| 1 |
<?php |
| 2 |
|
| 3 |
namespace Dudlewebs\WPMCS\s3\Aws\Sts; |
| 4 |
|
| 5 |
use Dudlewebs\WPMCS\s3\Aws\Arn\ArnParser; |
| 6 |
use Dudlewebs\WPMCS\s3\Aws\AwsClient; |
| 7 |
use Dudlewebs\WPMCS\s3\Aws\CacheInterface; |
| 8 |
use Dudlewebs\WPMCS\s3\Aws\Credentials\Credentials; |
| 9 |
use Dudlewebs\WPMCS\s3\Aws\Result; |
| 10 |
use Dudlewebs\WPMCS\s3\Aws\Sts\RegionalEndpoints\ConfigurationProvider; |
| 11 |
/** |
| 12 |
* This client is used to interact with the **AWS Security Token Service (AWS STS)**. |
| 13 |
* |
| 14 |
* @method \Aws\Result assumeRole(array $args = []) |
| 15 |
* @method \GuzzleHttp\Promise\Promise assumeRoleAsync(array $args = []) |
| 16 |
* @method \Aws\Result assumeRoleWithSAML(array $args = []) |
| 17 |
* @method \GuzzleHttp\Promise\Promise assumeRoleWithSAMLAsync(array $args = []) |
| 18 |
* @method \Aws\Result assumeRoleWithWebIdentity(array $args = []) |
| 19 |
* @method \GuzzleHttp\Promise\Promise assumeRoleWithWebIdentityAsync(array $args = []) |
| 20 |
* @method \Aws\Result assumeRoot(array $args = []) |
| 21 |
* @method \GuzzleHttp\Promise\Promise assumeRootAsync(array $args = []) |
| 22 |
* @method \Aws\Result decodeAuthorizationMessage(array $args = []) |
| 23 |
* @method \GuzzleHttp\Promise\Promise decodeAuthorizationMessageAsync(array $args = []) |
| 24 |
* @method \Aws\Result getAccessKeyInfo(array $args = []) |
| 25 |
* @method \GuzzleHttp\Promise\Promise getAccessKeyInfoAsync(array $args = []) |
| 26 |
* @method \Aws\Result getCallerIdentity(array $args = []) |
| 27 |
* @method \GuzzleHttp\Promise\Promise getCallerIdentityAsync(array $args = []) |
| 28 |
* @method \Aws\Result getDelegatedAccessToken(array $args = []) |
| 29 |
* @method \GuzzleHttp\Promise\Promise getDelegatedAccessTokenAsync(array $args = []) |
| 30 |
* @method \Aws\Result getFederationToken(array $args = []) |
| 31 |
* @method \GuzzleHttp\Promise\Promise getFederationTokenAsync(array $args = []) |
| 32 |
* @method \Aws\Result getSessionToken(array $args = []) |
| 33 |
* @method \GuzzleHttp\Promise\Promise getSessionTokenAsync(array $args = []) |
| 34 |
*/ |
| 35 |
class StsClient extends AwsClient |
| 36 |
{ |
| 37 |
/** |
| 38 |
* {@inheritdoc} |
| 39 |
* |
| 40 |
* In addition to the options available to |
| 41 |
* {@see \Aws\AwsClient::__construct}, StsClient accepts the following |
| 42 |
* options: |
| 43 |
* |
| 44 |
* - sts_regional_endpoints: |
| 45 |
* (Aws\Sts\RegionalEndpoints\ConfigurationInterface|Aws\CacheInterface\|callable|string|array) |
| 46 |
* Specifies whether to use regional or legacy endpoints for legacy regions. |
| 47 |
* Provide an Aws\Sts\RegionalEndpoints\ConfigurationInterface object, an |
| 48 |
* instance of Aws\CacheInterface, a callable configuration provider used |
| 49 |
* to create endpoint configuration, a string value of `legacy` or |
| 50 |
* `regional`, or an associative array with the following keys: |
| 51 |
* endpoint_types (string) Set to `legacy` or `regional`, defaults to |
| 52 |
* `legacy` |
| 53 |
* |
| 54 |
* @param array $args |
| 55 |
*/ |
| 56 |
public function __construct(array $args) |
| 57 |
{ |
| 58 |
if (!isset($args['sts_regional_endpoints']) || $args['sts_regional_endpoints'] instanceof CacheInterface) { |
| 59 |
$args['sts_regional_endpoints'] = ConfigurationProvider::defaultProvider($args); |
| 60 |
} |
| 61 |
$this->addBuiltIns($args); |
| 62 |
parent::__construct($args); |
| 63 |
} |
| 64 |
/** |
| 65 |
* Creates credentials from the result of an STS operations |
| 66 |
* |
| 67 |
* @param Result $result Result of an STS operation |
| 68 |
* |
| 69 |
* @return Credentials |
| 70 |
* @throws \InvalidArgumentException if the result contains no credentials |
| 71 |
*/ |
| 72 |
public function createCredentials(Result $result, $source = null) |
| 73 |
{ |
| 74 |
if (!$result->hasKey('Credentials')) { |
| 75 |
throw new \InvalidArgumentException('Result contains no credentials'); |
| 76 |
} |
| 77 |
$accountId = null; |
| 78 |
if ($result->hasKey('AssumedRoleUser')) { |
| 79 |
$parsedArn = ArnParser::parse($result->get('AssumedRoleUser')['Arn']); |
| 80 |
$accountId = $parsedArn->getAccountId(); |
| 81 |
} elseif ($result->hasKey('FederatedUser')) { |
| 82 |
$parsedArn = ArnParser::parse($result->get('FederatedUser')['Arn']); |
| 83 |
$accountId = $parsedArn->getAccountId(); |
| 84 |
} |
| 85 |
$credentials = $result['Credentials']; |
| 86 |
$expiration = isset($credentials['Expiration']) && $credentials['Expiration'] instanceof \DateTimeInterface ? (int) $credentials['Expiration']->format('U') : null; |
| 87 |
return new Credentials($credentials['AccessKeyId'], $credentials['SecretAccessKey'], isset($credentials['SessionToken']) ? $credentials['SessionToken'] : null, $expiration, $accountId, $source); |
| 88 |
} |
| 89 |
/** |
| 90 |
* Adds service-specific client built-in value |
| 91 |
* |
| 92 |
* @return void |
| 93 |
*/ |
| 94 |
private function addBuiltIns($args) |
| 95 |
{ |
| 96 |
$key = 'AWS::STS::UseGlobalEndpoint'; |
| 97 |
$result = $args['sts_regional_endpoints'] instanceof \Closure ? $args['sts_regional_endpoints']()->wait() : $args['sts_regional_endpoints']; |
| 98 |
if (\is_string($result)) { |
| 99 |
if ($result === 'regional') { |
| 100 |
$value = \false; |
| 101 |
} else { |
| 102 |
if ($result === 'legacy') { |
| 103 |
$value = \true; |
| 104 |
} else { |
| 105 |
return; |
| 106 |
} |
| 107 |
} |
| 108 |
} else { |
| 109 |
if ($result->getEndpointsType() === 'regional') { |
| 110 |
$value = \false; |
| 111 |
} else { |
| 112 |
$value = \true; |
| 113 |
} |
| 114 |
} |
| 115 |
$this->clientBuiltIns[$key] = $value; |
| 116 |
} |
| 117 |
} |
| 118 |
|