate(const Aws::String& accessKeyId) override;

private:
Aws::UniquePtr<Aws::Internal::SSOCredentialsClient> m_client;
Aws::Auth::AWSCredentials m_credentials;

// Profile description variables
Aws::String m_profileToUse;

// The AWS account ID that temporary AWS credentials are resolved for.
Aws::String m_ssoAccountId;
// The AWS region where the SSO directory for the given sso_start_url is hosted.
// This is independent of the general region configuration and MUST NOT be conflated.
Aws::String m_ssoRegion;
// The expiration time of the accessToken.
Aws::Utils::DateTime m_expiresAt;
// The SSO Token Provider
Aws::Auth::SSOBearerTokenProvider m_bearerTokenProvider;
// The client configuration to use
std::shared_ptr<const Aws::Client::ClientConfiguration> m_config;

void Reload() override;
void RefreshIfExpired();
Aws::String LoadAccessTokenFile(const Aws::String& ssoAccessTokenPath);
// Fetch-only provider composed into m_cachingProvider; defined in the .cpp.
class SSOFetchOnlyProvider;

std::shared_ptr<CredentialsCachingProvider> m_cachingProvider;
};
} // namespace Auth
} // namespace Aws
5 changes: 5 additions & 0 deletions src/aws-cpp-sdk-core/include/aws/core/client/AWSClient.h
Original file line number Diff line number Diff line change
Expand Up @@ -346,6 +346,11 @@ namespace Aws
* return true if signer's clock is adjusted, false otherwise.
*/
bool AdjustClockSkew(HttpResponseOutcome& outcome, const char* signerName) const;
/**
* Tell the credentials provider that a target service rejected the credentials that signed this
* attempt. No-op for providers that do not cache.
*/
void NotifyCredentialsRejected(const AWSError<CoreErrors>& error, const Aws::String& accessKeyId) const;
void AddHeadersToRequest(const std::shared_ptr<Aws::Http::HttpRequest>& httpRequest, const Http::HeaderValueCollection& headerValues) const;
void AddContentBodyToRequest(const std::shared_ptr<Aws::Http::HttpRequest>& httpRequest, const std::shared_ptr<Aws::IOStream>& body,
bool needsContentMd5 = false, bool isChunked = false) const;
Expand Down
2 changes: 2 additions & 0 deletions src/aws-cpp-sdk-core/include/aws/core/client/CoreErrors.h
Original file line number Diff line number Diff line change
Expand Up @@ -48,6 +48,8 @@ namespace Aws
NOT_INITIALIZED = 25,
MEMORY_ALLOCATION = 26,
NOT_IMPLEMENTED = 27,
EXPIRED_TOKEN = 28,
INVALID_TOKEN = 29,

NETWORK_CONNECTION = 99, // General failure to send message to service

Expand Down
Loading
Loading