| 1 |
<?php |
| 2 |
|
| 3 |
namespace Dudlewebs\WPMCS\s3\Aws\Token; |
| 4 |
|
| 5 |
use Dudlewebs\WPMCS\s3\Aws\Configuration\ConfigurationResolver; |
| 6 |
use Dudlewebs\WPMCS\s3\Aws\Exception\TokenException; |
| 7 |
use Dudlewebs\WPMCS\s3\GuzzleHttp\Promise; |
| 8 |
/** |
| 9 |
* Token provider for Bedrock that sources bearer tokens from environment variables. |
| 10 |
*/ |
| 11 |
class BedrockTokenProvider extends TokenProvider |
| 12 |
{ |
| 13 |
/** @var string used to resolve the AWS_BEARER_TOKEN_BEDROCK env var */ |
| 14 |
public const TOKEN_ENV_KEY = 'bearer_token_bedrock'; |
| 15 |
public const BEARER_AUTH = 'smithy.api#httpBearerAuth'; |
| 16 |
/** |
| 17 |
* Create a default Bedrock token provider that checks for a bearer token |
| 18 |
* in the AWS_BEARER_TOKEN_BEDROCK environment variable. |
| 19 |
* |
| 20 |
* This provider is automatically wrapped in a memoize function that caches |
| 21 |
* previously provided tokens. |
| 22 |
* |
| 23 |
* @param array $config Optional array of token provider options. |
| 24 |
* |
| 25 |
* @return callable |
| 26 |
*/ |
| 27 |
public static function defaultProvider(array $config = []) : callable |
| 28 |
{ |
| 29 |
$defaultChain = ['env' => self::env(self::TOKEN_ENV_KEY)]; |
| 30 |
return self::memoize(\call_user_func_array([TokenProvider::class, 'chain'], \array_values($defaultChain))); |
| 31 |
} |
| 32 |
/** |
| 33 |
* Token provider that creates a token from an environment variable. |
| 34 |
* |
| 35 |
* @param string $configKey The configuration key that will be transformed |
| 36 |
* to an environment variable name by ConfigurationResolver |
| 37 |
* |
| 38 |
* @return callable |
| 39 |
*/ |
| 40 |
public static function env(string $configKey) : callable |
| 41 |
{ |
| 42 |
return static function () use($configKey) { |
| 43 |
$tokenValue = ConfigurationResolver::env($configKey); |
| 44 |
if (empty($tokenValue)) { |
| 45 |
return Promise\Create::rejectionFor(new TokenException("No token found in environment variable " . ConfigurationResolver::$envPrefix . \strtoupper($configKey))); |
| 46 |
} |
| 47 |
return Promise\Create::promiseFor(new Token($tokenValue)); |
| 48 |
}; |
| 49 |
} |
| 50 |
/** |
| 51 |
* Create a token provider from a raw token value string. |
| 52 |
* Bedrock bearer tokens sourced from env do not have an expiration |
| 53 |
* |
| 54 |
* @param string $tokenValue The bearer token value |
| 55 |
* |
| 56 |
* @return callable |
| 57 |
*/ |
| 58 |
public static function fromTokenValue(string $tokenValue, ?TokenSource $source = null) : callable |
| 59 |
{ |
| 60 |
$token = new Token($tokenValue, null, $source); |
| 61 |
return self::fromToken($token); |
| 62 |
} |
| 63 |
/** |
| 64 |
* Create a Bedrock token provider if the service is 'bedrock' and a token is available. |
| 65 |
* Sets auth scheme preference to `bearer` auth. |
| 66 |
* |
| 67 |
* @param array $args Configuration arguments containing 'config' array |
| 68 |
* |
| 69 |
* @return callable|null Returns a token provider if conditions are met, null otherwise |
| 70 |
*/ |
| 71 |
public static function createIfAvailable(array &$args) : ?callable |
| 72 |
{ |
| 73 |
$tokenValue = ConfigurationResolver::env(self::TOKEN_ENV_KEY); |
| 74 |
if ($tokenValue) { |
| 75 |
$authSchemePreference = $args['config']['auth_scheme_preference'] ?? []; |
| 76 |
\array_unshift($authSchemePreference, self::BEARER_AUTH); |
| 77 |
$args['config']['auth_scheme_preference'] = $authSchemePreference; |
| 78 |
return self::fromTokenValue($tokenValue, TokenSource::BEARER_SERVICE_ENV_VARS); |
| 79 |
} |
| 80 |
return null; |
| 81 |
} |
| 82 |
} |
| 83 |
|