| @@ -1,8 +1,9 @@ | ||
| 1 | 1 | <?php |
| 2 | 2 | |
| 3 | 3 | namespace Dudlewebs\WPMCS\s3\Aws\Sts; |
| 4 | 4 | |
| 5 | +use Dudlewebs\WPMCS\s3\Aws\Arn\ArnParser; | |
| 5 | 6 | use Dudlewebs\WPMCS\s3\Aws\AwsClient; |
| 6 | 7 | use Dudlewebs\WPMCS\s3\Aws\CacheInterface; |
| 7 | 8 | use Dudlewebs\WPMCS\s3\Aws\Credentials\Credentials; |
| 8 | 9 | use Dudlewebs\WPMCS\s3\Aws\Result; |
| @@ -15,8 +16,10 @@ | ||
| 15 | 16 | * @method \Aws\Result assumeRoleWithSAML(array $args = []) |
| 16 | 17 | * @method \GuzzleHttp\Promise\Promise assumeRoleWithSAMLAsync(array $args = []) |
| 17 | 18 | * @method \Aws\Result assumeRoleWithWebIdentity(array $args = []) |
| 18 | 19 | * @method \GuzzleHttp\Promise\Promise assumeRoleWithWebIdentityAsync(array $args = []) |
| 20 | + * @method \Aws\Result assumeRoot(array $args = []) | |
| 21 | + * @method \GuzzleHttp\Promise\Promise assumeRootAsync(array $args = []) | |
| 19 | 22 | * @method \Aws\Result decodeAuthorizationMessage(array $args = []) |
| 20 | 23 | * @method \GuzzleHttp\Promise\Promise decodeAuthorizationMessageAsync(array $args = []) |
| 21 | 24 | * @method \Aws\Result getAccessKeyInfo(array $args = []) |
| 22 | 25 | * @method \GuzzleHttp\Promise\Promise getAccessKeyInfoAsync(array $args = []) |
| @@ -21,8 +24,10 @@ | ||
| 21 | 24 | * @method \Aws\Result getAccessKeyInfo(array $args = []) |
| 22 | 25 | * @method \GuzzleHttp\Promise\Promise getAccessKeyInfoAsync(array $args = []) |
| 23 | 26 | * @method \Aws\Result getCallerIdentity(array $args = []) |
| 24 | 27 | * @method \GuzzleHttp\Promise\Promise getCallerIdentityAsync(array $args = []) |
| 28 | + * @method \Aws\Result getDelegatedAccessToken(array $args = []) | |
| 29 | + * @method \GuzzleHttp\Promise\Promise getDelegatedAccessTokenAsync(array $args = []) | |
| 25 | 30 | * @method \Aws\Result getFederationToken(array $args = []) |
| 26 | 31 | * @method \GuzzleHttp\Promise\Promise getFederationTokenAsync(array $args = []) |
| 27 | 32 | * @method \Aws\Result getSessionToken(array $args = []) |
| 28 | 33 | * @method \GuzzleHttp\Promise\Promise getSessionTokenAsync(array $args = []) |
| @@ -52,8 +57,9 @@ | ||
| 52 | 57 | { |
| 53 | 58 | if (!isset($args['sts_regional_endpoints']) || $args['sts_regional_endpoints'] instanceof CacheInterface) { |
| 54 | 59 | $args['sts_regional_endpoints'] = ConfigurationProvider::defaultProvider($args); |
| 55 | 60 | } |
| 61 | + $this->addBuiltIns($args); | |
| 56 | 62 | parent::__construct($args); |
| 57 | 63 | } |
| 58 | 64 | /** |
| 59 | 65 | * Creates credentials from the result of an STS operations |
| @@ -62,13 +68,50 @@ | ||
| 62 | 68 | * |
| 63 | 69 | * @return Credentials |
| 64 | 70 | * @throws \InvalidArgumentException if the result contains no credentials |
| 65 | 71 | */ |
| 66 | - public function createCredentials(Result $result) | |
| 72 | + public function createCredentials(Result $result, $source = null) | |
| 67 | 73 | { |
| 68 | 74 | if (!$result->hasKey('Credentials')) { |
| 69 | 75 | throw new \InvalidArgumentException('Result contains no credentials'); |
| 70 | 76 | } |
| 71 | - $c = $result['Credentials']; | |
| 72 | - return new Credentials($c['AccessKeyId'], $c['SecretAccessKey'], isset($c['SessionToken']) ? $c['SessionToken'] : null, isset($c['Expiration']) && $c['Expiration'] instanceof \DateTimeInterface ? (int) $c['Expiration']->format('U') : null); | |
| 77 | + $accountId = null; | |
| 78 | + if ($result->hasKey('AssumedRoleUser')) { | |
| 79 | + $parsedArn = ArnParser::parse($result->get('AssumedRoleUser')['Arn']); | |
| 80 | + $accountId = $parsedArn->getAccountId(); | |
| 81 | + } elseif ($result->hasKey('FederatedUser')) { | |
| 82 | + $parsedArn = ArnParser::parse($result->get('FederatedUser')['Arn']); | |
| 83 | + $accountId = $parsedArn->getAccountId(); | |
| 84 | + } | |
| 85 | + $credentials = $result['Credentials']; | |
| 86 | + $expiration = isset($credentials['Expiration']) && $credentials['Expiration'] instanceof \DateTimeInterface ? (int) $credentials['Expiration']->format('U') : null; | |
| 87 | + return new Credentials($credentials['AccessKeyId'], $credentials['SecretAccessKey'], isset($credentials['SessionToken']) ? $credentials['SessionToken'] : null, $expiration, $accountId, $source); | |
| 88 | + } | |
| 89 | + /** | |
| 90 | + * Adds service-specific client built-in value | |
| 91 | + * | |
| 92 | + * @return void | |
| 93 | + */ | |
| 94 | + private function addBuiltIns($args) | |
| 95 | + { | |
| 96 | + $key = 'AWS::STS::UseGlobalEndpoint'; | |
| 97 | + $result = $args['sts_regional_endpoints'] instanceof \Closure ? $args['sts_regional_endpoints']()->wait() : $args['sts_regional_endpoints']; | |
| 98 | + if (\is_string($result)) { | |
| 99 | + if ($result === 'regional') { | |
| 100 | + $value = \false; | |
| 101 | + } else { | |
| 102 | + if ($result === 'legacy') { | |
| 103 | + $value = \true; | |
| 104 | + } else { | |
| 105 | + return; | |
| 106 | + } | |
| 107 | + } | |
| 108 | + } else { | |
| 109 | + if ($result->getEndpointsType() === 'regional') { | |
| 110 | + $value = \false; | |
| 111 | + } else { | |
| 112 | + $value = \true; | |
| 113 | + } | |
| 114 | + } | |
| 115 | + $this->clientBuiltIns[$key] = $value; | |
| 73 | 116 | } |
| 74 | 117 | } |