← All changes
|
includes/sdk/s3/Aws/Credentials/AssumeRoleWithWebIdentityCredentialProvider.php
+22
-4
1.2.12
→
1.4.2
View file →
| @@ -28,8 +28,10 @@ | ||
| 28 | 28 | /** @var integer */ |
| 29 | 29 | private $authenticationAttempts; |
| 30 | 30 | /** @var integer */ |
| 31 | 31 | private $tokenFileReadAttempts; |
| 32 | + /** @var string */ | |
| 33 | + private $source; | |
| 32 | 34 | /** |
| 33 | 35 | * The constructor attempts to load config from environment variables. |
| 34 | 36 | * If not set, the following config options are used: |
| 35 | 37 | * - WebIdentityTokenFile: full path of token filename |
| @@ -34,8 +36,10 @@ | ||
| 34 | 36 | * If not set, the following config options are used: |
| 35 | 37 | * - WebIdentityTokenFile: full path of token filename |
| 36 | 38 | * - RoleArn: arn of role to be assumed |
| 37 | 39 | * - SessionName: (optional) set by SDK if not provided |
| 40 | + * - source: To identify if the provider was sourced by a profile or | |
| 41 | + * from environment definition. Default will be `sts_web_id_token`. | |
| 38 | 42 | * |
| 39 | 43 | * @param array $config Configuration options |
| 40 | 44 | * @throws \InvalidArgumentException |
| 41 | 45 | */ |
| @@ -54,15 +58,16 @@ | ||
| 54 | 58 | } |
| 55 | 59 | $this->retries = (int) \getenv(self::ENV_RETRIES) ?: (isset($config['retries']) ? $config['retries'] : 3); |
| 56 | 60 | $this->authenticationAttempts = 0; |
| 57 | 61 | $this->tokenFileReadAttempts = 0; |
| 58 | - $this->session = isset($config['SessionName']) ? $config['SessionName'] : 'aws-sdk-php-' . \round(\microtime(\true) * 1000); | |
| 59 | - $region = isset($config['region']) ? $config['region'] : 'us-east-1'; | |
| 62 | + $this->session = $config['SessionName'] ?? 'aws-sdk-php-' . \round(\microtime(\true) * 1000); | |
| 60 | 63 | if (isset($config['client'])) { |
| 61 | 64 | $this->client = $config['client']; |
| 62 | 65 | } else { |
| 63 | - $this->client = new StsClient(['credentials' => \false, 'region' => $region, 'version' => 'latest']); | |
| 66 | + $region = $config['region'] ?? \getEnv(CredentialProvider::ENV_REGION) ?: null; | |
| 67 | + $this->client = $this->createDefaultStsClient($region); | |
| 64 | 68 | } |
| 69 | + $this->source = $config['source'] ?? CredentialSources::STS_WEB_ID_TOKEN; | |
| 65 | 70 | } |
| 66 | 71 | /** |
| 67 | 72 | * Loads assume role with web identity credentials. |
| 68 | 73 | * |
| @@ -113,8 +118,21 @@ | ||
| 113 | 118 | throw new CredentialsException("Error retrieving web identity credentials: " . $e->getMessage() . " (" . $e->getCode() . ")"); |
| 114 | 119 | } |
| 115 | 120 | $this->authenticationAttempts++; |
| 116 | 121 | } |
| 117 | - (yield $this->client->createCredentials($result)); | |
| 122 | + (yield $this->client->createCredentials($result, $this->source)); | |
| 118 | 123 | }); |
| 124 | + } | |
| 125 | + /** | |
| 126 | + * @param string|null $region | |
| 127 | + * | |
| 128 | + * @return StsClient | |
| 129 | + */ | |
| 130 | + private function createDefaultStsClient(?string $region) : StsClient | |
| 131 | + { | |
| 132 | + if (empty($region)) { | |
| 133 | + $region = CredentialProvider::FALLBACK_REGION; | |
| 134 | + \trigger_error('NOTICE: STS client created without explicit `region` configuration.' . \PHP_EOL . "Defaulting to {$region}. This fallback behavior may be removed." . \PHP_EOL . 'To avoid potential disruptions, configure a region using one of the following methods:' . \PHP_EOL . '(1) Pass `region` in the `$config` array when calling the provider,' . \PHP_EOL . '(2) Set the `AWS_REGION` environment variable.' . \PHP_EOL . 'OR provide an STS client in the `$config` array when creating the provider as `client`.' . \PHP_EOL . 'See: https://docs.aws.amazon.com/sdk-for-php/v3/developer-guide/assume-role-with-web-identity-provider.html' . \PHP_EOL, \E_USER_NOTICE); | |
| 135 | + } | |
| 136 | + return new StsClient(['credentials' => \false, 'region' => $region]); | |
| 119 | 137 | } |
| 120 | 138 | } |