PluginProbe
Media Cloud Sync / 1.4.2
Media Cloud Sync v1.4.2
1.4.2 1.4.1 1.4.0 1.3.12 1.3.11 1.3.10 trunk 1.0.0 1.0.1 1.0.2 1.0.3 1.1.0 1.1.1 1.2.0 1.2.10 1.2.11 1.2.12 1.2.13 1.2.2 1.2.3 1.2.4 1.2.5 1.2.6 1.2.7 1.2.8 All 36 releases
← All changes | includes/sdk/s3/Aws/Credentials/AssumeRoleWithWebIdentityCredentialProvider.php +22 -4 1.2.3 → 1.4.2 View file →
@@ -28,8 +28,10 @@
28 28 /** @var integer */
29 29 private $authenticationAttempts;
30 30 /** @var integer */
31 31 private $tokenFileReadAttempts;
32 + /** @var string */
33 + private $source;
32 34 /**
33 35 * The constructor attempts to load config from environment variables.
34 36 * If not set, the following config options are used:
35 37 * - WebIdentityTokenFile: full path of token filename
@@ -34,8 +36,10 @@
34 36 * If not set, the following config options are used:
35 37 * - WebIdentityTokenFile: full path of token filename
36 38 * - RoleArn: arn of role to be assumed
37 39 * - SessionName: (optional) set by SDK if not provided
40 + * - source: To identify if the provider was sourced by a profile or
41 + * from environment definition. Default will be `sts_web_id_token`.
38 42 *
39 43 * @param array $config Configuration options
40 44 * @throws \InvalidArgumentException
41 45 */
@@ -54,15 +58,16 @@
54 58 }
55 59 $this->retries = (int) \getenv(self::ENV_RETRIES) ?: (isset($config['retries']) ? $config['retries'] : 3);
56 60 $this->authenticationAttempts = 0;
57 61 $this->tokenFileReadAttempts = 0;
58 - $this->session = isset($config['SessionName']) ? $config['SessionName'] : 'aws-sdk-php-' . \round(\microtime(\true) * 1000);
59 - $region = isset($config['region']) ? $config['region'] : 'us-east-1';
62 + $this->session = $config['SessionName'] ?? 'aws-sdk-php-' . \round(\microtime(\true) * 1000);
60 63 if (isset($config['client'])) {
61 64 $this->client = $config['client'];
62 65 } else {
63 - $this->client = new StsClient(['credentials' => \false, 'region' => $region, 'version' => 'latest']);
66 + $region = $config['region'] ?? \getEnv(CredentialProvider::ENV_REGION) ?: null;
67 + $this->client = $this->createDefaultStsClient($region);
64 68 }
69 + $this->source = $config['source'] ?? CredentialSources::STS_WEB_ID_TOKEN;
65 70 }
66 71 /**
67 72 * Loads assume role with web identity credentials.
68 73 *
@@ -113,8 +118,21 @@
113 118 throw new CredentialsException("Error retrieving web identity credentials: " . $e->getMessage() . " (" . $e->getCode() . ")");
114 119 }
115 120 $this->authenticationAttempts++;
116 121 }
117 - (yield $this->client->createCredentials($result));
122 + (yield $this->client->createCredentials($result, $this->source));
118 123 });
124 + }
125 + /**
126 + * @param string|null $region
127 + *
128 + * @return StsClient
129 + */
130 + private function createDefaultStsClient(?string $region) : StsClient
131 + {
132 + if (empty($region)) {
133 + $region = CredentialProvider::FALLBACK_REGION;
134 + \trigger_error('NOTICE: STS client created without explicit `region` configuration.' . \PHP_EOL . "Defaulting to {$region}. This fallback behavior may be removed." . \PHP_EOL . 'To avoid potential disruptions, configure a region using one of the following methods:' . \PHP_EOL . '(1) Pass `region` in the `$config` array when calling the provider,' . \PHP_EOL . '(2) Set the `AWS_REGION` environment variable.' . \PHP_EOL . 'OR provide an STS client in the `$config` array when creating the provider as `client`.' . \PHP_EOL . 'See: https://docs.aws.amazon.com/sdk-for-php/v3/developer-guide/assume-role-with-web-identity-provider.html' . \PHP_EOL, \E_USER_NOTICE);
135 + }
136 + return new StsClient(['credentials' => \false, 'region' => $region]);
119 137 }
120 138 }