remove node_modules and .gitignore them
This commit is contained in:
-201
@@ -1,201 +0,0 @@
|
||||
Apache License
|
||||
Version 2.0, January 2004
|
||||
http://www.apache.org/licenses/
|
||||
|
||||
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
|
||||
|
||||
1. Definitions.
|
||||
|
||||
"License" shall mean the terms and conditions for use, reproduction,
|
||||
and distribution as defined by Sections 1 through 9 of this document.
|
||||
|
||||
"Licensor" shall mean the copyright owner or entity authorized by
|
||||
the copyright owner that is granting the License.
|
||||
|
||||
"Legal Entity" shall mean the union of the acting entity and all
|
||||
other entities that control, are controlled by, or are under common
|
||||
control with that entity. For the purposes of this definition,
|
||||
"control" means (i) the power, direct or indirect, to cause the
|
||||
direction or management of such entity, whether by contract or
|
||||
otherwise, or (ii) ownership of fifty percent (50%) or more of the
|
||||
outstanding shares, or (iii) beneficial ownership of such entity.
|
||||
|
||||
"You" (or "Your") shall mean an individual or Legal Entity
|
||||
exercising permissions granted by this License.
|
||||
|
||||
"Source" form shall mean the preferred form for making modifications,
|
||||
including but not limited to software source code, documentation
|
||||
source, and configuration files.
|
||||
|
||||
"Object" form shall mean any form resulting from mechanical
|
||||
transformation or translation of a Source form, including but
|
||||
not limited to compiled object code, generated documentation,
|
||||
and conversions to other media types.
|
||||
|
||||
"Work" shall mean the work of authorship, whether in Source or
|
||||
Object form, made available under the License, as indicated by a
|
||||
copyright notice that is included in or attached to the work
|
||||
(an example is provided in the Appendix below).
|
||||
|
||||
"Derivative Works" shall mean any work, whether in Source or Object
|
||||
form, that is based on (or derived from) the Work and for which the
|
||||
editorial revisions, annotations, elaborations, or other modifications
|
||||
represent, as a whole, an original work of authorship. For the purposes
|
||||
of this License, Derivative Works shall not include works that remain
|
||||
separable from, or merely link (or bind by name) to the interfaces of,
|
||||
the Work and Derivative Works thereof.
|
||||
|
||||
"Contribution" shall mean any work of authorship, including
|
||||
the original version of the Work and any modifications or additions
|
||||
to that Work or Derivative Works thereof, that is intentionally
|
||||
submitted to Licensor for inclusion in the Work by the copyright owner
|
||||
or by an individual or Legal Entity authorized to submit on behalf of
|
||||
the copyright owner. For the purposes of this definition, "submitted"
|
||||
means any form of electronic, verbal, or written communication sent
|
||||
to the Licensor or its representatives, including but not limited to
|
||||
communication on electronic mailing lists, source code control systems,
|
||||
and issue tracking systems that are managed by, or on behalf of, the
|
||||
Licensor for the purpose of discussing and improving the Work, but
|
||||
excluding communication that is conspicuously marked or otherwise
|
||||
designated in writing by the copyright owner as "Not a Contribution."
|
||||
|
||||
"Contributor" shall mean Licensor and any individual or Legal Entity
|
||||
on behalf of whom a Contribution has been received by Licensor and
|
||||
subsequently incorporated within the Work.
|
||||
|
||||
2. Grant of Copyright License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
copyright license to reproduce, prepare Derivative Works of,
|
||||
publicly display, publicly perform, sublicense, and distribute the
|
||||
Work and such Derivative Works in Source or Object form.
|
||||
|
||||
3. Grant of Patent License. Subject to the terms and conditions of
|
||||
this License, each Contributor hereby grants to You a perpetual,
|
||||
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
|
||||
(except as stated in this section) patent license to make, have made,
|
||||
use, offer to sell, sell, import, and otherwise transfer the Work,
|
||||
where such license applies only to those patent claims licensable
|
||||
by such Contributor that are necessarily infringed by their
|
||||
Contribution(s) alone or by combination of their Contribution(s)
|
||||
with the Work to which such Contribution(s) was submitted. If You
|
||||
institute patent litigation against any entity (including a
|
||||
cross-claim or counterclaim in a lawsuit) alleging that the Work
|
||||
or a Contribution incorporated within the Work constitutes direct
|
||||
or contributory patent infringement, then any patent licenses
|
||||
granted to You under this License for that Work shall terminate
|
||||
as of the date such litigation is filed.
|
||||
|
||||
4. Redistribution. You may reproduce and distribute copies of the
|
||||
Work or Derivative Works thereof in any medium, with or without
|
||||
modifications, and in Source or Object form, provided that You
|
||||
meet the following conditions:
|
||||
|
||||
(a) You must give any other recipients of the Work or
|
||||
Derivative Works a copy of this License; and
|
||||
|
||||
(b) You must cause any modified files to carry prominent notices
|
||||
stating that You changed the files; and
|
||||
|
||||
(c) You must retain, in the Source form of any Derivative Works
|
||||
that You distribute, all copyright, patent, trademark, and
|
||||
attribution notices from the Source form of the Work,
|
||||
excluding those notices that do not pertain to any part of
|
||||
the Derivative Works; and
|
||||
|
||||
(d) If the Work includes a "NOTICE" text file as part of its
|
||||
distribution, then any Derivative Works that You distribute must
|
||||
include a readable copy of the attribution notices contained
|
||||
within such NOTICE file, excluding those notices that do not
|
||||
pertain to any part of the Derivative Works, in at least one
|
||||
of the following places: within a NOTICE text file distributed
|
||||
as part of the Derivative Works; within the Source form or
|
||||
documentation, if provided along with the Derivative Works; or,
|
||||
within a display generated by the Derivative Works, if and
|
||||
wherever such third-party notices normally appear. The contents
|
||||
of the NOTICE file are for informational purposes only and
|
||||
do not modify the License. You may add Your own attribution
|
||||
notices within Derivative Works that You distribute, alongside
|
||||
or as an addendum to the NOTICE text from the Work, provided
|
||||
that such additional attribution notices cannot be construed
|
||||
as modifying the License.
|
||||
|
||||
You may add Your own copyright statement to Your modifications and
|
||||
may provide additional or different license terms and conditions
|
||||
for use, reproduction, or distribution of Your modifications, or
|
||||
for any such Derivative Works as a whole, provided Your use,
|
||||
reproduction, and distribution of the Work otherwise complies with
|
||||
the conditions stated in this License.
|
||||
|
||||
5. Submission of Contributions. Unless You explicitly state otherwise,
|
||||
any Contribution intentionally submitted for inclusion in the Work
|
||||
by You to the Licensor shall be under the terms and conditions of
|
||||
this License, without any additional terms or conditions.
|
||||
Notwithstanding the above, nothing herein shall supersede or modify
|
||||
the terms of any separate license agreement you may have executed
|
||||
with Licensor regarding such Contributions.
|
||||
|
||||
6. Trademarks. This License does not grant permission to use the trade
|
||||
names, trademarks, service marks, or product names of the Licensor,
|
||||
except as required for reasonable and customary use in describing the
|
||||
origin of the Work and reproducing the content of the NOTICE file.
|
||||
|
||||
7. Disclaimer of Warranty. Unless required by applicable law or
|
||||
agreed to in writing, Licensor provides the Work (and each
|
||||
Contributor provides its Contributions) on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
|
||||
implied, including, without limitation, any warranties or conditions
|
||||
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
|
||||
PARTICULAR PURPOSE. You are solely responsible for determining the
|
||||
appropriateness of using or redistributing the Work and assume any
|
||||
risks associated with Your exercise of permissions under this License.
|
||||
|
||||
8. Limitation of Liability. In no event and under no legal theory,
|
||||
whether in tort (including negligence), contract, or otherwise,
|
||||
unless required by applicable law (such as deliberate and grossly
|
||||
negligent acts) or agreed to in writing, shall any Contributor be
|
||||
liable to You for damages, including any direct, indirect, special,
|
||||
incidental, or consequential damages of any character arising as a
|
||||
result of this License or out of the use or inability to use the
|
||||
Work (including but not limited to damages for loss of goodwill,
|
||||
work stoppage, computer failure or malfunction, or any and all
|
||||
other commercial damages or losses), even if such Contributor
|
||||
has been advised of the possibility of such damages.
|
||||
|
||||
9. Accepting Warranty or Additional Liability. While redistributing
|
||||
the Work or Derivative Works thereof, You may choose to offer,
|
||||
and charge a fee for, acceptance of support, warranty, indemnity,
|
||||
or other liability obligations and/or rights consistent with this
|
||||
License. However, in accepting such obligations, You may act only
|
||||
on Your own behalf and on Your sole responsibility, not on behalf
|
||||
of any other Contributor, and only if You agree to indemnify,
|
||||
defend, and hold each Contributor harmless for any liability
|
||||
incurred by, or claims asserted against, such Contributor by reason
|
||||
of your accepting any such warranty or additional liability.
|
||||
|
||||
END OF TERMS AND CONDITIONS
|
||||
|
||||
APPENDIX: How to apply the Apache License to your work.
|
||||
|
||||
To apply the Apache License to your work, attach the following
|
||||
boilerplate notice, with the fields enclosed by brackets "{}"
|
||||
replaced with your own identifying information. (Don't include
|
||||
the brackets!) The text should be enclosed in the appropriate
|
||||
comment syntax for the file format. We also recommend that a
|
||||
file or class name and description of purpose be included on the
|
||||
same "printed page" as the copyright notice for easier
|
||||
identification within third-party archives.
|
||||
|
||||
Copyright 2018-2020 Amazon.com, Inc. or its affiliates. All Rights Reserved.
|
||||
|
||||
Licensed under the Apache License, Version 2.0 (the "License");
|
||||
you may not use this file except in compliance with the License.
|
||||
You may obtain a copy of the License at
|
||||
|
||||
http://www.apache.org/licenses/LICENSE-2.0
|
||||
|
||||
Unless required by applicable law or agreed to in writing, software
|
||||
distributed under the License is distributed on an "AS IS" BASIS,
|
||||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||||
See the License for the specific language governing permissions and
|
||||
limitations under the License.
|
||||
-273
@@ -1,273 +0,0 @@
|
||||
<!-- generated file, do not edit directly -->
|
||||
|
||||
# @aws-sdk/client-sts
|
||||
|
||||
## Description
|
||||
|
||||
AWS SDK for JavaScript STS Client for Node.js, Browser and React Native.
|
||||
|
||||
<fullname>Security Token Service</fullname>
|
||||
|
||||
<p>Security Token Service (STS) enables you to request temporary, limited-privilege
|
||||
credentials for users. This guide provides descriptions of the STS API. For
|
||||
more information about using this service, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html">Temporary Security Credentials</a>.</p>
|
||||
|
||||
## Installing
|
||||
|
||||
To install the this package, simply type add or install @aws-sdk/client-sts
|
||||
using your favorite package manager:
|
||||
|
||||
- `npm install @aws-sdk/client-sts`
|
||||
- `yarn add @aws-sdk/client-sts`
|
||||
- `pnpm add @aws-sdk/client-sts`
|
||||
|
||||
## Getting Started
|
||||
|
||||
### Import
|
||||
|
||||
The AWS SDK is modulized by clients and commands.
|
||||
To send a request, you only need to import the `STSClient` and
|
||||
the commands you need, for example `GetCallerIdentityCommand`:
|
||||
|
||||
```js
|
||||
// ES5 example
|
||||
const { STSClient, GetCallerIdentityCommand } = require("@aws-sdk/client-sts");
|
||||
```
|
||||
|
||||
```ts
|
||||
// ES6+ example
|
||||
import { STSClient, GetCallerIdentityCommand } from "@aws-sdk/client-sts";
|
||||
```
|
||||
|
||||
### Usage
|
||||
|
||||
To send a request, you:
|
||||
|
||||
- Initiate client with configuration (e.g. credentials, region).
|
||||
- Initiate command with input parameters.
|
||||
- Call `send` operation on client with command object as input.
|
||||
- If you are using a custom http handler, you may call `destroy()` to close open connections.
|
||||
|
||||
```js
|
||||
// a client can be shared by different commands.
|
||||
const client = new STSClient({ region: "REGION" });
|
||||
|
||||
const params = {
|
||||
/** input parameters */
|
||||
};
|
||||
const command = new GetCallerIdentityCommand(params);
|
||||
```
|
||||
|
||||
#### Async/await
|
||||
|
||||
We recommend using [await](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/await)
|
||||
operator to wait for the promise returned by send operation as follows:
|
||||
|
||||
```js
|
||||
// async/await.
|
||||
try {
|
||||
const data = await client.send(command);
|
||||
// process data.
|
||||
} catch (error) {
|
||||
// error handling.
|
||||
} finally {
|
||||
// finally.
|
||||
}
|
||||
```
|
||||
|
||||
Async-await is clean, concise, intuitive, easy to debug and has better error handling
|
||||
as compared to using Promise chains or callbacks.
|
||||
|
||||
#### Promises
|
||||
|
||||
You can also use [Promise chaining](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Guide/Using_promises#chaining)
|
||||
to execute send operation.
|
||||
|
||||
```js
|
||||
client.send(command).then(
|
||||
(data) => {
|
||||
// process data.
|
||||
},
|
||||
(error) => {
|
||||
// error handling.
|
||||
}
|
||||
);
|
||||
```
|
||||
|
||||
Promises can also be called using `.catch()` and `.finally()` as follows:
|
||||
|
||||
```js
|
||||
client
|
||||
.send(command)
|
||||
.then((data) => {
|
||||
// process data.
|
||||
})
|
||||
.catch((error) => {
|
||||
// error handling.
|
||||
})
|
||||
.finally(() => {
|
||||
// finally.
|
||||
});
|
||||
```
|
||||
|
||||
#### Callbacks
|
||||
|
||||
We do not recommend using callbacks because of [callback hell](http://callbackhell.com/),
|
||||
but they are supported by the send operation.
|
||||
|
||||
```js
|
||||
// callbacks.
|
||||
client.send(command, (err, data) => {
|
||||
// process err and data.
|
||||
});
|
||||
```
|
||||
|
||||
#### v2 compatible style
|
||||
|
||||
The client can also send requests using v2 compatible style.
|
||||
However, it results in a bigger bundle size and may be dropped in next major version. More details in the blog post
|
||||
on [modular packages in AWS SDK for JavaScript](https://aws.amazon.com/blogs/developer/modular-packages-in-aws-sdk-for-javascript/)
|
||||
|
||||
```ts
|
||||
import * as AWS from "@aws-sdk/client-sts";
|
||||
const client = new AWS.STS({ region: "REGION" });
|
||||
|
||||
// async/await.
|
||||
try {
|
||||
const data = await client.getCallerIdentity(params);
|
||||
// process data.
|
||||
} catch (error) {
|
||||
// error handling.
|
||||
}
|
||||
|
||||
// Promises.
|
||||
client
|
||||
.getCallerIdentity(params)
|
||||
.then((data) => {
|
||||
// process data.
|
||||
})
|
||||
.catch((error) => {
|
||||
// error handling.
|
||||
});
|
||||
|
||||
// callbacks.
|
||||
client.getCallerIdentity(params, (err, data) => {
|
||||
// process err and data.
|
||||
});
|
||||
```
|
||||
|
||||
### Troubleshooting
|
||||
|
||||
When the service returns an exception, the error will include the exception information,
|
||||
as well as response metadata (e.g. request id).
|
||||
|
||||
```js
|
||||
try {
|
||||
const data = await client.send(command);
|
||||
// process data.
|
||||
} catch (error) {
|
||||
const { requestId, cfId, extendedRequestId } = error.$metadata;
|
||||
console.log({ requestId, cfId, extendedRequestId });
|
||||
/**
|
||||
* The keys within exceptions are also parsed.
|
||||
* You can access them by specifying exception names:
|
||||
* if (error.name === 'SomeServiceException') {
|
||||
* const value = error.specialKeyInException;
|
||||
* }
|
||||
*/
|
||||
}
|
||||
```
|
||||
|
||||
## Getting Help
|
||||
|
||||
Please use these community resources for getting help.
|
||||
We use the GitHub issues for tracking bugs and feature requests, but have limited bandwidth to address them.
|
||||
|
||||
- Visit [Developer Guide](https://docs.aws.amazon.com/sdk-for-javascript/v3/developer-guide/welcome.html)
|
||||
or [API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/index.html).
|
||||
- Check out the blog posts tagged with [`aws-sdk-js`](https://aws.amazon.com/blogs/developer/tag/aws-sdk-js/)
|
||||
on AWS Developer Blog.
|
||||
- Ask a question on [StackOverflow](https://stackoverflow.com/questions/tagged/aws-sdk-js) and tag it with `aws-sdk-js`.
|
||||
- Join the AWS JavaScript community on [gitter](https://gitter.im/aws/aws-sdk-js-v3).
|
||||
- If it turns out that you may have found a bug, please [open an issue](https://github.com/aws/aws-sdk-js-v3/issues/new/choose).
|
||||
|
||||
To test your universal JavaScript code in Node.js, browser and react-native environments,
|
||||
visit our [code samples repo](https://github.com/aws-samples/aws-sdk-js-tests).
|
||||
|
||||
## Contributing
|
||||
|
||||
This client code is generated automatically. Any modifications will be overwritten the next time the `@aws-sdk/client-sts` package is updated.
|
||||
To contribute to client you can check our [generate clients scripts](https://github.com/aws/aws-sdk-js-v3/tree/main/scripts/generate-clients).
|
||||
|
||||
## License
|
||||
|
||||
This SDK is distributed under the
|
||||
[Apache License, Version 2.0](http://www.apache.org/licenses/LICENSE-2.0),
|
||||
see LICENSE for more information.
|
||||
|
||||
## Client Commands (Operations List)
|
||||
|
||||
<details>
|
||||
<summary>
|
||||
AssumeRole
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/assumerolecommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolecommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolecommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
AssumeRoleWithSAML
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/assumerolewithsamlcommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolewithsamlcommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolewithsamlcommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
AssumeRoleWithWebIdentity
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/assumerolewithwebidentitycommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolewithwebidentitycommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/assumerolewithwebidentitycommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
DecodeAuthorizationMessage
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/decodeauthorizationmessagecommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/decodeauthorizationmessagecommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/decodeauthorizationmessagecommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
GetAccessKeyInfo
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/getaccesskeyinfocommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getaccesskeyinfocommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getaccesskeyinfocommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
GetCallerIdentity
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/getcalleridentitycommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getcalleridentitycommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getcalleridentitycommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
GetFederationToken
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/getfederationtokencommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getfederationtokencommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getfederationtokencommandoutput.html)
|
||||
|
||||
</details>
|
||||
<details>
|
||||
<summary>
|
||||
GetSessionToken
|
||||
</summary>
|
||||
|
||||
[Command API Reference](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/classes/getsessiontokencommand.html) / [Input](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getsessiontokencommandinput.html) / [Output](https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/clients/client-sts/interfaces/getsessiontokencommandoutput.html)
|
||||
|
||||
</details>
|
||||
-27
@@ -1,27 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.STS = void 0;
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const AssumeRoleCommand_1 = require("./commands/AssumeRoleCommand");
|
||||
const AssumeRoleWithSAMLCommand_1 = require("./commands/AssumeRoleWithSAMLCommand");
|
||||
const AssumeRoleWithWebIdentityCommand_1 = require("./commands/AssumeRoleWithWebIdentityCommand");
|
||||
const DecodeAuthorizationMessageCommand_1 = require("./commands/DecodeAuthorizationMessageCommand");
|
||||
const GetAccessKeyInfoCommand_1 = require("./commands/GetAccessKeyInfoCommand");
|
||||
const GetCallerIdentityCommand_1 = require("./commands/GetCallerIdentityCommand");
|
||||
const GetFederationTokenCommand_1 = require("./commands/GetFederationTokenCommand");
|
||||
const GetSessionTokenCommand_1 = require("./commands/GetSessionTokenCommand");
|
||||
const STSClient_1 = require("./STSClient");
|
||||
const commands = {
|
||||
AssumeRoleCommand: AssumeRoleCommand_1.AssumeRoleCommand,
|
||||
AssumeRoleWithSAMLCommand: AssumeRoleWithSAMLCommand_1.AssumeRoleWithSAMLCommand,
|
||||
AssumeRoleWithWebIdentityCommand: AssumeRoleWithWebIdentityCommand_1.AssumeRoleWithWebIdentityCommand,
|
||||
DecodeAuthorizationMessageCommand: DecodeAuthorizationMessageCommand_1.DecodeAuthorizationMessageCommand,
|
||||
GetAccessKeyInfoCommand: GetAccessKeyInfoCommand_1.GetAccessKeyInfoCommand,
|
||||
GetCallerIdentityCommand: GetCallerIdentityCommand_1.GetCallerIdentityCommand,
|
||||
GetFederationTokenCommand: GetFederationTokenCommand_1.GetFederationTokenCommand,
|
||||
GetSessionTokenCommand: GetSessionTokenCommand_1.GetSessionTokenCommand,
|
||||
};
|
||||
class STS extends STSClient_1.STSClient {
|
||||
}
|
||||
exports.STS = STS;
|
||||
(0, smithy_client_1.createAggregatedClient)(commands, STS);
|
||||
-42
@@ -1,42 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.STSClient = exports.__Client = void 0;
|
||||
const middleware_host_header_1 = require("@aws-sdk/middleware-host-header");
|
||||
const middleware_logger_1 = require("@aws-sdk/middleware-logger");
|
||||
const middleware_recursion_detection_1 = require("@aws-sdk/middleware-recursion-detection");
|
||||
const middleware_sdk_sts_1 = require("@aws-sdk/middleware-sdk-sts");
|
||||
const middleware_user_agent_1 = require("@aws-sdk/middleware-user-agent");
|
||||
const config_resolver_1 = require("@smithy/config-resolver");
|
||||
const middleware_content_length_1 = require("@smithy/middleware-content-length");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_retry_1 = require("@smithy/middleware-retry");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "__Client", { enumerable: true, get: function () { return smithy_client_1.Client; } });
|
||||
const EndpointParameters_1 = require("./endpoint/EndpointParameters");
|
||||
const runtimeConfig_1 = require("./runtimeConfig");
|
||||
const runtimeExtensions_1 = require("./runtimeExtensions");
|
||||
class STSClient extends smithy_client_1.Client {
|
||||
constructor(...[configuration]) {
|
||||
const _config_0 = (0, runtimeConfig_1.getRuntimeConfig)(configuration || {});
|
||||
const _config_1 = (0, EndpointParameters_1.resolveClientEndpointParameters)(_config_0);
|
||||
const _config_2 = (0, config_resolver_1.resolveRegionConfig)(_config_1);
|
||||
const _config_3 = (0, middleware_endpoint_1.resolveEndpointConfig)(_config_2);
|
||||
const _config_4 = (0, middleware_retry_1.resolveRetryConfig)(_config_3);
|
||||
const _config_5 = (0, middleware_host_header_1.resolveHostHeaderConfig)(_config_4);
|
||||
const _config_6 = (0, middleware_sdk_sts_1.resolveStsAuthConfig)(_config_5, { stsClientCtor: STSClient });
|
||||
const _config_7 = (0, middleware_user_agent_1.resolveUserAgentConfig)(_config_6);
|
||||
const _config_8 = (0, runtimeExtensions_1.resolveRuntimeExtensions)(_config_7, configuration?.extensions || []);
|
||||
super(_config_8);
|
||||
this.config = _config_8;
|
||||
this.middlewareStack.use((0, middleware_retry_1.getRetryPlugin)(this.config));
|
||||
this.middlewareStack.use((0, middleware_content_length_1.getContentLengthPlugin)(this.config));
|
||||
this.middlewareStack.use((0, middleware_host_header_1.getHostHeaderPlugin)(this.config));
|
||||
this.middlewareStack.use((0, middleware_logger_1.getLoggerPlugin)(this.config));
|
||||
this.middlewareStack.use((0, middleware_recursion_detection_1.getRecursionDetectionPlugin)(this.config));
|
||||
this.middlewareStack.use((0, middleware_user_agent_1.getUserAgentPlugin)(this.config));
|
||||
}
|
||||
destroy() {
|
||||
super.destroy();
|
||||
}
|
||||
}
|
||||
exports.STSClient = STSClient;
|
||||
-55
@@ -1,55 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.AssumeRoleCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const models_0_1 = require("../models/models_0");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class AssumeRoleCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, AssumeRoleCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: models_0_1.AssumeRoleResponseFilterSensitiveLog,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRole",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_AssumeRoleCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_AssumeRoleCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.AssumeRoleCommand = AssumeRoleCommand;
|
||||
-53
@@ -1,53 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.AssumeRoleWithSAMLCommand = exports.$Command = void 0;
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const models_0_1 = require("../models/models_0");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class AssumeRoleWithSAMLCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, AssumeRoleWithSAMLCommand.getEndpointParameterInstructions()));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleWithSAMLCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: models_0_1.AssumeRoleWithSAMLRequestFilterSensitiveLog,
|
||||
outputFilterSensitiveLog: models_0_1.AssumeRoleWithSAMLResponseFilterSensitiveLog,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRoleWithSAML",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_AssumeRoleWithSAMLCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_AssumeRoleWithSAMLCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.AssumeRoleWithSAMLCommand = AssumeRoleWithSAMLCommand;
|
||||
Generated
Vendored
-53
@@ -1,53 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.AssumeRoleWithWebIdentityCommand = exports.$Command = void 0;
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const models_0_1 = require("../models/models_0");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class AssumeRoleWithWebIdentityCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, AssumeRoleWithWebIdentityCommand.getEndpointParameterInstructions()));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleWithWebIdentityCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: models_0_1.AssumeRoleWithWebIdentityRequestFilterSensitiveLog,
|
||||
outputFilterSensitiveLog: models_0_1.AssumeRoleWithWebIdentityResponseFilterSensitiveLog,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRoleWithWebIdentity",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_AssumeRoleWithWebIdentityCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_AssumeRoleWithWebIdentityCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.AssumeRoleWithWebIdentityCommand = AssumeRoleWithWebIdentityCommand;
|
||||
Generated
Vendored
-54
@@ -1,54 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.DecodeAuthorizationMessageCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class DecodeAuthorizationMessageCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, DecodeAuthorizationMessageCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "DecodeAuthorizationMessageCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "DecodeAuthorizationMessage",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_DecodeAuthorizationMessageCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_DecodeAuthorizationMessageCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.DecodeAuthorizationMessageCommand = DecodeAuthorizationMessageCommand;
|
||||
-54
@@ -1,54 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.GetAccessKeyInfoCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class GetAccessKeyInfoCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, GetAccessKeyInfoCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetAccessKeyInfoCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetAccessKeyInfo",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_GetAccessKeyInfoCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_GetAccessKeyInfoCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.GetAccessKeyInfoCommand = GetAccessKeyInfoCommand;
|
||||
-54
@@ -1,54 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.GetCallerIdentityCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class GetCallerIdentityCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, GetCallerIdentityCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetCallerIdentityCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetCallerIdentity",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_GetCallerIdentityCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_GetCallerIdentityCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.GetCallerIdentityCommand = GetCallerIdentityCommand;
|
||||
-55
@@ -1,55 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.GetFederationTokenCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const models_0_1 = require("../models/models_0");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class GetFederationTokenCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, GetFederationTokenCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetFederationTokenCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: models_0_1.GetFederationTokenResponseFilterSensitiveLog,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetFederationToken",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_GetFederationTokenCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_GetFederationTokenCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.GetFederationTokenCommand = GetFederationTokenCommand;
|
||||
-55
@@ -1,55 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.GetSessionTokenCommand = exports.$Command = void 0;
|
||||
const middleware_signing_1 = require("@aws-sdk/middleware-signing");
|
||||
const middleware_endpoint_1 = require("@smithy/middleware-endpoint");
|
||||
const middleware_serde_1 = require("@smithy/middleware-serde");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "$Command", { enumerable: true, get: function () { return smithy_client_1.Command; } });
|
||||
const types_1 = require("@smithy/types");
|
||||
const models_0_1 = require("../models/models_0");
|
||||
const Aws_query_1 = require("../protocols/Aws_query");
|
||||
class GetSessionTokenCommand extends smithy_client_1.Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use((0, middleware_serde_1.getSerdePlugin)(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use((0, middleware_endpoint_1.getEndpointPlugin)(configuration, GetSessionTokenCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use((0, middleware_signing_1.getAwsAuthPlugin)(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetSessionTokenCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: models_0_1.GetSessionTokenResponseFilterSensitiveLog,
|
||||
[types_1.SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetSessionToken",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return (0, Aws_query_1.se_GetSessionTokenCommand)(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return (0, Aws_query_1.de_GetSessionTokenCommand)(output, context);
|
||||
}
|
||||
}
|
||||
exports.GetSessionTokenCommand = GetSessionTokenCommand;
|
||||
-11
@@ -1,11 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
const tslib_1 = require("tslib");
|
||||
tslib_1.__exportStar(require("./AssumeRoleCommand"), exports);
|
||||
tslib_1.__exportStar(require("./AssumeRoleWithSAMLCommand"), exports);
|
||||
tslib_1.__exportStar(require("./AssumeRoleWithWebIdentityCommand"), exports);
|
||||
tslib_1.__exportStar(require("./DecodeAuthorizationMessageCommand"), exports);
|
||||
tslib_1.__exportStar(require("./GetAccessKeyInfoCommand"), exports);
|
||||
tslib_1.__exportStar(require("./GetCallerIdentityCommand"), exports);
|
||||
tslib_1.__exportStar(require("./GetFederationTokenCommand"), exports);
|
||||
tslib_1.__exportStar(require("./GetSessionTokenCommand"), exports);
|
||||
-28
@@ -1,28 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.decorateDefaultCredentialProvider = exports.getDefaultRoleAssumerWithWebIdentity = exports.getDefaultRoleAssumer = void 0;
|
||||
const defaultStsRoleAssumers_1 = require("./defaultStsRoleAssumers");
|
||||
const STSClient_1 = require("./STSClient");
|
||||
const getCustomizableStsClientCtor = (baseCtor, customizations) => {
|
||||
if (!customizations)
|
||||
return baseCtor;
|
||||
else
|
||||
return class CustomizableSTSClient extends baseCtor {
|
||||
constructor(config) {
|
||||
super(config);
|
||||
for (const customization of customizations) {
|
||||
this.middlewareStack.use(customization);
|
||||
}
|
||||
}
|
||||
};
|
||||
};
|
||||
const getDefaultRoleAssumer = (stsOptions = {}, stsPlugins) => (0, defaultStsRoleAssumers_1.getDefaultRoleAssumer)(stsOptions, getCustomizableStsClientCtor(STSClient_1.STSClient, stsPlugins));
|
||||
exports.getDefaultRoleAssumer = getDefaultRoleAssumer;
|
||||
const getDefaultRoleAssumerWithWebIdentity = (stsOptions = {}, stsPlugins) => (0, defaultStsRoleAssumers_1.getDefaultRoleAssumerWithWebIdentity)(stsOptions, getCustomizableStsClientCtor(STSClient_1.STSClient, stsPlugins));
|
||||
exports.getDefaultRoleAssumerWithWebIdentity = getDefaultRoleAssumerWithWebIdentity;
|
||||
const decorateDefaultCredentialProvider = (provider) => (input) => provider({
|
||||
roleAssumer: (0, exports.getDefaultRoleAssumer)(input),
|
||||
roleAssumerWithWebIdentity: (0, exports.getDefaultRoleAssumerWithWebIdentity)(input),
|
||||
...input,
|
||||
});
|
||||
exports.decorateDefaultCredentialProvider = decorateDefaultCredentialProvider;
|
||||
-76
@@ -1,76 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.decorateDefaultCredentialProvider = exports.getDefaultRoleAssumerWithWebIdentity = exports.getDefaultRoleAssumer = void 0;
|
||||
const AssumeRoleCommand_1 = require("./commands/AssumeRoleCommand");
|
||||
const AssumeRoleWithWebIdentityCommand_1 = require("./commands/AssumeRoleWithWebIdentityCommand");
|
||||
const ASSUME_ROLE_DEFAULT_REGION = "us-east-1";
|
||||
const decorateDefaultRegion = (region) => {
|
||||
if (typeof region !== "function") {
|
||||
return region === undefined ? ASSUME_ROLE_DEFAULT_REGION : region;
|
||||
}
|
||||
return async () => {
|
||||
try {
|
||||
return await region();
|
||||
}
|
||||
catch (e) {
|
||||
return ASSUME_ROLE_DEFAULT_REGION;
|
||||
}
|
||||
};
|
||||
};
|
||||
const getDefaultRoleAssumer = (stsOptions, stsClientCtor) => {
|
||||
let stsClient;
|
||||
let closureSourceCreds;
|
||||
return async (sourceCreds, params) => {
|
||||
closureSourceCreds = sourceCreds;
|
||||
if (!stsClient) {
|
||||
const { logger, region, requestHandler } = stsOptions;
|
||||
stsClient = new stsClientCtor({
|
||||
logger,
|
||||
credentialDefaultProvider: () => async () => closureSourceCreds,
|
||||
region: decorateDefaultRegion(region || stsOptions.region),
|
||||
...(requestHandler ? { requestHandler } : {}),
|
||||
});
|
||||
}
|
||||
const { Credentials } = await stsClient.send(new AssumeRoleCommand_1.AssumeRoleCommand(params));
|
||||
if (!Credentials || !Credentials.AccessKeyId || !Credentials.SecretAccessKey) {
|
||||
throw new Error(`Invalid response from STS.assumeRole call with role ${params.RoleArn}`);
|
||||
}
|
||||
return {
|
||||
accessKeyId: Credentials.AccessKeyId,
|
||||
secretAccessKey: Credentials.SecretAccessKey,
|
||||
sessionToken: Credentials.SessionToken,
|
||||
expiration: Credentials.Expiration,
|
||||
};
|
||||
};
|
||||
};
|
||||
exports.getDefaultRoleAssumer = getDefaultRoleAssumer;
|
||||
const getDefaultRoleAssumerWithWebIdentity = (stsOptions, stsClientCtor) => {
|
||||
let stsClient;
|
||||
return async (params) => {
|
||||
if (!stsClient) {
|
||||
const { logger, region, requestHandler } = stsOptions;
|
||||
stsClient = new stsClientCtor({
|
||||
logger,
|
||||
region: decorateDefaultRegion(region || stsOptions.region),
|
||||
...(requestHandler ? { requestHandler } : {}),
|
||||
});
|
||||
}
|
||||
const { Credentials } = await stsClient.send(new AssumeRoleWithWebIdentityCommand_1.AssumeRoleWithWebIdentityCommand(params));
|
||||
if (!Credentials || !Credentials.AccessKeyId || !Credentials.SecretAccessKey) {
|
||||
throw new Error(`Invalid response from STS.assumeRoleWithWebIdentity call with role ${params.RoleArn}`);
|
||||
}
|
||||
return {
|
||||
accessKeyId: Credentials.AccessKeyId,
|
||||
secretAccessKey: Credentials.SecretAccessKey,
|
||||
sessionToken: Credentials.SessionToken,
|
||||
expiration: Credentials.Expiration,
|
||||
};
|
||||
};
|
||||
};
|
||||
exports.getDefaultRoleAssumerWithWebIdentity = getDefaultRoleAssumerWithWebIdentity;
|
||||
const decorateDefaultCredentialProvider = (provider) => (input) => provider({
|
||||
roleAssumer: (0, exports.getDefaultRoleAssumer)(input, input.stsClientCtor),
|
||||
roleAssumerWithWebIdentity: (0, exports.getDefaultRoleAssumerWithWebIdentity)(input, input.stsClientCtor),
|
||||
...input,
|
||||
});
|
||||
exports.decorateDefaultCredentialProvider = decorateDefaultCredentialProvider;
|
||||
-13
@@ -1,13 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.resolveClientEndpointParameters = void 0;
|
||||
const resolveClientEndpointParameters = (options) => {
|
||||
return {
|
||||
...options,
|
||||
useDualstackEndpoint: options.useDualstackEndpoint ?? false,
|
||||
useFipsEndpoint: options.useFipsEndpoint ?? false,
|
||||
useGlobalEndpoint: options.useGlobalEndpoint ?? false,
|
||||
defaultSigningName: "sts",
|
||||
};
|
||||
};
|
||||
exports.resolveClientEndpointParameters = resolveClientEndpointParameters;
|
||||
-12
@@ -1,12 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.defaultEndpointResolver = void 0;
|
||||
const util_endpoints_1 = require("@smithy/util-endpoints");
|
||||
const ruleset_1 = require("./ruleset");
|
||||
const defaultEndpointResolver = (endpointParams, context = {}) => {
|
||||
return (0, util_endpoints_1.resolveEndpoint)(ruleset_1.ruleSet, {
|
||||
endpointParams: endpointParams,
|
||||
logger: context.logger,
|
||||
});
|
||||
};
|
||||
exports.defaultEndpointResolver = defaultEndpointResolver;
|
||||
-7
@@ -1,7 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.ruleSet = void 0;
|
||||
const F = "required", G = "type", H = "fn", I = "argv", J = "ref";
|
||||
const a = false, b = true, c = "booleanEquals", d = "stringEquals", e = "sigv4", f = "sts", g = "us-east-1", h = "endpoint", i = "https://sts.{Region}.{PartitionResult#dnsSuffix}", j = "tree", k = "error", l = "getAttr", m = { [F]: false, [G]: "String" }, n = { [F]: true, "default": false, [G]: "Boolean" }, o = { [J]: "Endpoint" }, p = { [H]: "isSet", [I]: [{ [J]: "Region" }] }, q = { [J]: "Region" }, r = { [H]: "aws.partition", [I]: [q], "assign": "PartitionResult" }, s = { [J]: "UseFIPS" }, t = { [J]: "UseDualStack" }, u = { "url": "https://sts.amazonaws.com", "properties": { "authSchemes": [{ "name": e, "signingName": f, "signingRegion": g }] }, "headers": {} }, v = {}, w = { "conditions": [{ [H]: d, [I]: [q, "aws-global"] }], [h]: u, [G]: h }, x = { [H]: c, [I]: [s, true] }, y = { [H]: c, [I]: [t, true] }, z = { [H]: l, [I]: [{ [J]: "PartitionResult" }, "supportsFIPS"] }, A = { [J]: "PartitionResult" }, B = { [H]: c, [I]: [true, { [H]: l, [I]: [A, "supportsDualStack"] }] }, C = [{ [H]: "isSet", [I]: [o] }], D = [x], E = [y];
|
||||
const _data = { version: "1.0", parameters: { Region: m, UseDualStack: n, UseFIPS: n, Endpoint: m, UseGlobalEndpoint: n }, rules: [{ conditions: [{ [H]: c, [I]: [{ [J]: "UseGlobalEndpoint" }, b] }, { [H]: "not", [I]: C }, p, r, { [H]: c, [I]: [s, a] }, { [H]: c, [I]: [t, a] }], rules: [{ conditions: [{ [H]: d, [I]: [q, "ap-northeast-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-south-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-southeast-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-southeast-2"] }], endpoint: u, [G]: h }, w, { conditions: [{ [H]: d, [I]: [q, "ca-central-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-central-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-north-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-2"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-3"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "sa-east-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, g] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-east-2"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-west-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-west-2"] }], endpoint: u, [G]: h }, { endpoint: { url: i, properties: { authSchemes: [{ name: e, signingName: f, signingRegion: "{Region}" }] }, headers: v }, [G]: h }], [G]: j }, { conditions: C, rules: [{ conditions: D, error: "Invalid Configuration: FIPS and custom endpoint are not supported", [G]: k }, { conditions: E, error: "Invalid Configuration: Dualstack and custom endpoint are not supported", [G]: k }, { endpoint: { url: o, properties: v, headers: v }, [G]: h }], [G]: j }, { conditions: [p], rules: [{ conditions: [r], rules: [{ conditions: [x, y], rules: [{ conditions: [{ [H]: c, [I]: [b, z] }, B], rules: [{ endpoint: { url: "https://sts-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "FIPS and DualStack are enabled, but this partition does not support one or both", [G]: k }], [G]: j }, { conditions: D, rules: [{ conditions: [{ [H]: c, [I]: [z, b] }], rules: [{ conditions: [{ [H]: d, [I]: [{ [H]: l, [I]: [A, "name"] }, "aws-us-gov"] }], endpoint: { url: "https://sts.{Region}.amazonaws.com", properties: v, headers: v }, [G]: h }, { endpoint: { url: "https://sts-fips.{Region}.{PartitionResult#dnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "FIPS is enabled but this partition does not support FIPS", [G]: k }], [G]: j }, { conditions: E, rules: [{ conditions: [B], rules: [{ endpoint: { url: "https://sts.{Region}.{PartitionResult#dualStackDnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "DualStack is enabled but this partition does not support DualStack", [G]: k }], [G]: j }, w, { endpoint: { url: i, properties: v, headers: v }, [G]: h }], [G]: j }], [G]: j }, { error: "Invalid Configuration: Missing Region", [G]: k }] };
|
||||
exports.ruleSet = _data;
|
||||
-2
@@ -1,2 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
-12
@@ -1,12 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.STSServiceException = void 0;
|
||||
const tslib_1 = require("tslib");
|
||||
tslib_1.__exportStar(require("./STSClient"), exports);
|
||||
tslib_1.__exportStar(require("./STS"), exports);
|
||||
tslib_1.__exportStar(require("./commands"), exports);
|
||||
tslib_1.__exportStar(require("./models"), exports);
|
||||
tslib_1.__exportStar(require("./defaultRoleAssumers"), exports);
|
||||
require("@aws-sdk/util-endpoints");
|
||||
var STSServiceException_1 = require("./models/STSServiceException");
|
||||
Object.defineProperty(exports, "STSServiceException", { enumerable: true, get: function () { return STSServiceException_1.STSServiceException; } });
|
||||
-12
@@ -1,12 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.STSServiceException = exports.__ServiceException = void 0;
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
Object.defineProperty(exports, "__ServiceException", { enumerable: true, get: function () { return smithy_client_1.ServiceException; } });
|
||||
class STSServiceException extends smithy_client_1.ServiceException {
|
||||
constructor(options) {
|
||||
super(options);
|
||||
Object.setPrototypeOf(this, STSServiceException.prototype);
|
||||
}
|
||||
}
|
||||
exports.STSServiceException = STSServiceException;
|
||||
-4
@@ -1,4 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
const tslib_1 = require("tslib");
|
||||
tslib_1.__exportStar(require("./models_0"), exports);
|
||||
-149
@@ -1,149 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.GetSessionTokenResponseFilterSensitiveLog = exports.GetFederationTokenResponseFilterSensitiveLog = exports.AssumeRoleWithWebIdentityResponseFilterSensitiveLog = exports.AssumeRoleWithWebIdentityRequestFilterSensitiveLog = exports.AssumeRoleWithSAMLResponseFilterSensitiveLog = exports.AssumeRoleWithSAMLRequestFilterSensitiveLog = exports.AssumeRoleResponseFilterSensitiveLog = exports.CredentialsFilterSensitiveLog = exports.InvalidAuthorizationMessageException = exports.IDPCommunicationErrorException = exports.InvalidIdentityTokenException = exports.IDPRejectedClaimException = exports.RegionDisabledException = exports.PackedPolicyTooLargeException = exports.MalformedPolicyDocumentException = exports.ExpiredTokenException = void 0;
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const STSServiceException_1 = require("./STSServiceException");
|
||||
class ExpiredTokenException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "ExpiredTokenException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "ExpiredTokenException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, ExpiredTokenException.prototype);
|
||||
}
|
||||
}
|
||||
exports.ExpiredTokenException = ExpiredTokenException;
|
||||
class MalformedPolicyDocumentException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "MalformedPolicyDocumentException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "MalformedPolicyDocumentException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, MalformedPolicyDocumentException.prototype);
|
||||
}
|
||||
}
|
||||
exports.MalformedPolicyDocumentException = MalformedPolicyDocumentException;
|
||||
class PackedPolicyTooLargeException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "PackedPolicyTooLargeException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "PackedPolicyTooLargeException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, PackedPolicyTooLargeException.prototype);
|
||||
}
|
||||
}
|
||||
exports.PackedPolicyTooLargeException = PackedPolicyTooLargeException;
|
||||
class RegionDisabledException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "RegionDisabledException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "RegionDisabledException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, RegionDisabledException.prototype);
|
||||
}
|
||||
}
|
||||
exports.RegionDisabledException = RegionDisabledException;
|
||||
class IDPRejectedClaimException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "IDPRejectedClaimException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "IDPRejectedClaimException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, IDPRejectedClaimException.prototype);
|
||||
}
|
||||
}
|
||||
exports.IDPRejectedClaimException = IDPRejectedClaimException;
|
||||
class InvalidIdentityTokenException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "InvalidIdentityTokenException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "InvalidIdentityTokenException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, InvalidIdentityTokenException.prototype);
|
||||
}
|
||||
}
|
||||
exports.InvalidIdentityTokenException = InvalidIdentityTokenException;
|
||||
class IDPCommunicationErrorException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "IDPCommunicationErrorException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "IDPCommunicationErrorException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, IDPCommunicationErrorException.prototype);
|
||||
}
|
||||
}
|
||||
exports.IDPCommunicationErrorException = IDPCommunicationErrorException;
|
||||
class InvalidAuthorizationMessageException extends STSServiceException_1.STSServiceException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "InvalidAuthorizationMessageException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "InvalidAuthorizationMessageException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, InvalidAuthorizationMessageException.prototype);
|
||||
}
|
||||
}
|
||||
exports.InvalidAuthorizationMessageException = InvalidAuthorizationMessageException;
|
||||
const CredentialsFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.SecretAccessKey && { SecretAccessKey: smithy_client_1.SENSITIVE_STRING }),
|
||||
});
|
||||
exports.CredentialsFilterSensitiveLog = CredentialsFilterSensitiveLog;
|
||||
const AssumeRoleResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: (0, exports.CredentialsFilterSensitiveLog)(obj.Credentials) }),
|
||||
});
|
||||
exports.AssumeRoleResponseFilterSensitiveLog = AssumeRoleResponseFilterSensitiveLog;
|
||||
const AssumeRoleWithSAMLRequestFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.SAMLAssertion && { SAMLAssertion: smithy_client_1.SENSITIVE_STRING }),
|
||||
});
|
||||
exports.AssumeRoleWithSAMLRequestFilterSensitiveLog = AssumeRoleWithSAMLRequestFilterSensitiveLog;
|
||||
const AssumeRoleWithSAMLResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: (0, exports.CredentialsFilterSensitiveLog)(obj.Credentials) }),
|
||||
});
|
||||
exports.AssumeRoleWithSAMLResponseFilterSensitiveLog = AssumeRoleWithSAMLResponseFilterSensitiveLog;
|
||||
const AssumeRoleWithWebIdentityRequestFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.WebIdentityToken && { WebIdentityToken: smithy_client_1.SENSITIVE_STRING }),
|
||||
});
|
||||
exports.AssumeRoleWithWebIdentityRequestFilterSensitiveLog = AssumeRoleWithWebIdentityRequestFilterSensitiveLog;
|
||||
const AssumeRoleWithWebIdentityResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: (0, exports.CredentialsFilterSensitiveLog)(obj.Credentials) }),
|
||||
});
|
||||
exports.AssumeRoleWithWebIdentityResponseFilterSensitiveLog = AssumeRoleWithWebIdentityResponseFilterSensitiveLog;
|
||||
const GetFederationTokenResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: (0, exports.CredentialsFilterSensitiveLog)(obj.Credentials) }),
|
||||
});
|
||||
exports.GetFederationTokenResponseFilterSensitiveLog = GetFederationTokenResponseFilterSensitiveLog;
|
||||
const GetSessionTokenResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: (0, exports.CredentialsFilterSensitiveLog)(obj.Credentials) }),
|
||||
});
|
||||
exports.GetSessionTokenResponseFilterSensitiveLog = GetSessionTokenResponseFilterSensitiveLog;
|
||||
-1028
File diff suppressed because it is too large
Load Diff
-39
@@ -1,39 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.getRuntimeConfig = void 0;
|
||||
const tslib_1 = require("tslib");
|
||||
const package_json_1 = tslib_1.__importDefault(require("../package.json"));
|
||||
const sha256_browser_1 = require("@aws-crypto/sha256-browser");
|
||||
const util_user_agent_browser_1 = require("@aws-sdk/util-user-agent-browser");
|
||||
const config_resolver_1 = require("@smithy/config-resolver");
|
||||
const fetch_http_handler_1 = require("@smithy/fetch-http-handler");
|
||||
const invalid_dependency_1 = require("@smithy/invalid-dependency");
|
||||
const util_body_length_browser_1 = require("@smithy/util-body-length-browser");
|
||||
const util_retry_1 = require("@smithy/util-retry");
|
||||
const runtimeConfig_shared_1 = require("./runtimeConfig.shared");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const util_defaults_mode_browser_1 = require("@smithy/util-defaults-mode-browser");
|
||||
const getRuntimeConfig = (config) => {
|
||||
const defaultsMode = (0, util_defaults_mode_browser_1.resolveDefaultsModeConfig)(config);
|
||||
const defaultConfigProvider = () => defaultsMode().then(smithy_client_1.loadConfigsForDefaultMode);
|
||||
const clientSharedValues = (0, runtimeConfig_shared_1.getRuntimeConfig)(config);
|
||||
return {
|
||||
...clientSharedValues,
|
||||
...config,
|
||||
runtime: "browser",
|
||||
defaultsMode,
|
||||
bodyLengthChecker: config?.bodyLengthChecker ?? util_body_length_browser_1.calculateBodyLength,
|
||||
credentialDefaultProvider: config?.credentialDefaultProvider ?? ((_) => () => Promise.reject(new Error("Credential is missing"))),
|
||||
defaultUserAgentProvider: config?.defaultUserAgentProvider ??
|
||||
(0, util_user_agent_browser_1.defaultUserAgent)({ serviceId: clientSharedValues.serviceId, clientVersion: package_json_1.default.version }),
|
||||
maxAttempts: config?.maxAttempts ?? util_retry_1.DEFAULT_MAX_ATTEMPTS,
|
||||
region: config?.region ?? (0, invalid_dependency_1.invalidProvider)("Region is missing"),
|
||||
requestHandler: config?.requestHandler ?? new fetch_http_handler_1.FetchHttpHandler(defaultConfigProvider),
|
||||
retryMode: config?.retryMode ?? (async () => (await defaultConfigProvider()).retryMode || util_retry_1.DEFAULT_RETRY_MODE),
|
||||
sha256: config?.sha256 ?? sha256_browser_1.Sha256,
|
||||
streamCollector: config?.streamCollector ?? fetch_http_handler_1.streamCollector,
|
||||
useDualstackEndpoint: config?.useDualstackEndpoint ?? (() => Promise.resolve(config_resolver_1.DEFAULT_USE_DUALSTACK_ENDPOINT)),
|
||||
useFipsEndpoint: config?.useFipsEndpoint ?? (() => Promise.resolve(config_resolver_1.DEFAULT_USE_FIPS_ENDPOINT)),
|
||||
};
|
||||
};
|
||||
exports.getRuntimeConfig = getRuntimeConfig;
|
||||
-50
@@ -1,50 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.getRuntimeConfig = void 0;
|
||||
const tslib_1 = require("tslib");
|
||||
const package_json_1 = tslib_1.__importDefault(require("../package.json"));
|
||||
const defaultStsRoleAssumers_1 = require("./defaultStsRoleAssumers");
|
||||
const core_1 = require("@aws-sdk/core");
|
||||
const credential_provider_node_1 = require("@aws-sdk/credential-provider-node");
|
||||
const util_user_agent_node_1 = require("@aws-sdk/util-user-agent-node");
|
||||
const config_resolver_1 = require("@smithy/config-resolver");
|
||||
const hash_node_1 = require("@smithy/hash-node");
|
||||
const middleware_retry_1 = require("@smithy/middleware-retry");
|
||||
const node_config_provider_1 = require("@smithy/node-config-provider");
|
||||
const node_http_handler_1 = require("@smithy/node-http-handler");
|
||||
const util_body_length_node_1 = require("@smithy/util-body-length-node");
|
||||
const util_retry_1 = require("@smithy/util-retry");
|
||||
const runtimeConfig_shared_1 = require("./runtimeConfig.shared");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const util_defaults_mode_node_1 = require("@smithy/util-defaults-mode-node");
|
||||
const smithy_client_2 = require("@smithy/smithy-client");
|
||||
const getRuntimeConfig = (config) => {
|
||||
(0, smithy_client_2.emitWarningIfUnsupportedVersion)(process.version);
|
||||
const defaultsMode = (0, util_defaults_mode_node_1.resolveDefaultsModeConfig)(config);
|
||||
const defaultConfigProvider = () => defaultsMode().then(smithy_client_1.loadConfigsForDefaultMode);
|
||||
const clientSharedValues = (0, runtimeConfig_shared_1.getRuntimeConfig)(config);
|
||||
(0, core_1.emitWarningIfUnsupportedVersion)(process.version);
|
||||
return {
|
||||
...clientSharedValues,
|
||||
...config,
|
||||
runtime: "node",
|
||||
defaultsMode,
|
||||
bodyLengthChecker: config?.bodyLengthChecker ?? util_body_length_node_1.calculateBodyLength,
|
||||
credentialDefaultProvider: config?.credentialDefaultProvider ?? (0, defaultStsRoleAssumers_1.decorateDefaultCredentialProvider)(credential_provider_node_1.defaultProvider),
|
||||
defaultUserAgentProvider: config?.defaultUserAgentProvider ??
|
||||
(0, util_user_agent_node_1.defaultUserAgent)({ serviceId: clientSharedValues.serviceId, clientVersion: package_json_1.default.version }),
|
||||
maxAttempts: config?.maxAttempts ?? (0, node_config_provider_1.loadConfig)(middleware_retry_1.NODE_MAX_ATTEMPT_CONFIG_OPTIONS),
|
||||
region: config?.region ?? (0, node_config_provider_1.loadConfig)(config_resolver_1.NODE_REGION_CONFIG_OPTIONS, config_resolver_1.NODE_REGION_CONFIG_FILE_OPTIONS),
|
||||
requestHandler: config?.requestHandler ?? new node_http_handler_1.NodeHttpHandler(defaultConfigProvider),
|
||||
retryMode: config?.retryMode ??
|
||||
(0, node_config_provider_1.loadConfig)({
|
||||
...middleware_retry_1.NODE_RETRY_MODE_CONFIG_OPTIONS,
|
||||
default: async () => (await defaultConfigProvider()).retryMode || util_retry_1.DEFAULT_RETRY_MODE,
|
||||
}),
|
||||
sha256: config?.sha256 ?? hash_node_1.Hash.bind(null, "sha256"),
|
||||
streamCollector: config?.streamCollector ?? node_http_handler_1.streamCollector,
|
||||
useDualstackEndpoint: config?.useDualstackEndpoint ?? (0, node_config_provider_1.loadConfig)(config_resolver_1.NODE_USE_DUALSTACK_ENDPOINT_CONFIG_OPTIONS),
|
||||
useFipsEndpoint: config?.useFipsEndpoint ?? (0, node_config_provider_1.loadConfig)(config_resolver_1.NODE_USE_FIPS_ENDPOINT_CONFIG_OPTIONS),
|
||||
};
|
||||
};
|
||||
exports.getRuntimeConfig = getRuntimeConfig;
|
||||
-15
@@ -1,15 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.getRuntimeConfig = void 0;
|
||||
const sha256_js_1 = require("@aws-crypto/sha256-js");
|
||||
const runtimeConfig_browser_1 = require("./runtimeConfig.browser");
|
||||
const getRuntimeConfig = (config) => {
|
||||
const browserDefaults = (0, runtimeConfig_browser_1.getRuntimeConfig)(config);
|
||||
return {
|
||||
...browserDefaults,
|
||||
...config,
|
||||
runtime: "react-native",
|
||||
sha256: config?.sha256 ?? sha256_js_1.Sha256,
|
||||
};
|
||||
};
|
||||
exports.getRuntimeConfig = getRuntimeConfig;
|
||||
-24
@@ -1,24 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.getRuntimeConfig = void 0;
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const url_parser_1 = require("@smithy/url-parser");
|
||||
const util_base64_1 = require("@smithy/util-base64");
|
||||
const util_utf8_1 = require("@smithy/util-utf8");
|
||||
const endpointResolver_1 = require("./endpoint/endpointResolver");
|
||||
const getRuntimeConfig = (config) => {
|
||||
return {
|
||||
apiVersion: "2011-06-15",
|
||||
base64Decoder: config?.base64Decoder ?? util_base64_1.fromBase64,
|
||||
base64Encoder: config?.base64Encoder ?? util_base64_1.toBase64,
|
||||
disableHostPrefix: config?.disableHostPrefix ?? false,
|
||||
endpointProvider: config?.endpointProvider ?? endpointResolver_1.defaultEndpointResolver,
|
||||
extensions: config?.extensions ?? [],
|
||||
logger: config?.logger ?? new smithy_client_1.NoOpLogger(),
|
||||
serviceId: config?.serviceId ?? "STS",
|
||||
urlParser: config?.urlParser ?? url_parser_1.parseUrl,
|
||||
utf8Decoder: config?.utf8Decoder ?? util_utf8_1.fromUtf8,
|
||||
utf8Encoder: config?.utf8Encoder ?? util_utf8_1.toUtf8,
|
||||
};
|
||||
};
|
||||
exports.getRuntimeConfig = getRuntimeConfig;
|
||||
-22
@@ -1,22 +0,0 @@
|
||||
"use strict";
|
||||
Object.defineProperty(exports, "__esModule", { value: true });
|
||||
exports.resolveRuntimeExtensions = void 0;
|
||||
const region_config_resolver_1 = require("@aws-sdk/region-config-resolver");
|
||||
const protocol_http_1 = require("@smithy/protocol-http");
|
||||
const smithy_client_1 = require("@smithy/smithy-client");
|
||||
const asPartial = (t) => t;
|
||||
const resolveRuntimeExtensions = (runtimeConfig, extensions) => {
|
||||
const extensionConfiguration = {
|
||||
...asPartial((0, region_config_resolver_1.getAwsRegionExtensionConfiguration)(runtimeConfig)),
|
||||
...asPartial((0, smithy_client_1.getDefaultExtensionConfiguration)(runtimeConfig)),
|
||||
...asPartial((0, protocol_http_1.getHttpHandlerExtensionConfiguration)(runtimeConfig)),
|
||||
};
|
||||
extensions.forEach((extension) => extension.configure(extensionConfiguration));
|
||||
return {
|
||||
...runtimeConfig,
|
||||
...(0, region_config_resolver_1.resolveAwsRegionExtensionConfiguration)(extensionConfiguration),
|
||||
...(0, smithy_client_1.resolveDefaultRuntimeConfig)(extensionConfiguration),
|
||||
...(0, protocol_http_1.resolveHttpHandlerRuntimeConfig)(extensionConfiguration),
|
||||
};
|
||||
};
|
||||
exports.resolveRuntimeExtensions = resolveRuntimeExtensions;
|
||||
-23
@@ -1,23 +0,0 @@
|
||||
import { createAggregatedClient } from "@smithy/smithy-client";
|
||||
import { AssumeRoleCommand } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithSAMLCommand, } from "./commands/AssumeRoleWithSAMLCommand";
|
||||
import { AssumeRoleWithWebIdentityCommand, } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import { DecodeAuthorizationMessageCommand, } from "./commands/DecodeAuthorizationMessageCommand";
|
||||
import { GetAccessKeyInfoCommand, } from "./commands/GetAccessKeyInfoCommand";
|
||||
import { GetCallerIdentityCommand, } from "./commands/GetCallerIdentityCommand";
|
||||
import { GetFederationTokenCommand, } from "./commands/GetFederationTokenCommand";
|
||||
import { GetSessionTokenCommand, } from "./commands/GetSessionTokenCommand";
|
||||
import { STSClient } from "./STSClient";
|
||||
const commands = {
|
||||
AssumeRoleCommand,
|
||||
AssumeRoleWithSAMLCommand,
|
||||
AssumeRoleWithWebIdentityCommand,
|
||||
DecodeAuthorizationMessageCommand,
|
||||
GetAccessKeyInfoCommand,
|
||||
GetCallerIdentityCommand,
|
||||
GetFederationTokenCommand,
|
||||
GetSessionTokenCommand,
|
||||
};
|
||||
export class STS extends STSClient {
|
||||
}
|
||||
createAggregatedClient(commands, STS);
|
||||
-38
@@ -1,38 +0,0 @@
|
||||
import { getHostHeaderPlugin, resolveHostHeaderConfig, } from "@aws-sdk/middleware-host-header";
|
||||
import { getLoggerPlugin } from "@aws-sdk/middleware-logger";
|
||||
import { getRecursionDetectionPlugin } from "@aws-sdk/middleware-recursion-detection";
|
||||
import { resolveStsAuthConfig } from "@aws-sdk/middleware-sdk-sts";
|
||||
import { getUserAgentPlugin, resolveUserAgentConfig, } from "@aws-sdk/middleware-user-agent";
|
||||
import { resolveRegionConfig } from "@smithy/config-resolver";
|
||||
import { getContentLengthPlugin } from "@smithy/middleware-content-length";
|
||||
import { resolveEndpointConfig } from "@smithy/middleware-endpoint";
|
||||
import { getRetryPlugin, resolveRetryConfig } from "@smithy/middleware-retry";
|
||||
import { Client as __Client, } from "@smithy/smithy-client";
|
||||
import { resolveClientEndpointParameters, } from "./endpoint/EndpointParameters";
|
||||
import { getRuntimeConfig as __getRuntimeConfig } from "./runtimeConfig";
|
||||
import { resolveRuntimeExtensions } from "./runtimeExtensions";
|
||||
export { __Client };
|
||||
export class STSClient extends __Client {
|
||||
constructor(...[configuration]) {
|
||||
const _config_0 = __getRuntimeConfig(configuration || {});
|
||||
const _config_1 = resolveClientEndpointParameters(_config_0);
|
||||
const _config_2 = resolveRegionConfig(_config_1);
|
||||
const _config_3 = resolveEndpointConfig(_config_2);
|
||||
const _config_4 = resolveRetryConfig(_config_3);
|
||||
const _config_5 = resolveHostHeaderConfig(_config_4);
|
||||
const _config_6 = resolveStsAuthConfig(_config_5, { stsClientCtor: STSClient });
|
||||
const _config_7 = resolveUserAgentConfig(_config_6);
|
||||
const _config_8 = resolveRuntimeExtensions(_config_7, configuration?.extensions || []);
|
||||
super(_config_8);
|
||||
this.config = _config_8;
|
||||
this.middlewareStack.use(getRetryPlugin(this.config));
|
||||
this.middlewareStack.use(getContentLengthPlugin(this.config));
|
||||
this.middlewareStack.use(getHostHeaderPlugin(this.config));
|
||||
this.middlewareStack.use(getLoggerPlugin(this.config));
|
||||
this.middlewareStack.use(getRecursionDetectionPlugin(this.config));
|
||||
this.middlewareStack.use(getUserAgentPlugin(this.config));
|
||||
}
|
||||
destroy() {
|
||||
super.destroy();
|
||||
}
|
||||
}
|
||||
-51
@@ -1,51 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { AssumeRoleResponseFilterSensitiveLog } from "../models/models_0";
|
||||
import { de_AssumeRoleCommand, se_AssumeRoleCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class AssumeRoleCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, AssumeRoleCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: AssumeRoleResponseFilterSensitiveLog,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRole",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_AssumeRoleCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_AssumeRoleCommand(output, context);
|
||||
}
|
||||
}
|
||||
-49
@@ -1,49 +0,0 @@
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { AssumeRoleWithSAMLRequestFilterSensitiveLog, AssumeRoleWithSAMLResponseFilterSensitiveLog, } from "../models/models_0";
|
||||
import { de_AssumeRoleWithSAMLCommand, se_AssumeRoleWithSAMLCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class AssumeRoleWithSAMLCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, AssumeRoleWithSAMLCommand.getEndpointParameterInstructions()));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleWithSAMLCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: AssumeRoleWithSAMLRequestFilterSensitiveLog,
|
||||
outputFilterSensitiveLog: AssumeRoleWithSAMLResponseFilterSensitiveLog,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRoleWithSAML",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_AssumeRoleWithSAMLCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_AssumeRoleWithSAMLCommand(output, context);
|
||||
}
|
||||
}
|
||||
Generated
Vendored
-49
@@ -1,49 +0,0 @@
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { AssumeRoleWithWebIdentityRequestFilterSensitiveLog, AssumeRoleWithWebIdentityResponseFilterSensitiveLog, } from "../models/models_0";
|
||||
import { de_AssumeRoleWithWebIdentityCommand, se_AssumeRoleWithWebIdentityCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class AssumeRoleWithWebIdentityCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, AssumeRoleWithWebIdentityCommand.getEndpointParameterInstructions()));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "AssumeRoleWithWebIdentityCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: AssumeRoleWithWebIdentityRequestFilterSensitiveLog,
|
||||
outputFilterSensitiveLog: AssumeRoleWithWebIdentityResponseFilterSensitiveLog,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "AssumeRoleWithWebIdentity",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_AssumeRoleWithWebIdentityCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_AssumeRoleWithWebIdentityCommand(output, context);
|
||||
}
|
||||
}
|
||||
Generated
Vendored
-50
@@ -1,50 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { de_DecodeAuthorizationMessageCommand, se_DecodeAuthorizationMessageCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class DecodeAuthorizationMessageCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, DecodeAuthorizationMessageCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "DecodeAuthorizationMessageCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "DecodeAuthorizationMessage",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_DecodeAuthorizationMessageCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_DecodeAuthorizationMessageCommand(output, context);
|
||||
}
|
||||
}
|
||||
-50
@@ -1,50 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { de_GetAccessKeyInfoCommand, se_GetAccessKeyInfoCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class GetAccessKeyInfoCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, GetAccessKeyInfoCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetAccessKeyInfoCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetAccessKeyInfo",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_GetAccessKeyInfoCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_GetAccessKeyInfoCommand(output, context);
|
||||
}
|
||||
}
|
||||
-50
@@ -1,50 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { de_GetCallerIdentityCommand, se_GetCallerIdentityCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class GetCallerIdentityCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, GetCallerIdentityCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetCallerIdentityCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: (_) => _,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetCallerIdentity",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_GetCallerIdentityCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_GetCallerIdentityCommand(output, context);
|
||||
}
|
||||
}
|
||||
-51
@@ -1,51 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { GetFederationTokenResponseFilterSensitiveLog, } from "../models/models_0";
|
||||
import { de_GetFederationTokenCommand, se_GetFederationTokenCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class GetFederationTokenCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, GetFederationTokenCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetFederationTokenCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: GetFederationTokenResponseFilterSensitiveLog,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetFederationToken",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_GetFederationTokenCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_GetFederationTokenCommand(output, context);
|
||||
}
|
||||
}
|
||||
-51
@@ -1,51 +0,0 @@
|
||||
import { getAwsAuthPlugin } from "@aws-sdk/middleware-signing";
|
||||
import { getEndpointPlugin } from "@smithy/middleware-endpoint";
|
||||
import { getSerdePlugin } from "@smithy/middleware-serde";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { SMITHY_CONTEXT_KEY, } from "@smithy/types";
|
||||
import { GetSessionTokenResponseFilterSensitiveLog, } from "../models/models_0";
|
||||
import { de_GetSessionTokenCommand, se_GetSessionTokenCommand } from "../protocols/Aws_query";
|
||||
export { $Command };
|
||||
export class GetSessionTokenCommand extends $Command {
|
||||
static getEndpointParameterInstructions() {
|
||||
return {
|
||||
UseGlobalEndpoint: { type: "builtInParams", name: "useGlobalEndpoint" },
|
||||
UseFIPS: { type: "builtInParams", name: "useFipsEndpoint" },
|
||||
Endpoint: { type: "builtInParams", name: "endpoint" },
|
||||
Region: { type: "builtInParams", name: "region" },
|
||||
UseDualStack: { type: "builtInParams", name: "useDualstackEndpoint" },
|
||||
};
|
||||
}
|
||||
constructor(input) {
|
||||
super();
|
||||
this.input = input;
|
||||
}
|
||||
resolveMiddleware(clientStack, configuration, options) {
|
||||
this.middlewareStack.use(getSerdePlugin(configuration, this.serialize, this.deserialize));
|
||||
this.middlewareStack.use(getEndpointPlugin(configuration, GetSessionTokenCommand.getEndpointParameterInstructions()));
|
||||
this.middlewareStack.use(getAwsAuthPlugin(configuration));
|
||||
const stack = clientStack.concat(this.middlewareStack);
|
||||
const { logger } = configuration;
|
||||
const clientName = "STSClient";
|
||||
const commandName = "GetSessionTokenCommand";
|
||||
const handlerExecutionContext = {
|
||||
logger,
|
||||
clientName,
|
||||
commandName,
|
||||
inputFilterSensitiveLog: (_) => _,
|
||||
outputFilterSensitiveLog: GetSessionTokenResponseFilterSensitiveLog,
|
||||
[SMITHY_CONTEXT_KEY]: {
|
||||
service: "AWSSecurityTokenServiceV20110615",
|
||||
operation: "GetSessionToken",
|
||||
},
|
||||
};
|
||||
const { requestHandler } = configuration;
|
||||
return stack.resolve((request) => requestHandler.handle(request.request, options || {}), handlerExecutionContext);
|
||||
}
|
||||
serialize(input, context) {
|
||||
return se_GetSessionTokenCommand(input, context);
|
||||
}
|
||||
deserialize(output, context) {
|
||||
return de_GetSessionTokenCommand(output, context);
|
||||
}
|
||||
}
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
export * from "./AssumeRoleCommand";
|
||||
export * from "./AssumeRoleWithSAMLCommand";
|
||||
export * from "./AssumeRoleWithWebIdentityCommand";
|
||||
export * from "./DecodeAuthorizationMessageCommand";
|
||||
export * from "./GetAccessKeyInfoCommand";
|
||||
export * from "./GetCallerIdentityCommand";
|
||||
export * from "./GetFederationTokenCommand";
|
||||
export * from "./GetSessionTokenCommand";
|
||||
-22
@@ -1,22 +0,0 @@
|
||||
import { getDefaultRoleAssumer as StsGetDefaultRoleAssumer, getDefaultRoleAssumerWithWebIdentity as StsGetDefaultRoleAssumerWithWebIdentity, } from "./defaultStsRoleAssumers";
|
||||
import { STSClient } from "./STSClient";
|
||||
const getCustomizableStsClientCtor = (baseCtor, customizations) => {
|
||||
if (!customizations)
|
||||
return baseCtor;
|
||||
else
|
||||
return class CustomizableSTSClient extends baseCtor {
|
||||
constructor(config) {
|
||||
super(config);
|
||||
for (const customization of customizations) {
|
||||
this.middlewareStack.use(customization);
|
||||
}
|
||||
}
|
||||
};
|
||||
};
|
||||
export const getDefaultRoleAssumer = (stsOptions = {}, stsPlugins) => StsGetDefaultRoleAssumer(stsOptions, getCustomizableStsClientCtor(STSClient, stsPlugins));
|
||||
export const getDefaultRoleAssumerWithWebIdentity = (stsOptions = {}, stsPlugins) => StsGetDefaultRoleAssumerWithWebIdentity(stsOptions, getCustomizableStsClientCtor(STSClient, stsPlugins));
|
||||
export const decorateDefaultCredentialProvider = (provider) => (input) => provider({
|
||||
roleAssumer: getDefaultRoleAssumer(input),
|
||||
roleAssumerWithWebIdentity: getDefaultRoleAssumerWithWebIdentity(input),
|
||||
...input,
|
||||
});
|
||||
-70
@@ -1,70 +0,0 @@
|
||||
import { AssumeRoleCommand } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithWebIdentityCommand, } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
const ASSUME_ROLE_DEFAULT_REGION = "us-east-1";
|
||||
const decorateDefaultRegion = (region) => {
|
||||
if (typeof region !== "function") {
|
||||
return region === undefined ? ASSUME_ROLE_DEFAULT_REGION : region;
|
||||
}
|
||||
return async () => {
|
||||
try {
|
||||
return await region();
|
||||
}
|
||||
catch (e) {
|
||||
return ASSUME_ROLE_DEFAULT_REGION;
|
||||
}
|
||||
};
|
||||
};
|
||||
export const getDefaultRoleAssumer = (stsOptions, stsClientCtor) => {
|
||||
let stsClient;
|
||||
let closureSourceCreds;
|
||||
return async (sourceCreds, params) => {
|
||||
closureSourceCreds = sourceCreds;
|
||||
if (!stsClient) {
|
||||
const { logger, region, requestHandler } = stsOptions;
|
||||
stsClient = new stsClientCtor({
|
||||
logger,
|
||||
credentialDefaultProvider: () => async () => closureSourceCreds,
|
||||
region: decorateDefaultRegion(region || stsOptions.region),
|
||||
...(requestHandler ? { requestHandler } : {}),
|
||||
});
|
||||
}
|
||||
const { Credentials } = await stsClient.send(new AssumeRoleCommand(params));
|
||||
if (!Credentials || !Credentials.AccessKeyId || !Credentials.SecretAccessKey) {
|
||||
throw new Error(`Invalid response from STS.assumeRole call with role ${params.RoleArn}`);
|
||||
}
|
||||
return {
|
||||
accessKeyId: Credentials.AccessKeyId,
|
||||
secretAccessKey: Credentials.SecretAccessKey,
|
||||
sessionToken: Credentials.SessionToken,
|
||||
expiration: Credentials.Expiration,
|
||||
};
|
||||
};
|
||||
};
|
||||
export const getDefaultRoleAssumerWithWebIdentity = (stsOptions, stsClientCtor) => {
|
||||
let stsClient;
|
||||
return async (params) => {
|
||||
if (!stsClient) {
|
||||
const { logger, region, requestHandler } = stsOptions;
|
||||
stsClient = new stsClientCtor({
|
||||
logger,
|
||||
region: decorateDefaultRegion(region || stsOptions.region),
|
||||
...(requestHandler ? { requestHandler } : {}),
|
||||
});
|
||||
}
|
||||
const { Credentials } = await stsClient.send(new AssumeRoleWithWebIdentityCommand(params));
|
||||
if (!Credentials || !Credentials.AccessKeyId || !Credentials.SecretAccessKey) {
|
||||
throw new Error(`Invalid response from STS.assumeRoleWithWebIdentity call with role ${params.RoleArn}`);
|
||||
}
|
||||
return {
|
||||
accessKeyId: Credentials.AccessKeyId,
|
||||
secretAccessKey: Credentials.SecretAccessKey,
|
||||
sessionToken: Credentials.SessionToken,
|
||||
expiration: Credentials.Expiration,
|
||||
};
|
||||
};
|
||||
};
|
||||
export const decorateDefaultCredentialProvider = (provider) => (input) => provider({
|
||||
roleAssumer: getDefaultRoleAssumer(input, input.stsClientCtor),
|
||||
roleAssumerWithWebIdentity: getDefaultRoleAssumerWithWebIdentity(input, input.stsClientCtor),
|
||||
...input,
|
||||
});
|
||||
-9
@@ -1,9 +0,0 @@
|
||||
export const resolveClientEndpointParameters = (options) => {
|
||||
return {
|
||||
...options,
|
||||
useDualstackEndpoint: options.useDualstackEndpoint ?? false,
|
||||
useFipsEndpoint: options.useFipsEndpoint ?? false,
|
||||
useGlobalEndpoint: options.useGlobalEndpoint ?? false,
|
||||
defaultSigningName: "sts",
|
||||
};
|
||||
};
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
import { resolveEndpoint } from "@smithy/util-endpoints";
|
||||
import { ruleSet } from "./ruleset";
|
||||
export const defaultEndpointResolver = (endpointParams, context = {}) => {
|
||||
return resolveEndpoint(ruleSet, {
|
||||
endpointParams: endpointParams,
|
||||
logger: context.logger,
|
||||
});
|
||||
};
|
||||
-4
@@ -1,4 +0,0 @@
|
||||
const F = "required", G = "type", H = "fn", I = "argv", J = "ref";
|
||||
const a = false, b = true, c = "booleanEquals", d = "stringEquals", e = "sigv4", f = "sts", g = "us-east-1", h = "endpoint", i = "https://sts.{Region}.{PartitionResult#dnsSuffix}", j = "tree", k = "error", l = "getAttr", m = { [F]: false, [G]: "String" }, n = { [F]: true, "default": false, [G]: "Boolean" }, o = { [J]: "Endpoint" }, p = { [H]: "isSet", [I]: [{ [J]: "Region" }] }, q = { [J]: "Region" }, r = { [H]: "aws.partition", [I]: [q], "assign": "PartitionResult" }, s = { [J]: "UseFIPS" }, t = { [J]: "UseDualStack" }, u = { "url": "https://sts.amazonaws.com", "properties": { "authSchemes": [{ "name": e, "signingName": f, "signingRegion": g }] }, "headers": {} }, v = {}, w = { "conditions": [{ [H]: d, [I]: [q, "aws-global"] }], [h]: u, [G]: h }, x = { [H]: c, [I]: [s, true] }, y = { [H]: c, [I]: [t, true] }, z = { [H]: l, [I]: [{ [J]: "PartitionResult" }, "supportsFIPS"] }, A = { [J]: "PartitionResult" }, B = { [H]: c, [I]: [true, { [H]: l, [I]: [A, "supportsDualStack"] }] }, C = [{ [H]: "isSet", [I]: [o] }], D = [x], E = [y];
|
||||
const _data = { version: "1.0", parameters: { Region: m, UseDualStack: n, UseFIPS: n, Endpoint: m, UseGlobalEndpoint: n }, rules: [{ conditions: [{ [H]: c, [I]: [{ [J]: "UseGlobalEndpoint" }, b] }, { [H]: "not", [I]: C }, p, r, { [H]: c, [I]: [s, a] }, { [H]: c, [I]: [t, a] }], rules: [{ conditions: [{ [H]: d, [I]: [q, "ap-northeast-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-south-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-southeast-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "ap-southeast-2"] }], endpoint: u, [G]: h }, w, { conditions: [{ [H]: d, [I]: [q, "ca-central-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-central-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-north-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-2"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "eu-west-3"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "sa-east-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, g] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-east-2"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-west-1"] }], endpoint: u, [G]: h }, { conditions: [{ [H]: d, [I]: [q, "us-west-2"] }], endpoint: u, [G]: h }, { endpoint: { url: i, properties: { authSchemes: [{ name: e, signingName: f, signingRegion: "{Region}" }] }, headers: v }, [G]: h }], [G]: j }, { conditions: C, rules: [{ conditions: D, error: "Invalid Configuration: FIPS and custom endpoint are not supported", [G]: k }, { conditions: E, error: "Invalid Configuration: Dualstack and custom endpoint are not supported", [G]: k }, { endpoint: { url: o, properties: v, headers: v }, [G]: h }], [G]: j }, { conditions: [p], rules: [{ conditions: [r], rules: [{ conditions: [x, y], rules: [{ conditions: [{ [H]: c, [I]: [b, z] }, B], rules: [{ endpoint: { url: "https://sts-fips.{Region}.{PartitionResult#dualStackDnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "FIPS and DualStack are enabled, but this partition does not support one or both", [G]: k }], [G]: j }, { conditions: D, rules: [{ conditions: [{ [H]: c, [I]: [z, b] }], rules: [{ conditions: [{ [H]: d, [I]: [{ [H]: l, [I]: [A, "name"] }, "aws-us-gov"] }], endpoint: { url: "https://sts.{Region}.amazonaws.com", properties: v, headers: v }, [G]: h }, { endpoint: { url: "https://sts-fips.{Region}.{PartitionResult#dnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "FIPS is enabled but this partition does not support FIPS", [G]: k }], [G]: j }, { conditions: E, rules: [{ conditions: [B], rules: [{ endpoint: { url: "https://sts.{Region}.{PartitionResult#dualStackDnsSuffix}", properties: v, headers: v }, [G]: h }], [G]: j }, { error: "DualStack is enabled but this partition does not support DualStack", [G]: k }], [G]: j }, w, { endpoint: { url: i, properties: v, headers: v }, [G]: h }], [G]: j }], [G]: j }, { error: "Invalid Configuration: Missing Region", [G]: k }] };
|
||||
export const ruleSet = _data;
|
||||
-1
@@ -1 +0,0 @@
|
||||
export {};
|
||||
-7
@@ -1,7 +0,0 @@
|
||||
export * from "./STSClient";
|
||||
export * from "./STS";
|
||||
export * from "./commands";
|
||||
export * from "./models";
|
||||
export * from "./defaultRoleAssumers";
|
||||
import "@aws-sdk/util-endpoints";
|
||||
export { STSServiceException } from "./models/STSServiceException";
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
import { ServiceException as __ServiceException, } from "@smithy/smithy-client";
|
||||
export { __ServiceException };
|
||||
export class STSServiceException extends __ServiceException {
|
||||
constructor(options) {
|
||||
super(options);
|
||||
Object.setPrototypeOf(this, STSServiceException.prototype);
|
||||
}
|
||||
}
|
||||
-1
@@ -1 +0,0 @@
|
||||
export * from "./models_0";
|
||||
-130
@@ -1,130 +0,0 @@
|
||||
import { SENSITIVE_STRING } from "@smithy/smithy-client";
|
||||
import { STSServiceException as __BaseException } from "./STSServiceException";
|
||||
export class ExpiredTokenException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "ExpiredTokenException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "ExpiredTokenException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, ExpiredTokenException.prototype);
|
||||
}
|
||||
}
|
||||
export class MalformedPolicyDocumentException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "MalformedPolicyDocumentException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "MalformedPolicyDocumentException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, MalformedPolicyDocumentException.prototype);
|
||||
}
|
||||
}
|
||||
export class PackedPolicyTooLargeException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "PackedPolicyTooLargeException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "PackedPolicyTooLargeException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, PackedPolicyTooLargeException.prototype);
|
||||
}
|
||||
}
|
||||
export class RegionDisabledException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "RegionDisabledException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "RegionDisabledException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, RegionDisabledException.prototype);
|
||||
}
|
||||
}
|
||||
export class IDPRejectedClaimException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "IDPRejectedClaimException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "IDPRejectedClaimException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, IDPRejectedClaimException.prototype);
|
||||
}
|
||||
}
|
||||
export class InvalidIdentityTokenException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "InvalidIdentityTokenException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "InvalidIdentityTokenException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, InvalidIdentityTokenException.prototype);
|
||||
}
|
||||
}
|
||||
export class IDPCommunicationErrorException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "IDPCommunicationErrorException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "IDPCommunicationErrorException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, IDPCommunicationErrorException.prototype);
|
||||
}
|
||||
}
|
||||
export class InvalidAuthorizationMessageException extends __BaseException {
|
||||
constructor(opts) {
|
||||
super({
|
||||
name: "InvalidAuthorizationMessageException",
|
||||
$fault: "client",
|
||||
...opts,
|
||||
});
|
||||
this.name = "InvalidAuthorizationMessageException";
|
||||
this.$fault = "client";
|
||||
Object.setPrototypeOf(this, InvalidAuthorizationMessageException.prototype);
|
||||
}
|
||||
}
|
||||
export const CredentialsFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.SecretAccessKey && { SecretAccessKey: SENSITIVE_STRING }),
|
||||
});
|
||||
export const AssumeRoleResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: CredentialsFilterSensitiveLog(obj.Credentials) }),
|
||||
});
|
||||
export const AssumeRoleWithSAMLRequestFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.SAMLAssertion && { SAMLAssertion: SENSITIVE_STRING }),
|
||||
});
|
||||
export const AssumeRoleWithSAMLResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: CredentialsFilterSensitiveLog(obj.Credentials) }),
|
||||
});
|
||||
export const AssumeRoleWithWebIdentityRequestFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.WebIdentityToken && { WebIdentityToken: SENSITIVE_STRING }),
|
||||
});
|
||||
export const AssumeRoleWithWebIdentityResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: CredentialsFilterSensitiveLog(obj.Credentials) }),
|
||||
});
|
||||
export const GetFederationTokenResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: CredentialsFilterSensitiveLog(obj.Credentials) }),
|
||||
});
|
||||
export const GetSessionTokenResponseFilterSensitiveLog = (obj) => ({
|
||||
...obj,
|
||||
...(obj.Credentials && { Credentials: CredentialsFilterSensitiveLog(obj.Credentials) }),
|
||||
});
|
||||
-1009
File diff suppressed because it is too large
Load Diff
-34
@@ -1,34 +0,0 @@
|
||||
import packageInfo from "../package.json";
|
||||
import { Sha256 } from "@aws-crypto/sha256-browser";
|
||||
import { defaultUserAgent } from "@aws-sdk/util-user-agent-browser";
|
||||
import { DEFAULT_USE_DUALSTACK_ENDPOINT, DEFAULT_USE_FIPS_ENDPOINT } from "@smithy/config-resolver";
|
||||
import { FetchHttpHandler as RequestHandler, streamCollector } from "@smithy/fetch-http-handler";
|
||||
import { invalidProvider } from "@smithy/invalid-dependency";
|
||||
import { calculateBodyLength } from "@smithy/util-body-length-browser";
|
||||
import { DEFAULT_MAX_ATTEMPTS, DEFAULT_RETRY_MODE } from "@smithy/util-retry";
|
||||
import { getRuntimeConfig as getSharedRuntimeConfig } from "./runtimeConfig.shared";
|
||||
import { loadConfigsForDefaultMode } from "@smithy/smithy-client";
|
||||
import { resolveDefaultsModeConfig } from "@smithy/util-defaults-mode-browser";
|
||||
export const getRuntimeConfig = (config) => {
|
||||
const defaultsMode = resolveDefaultsModeConfig(config);
|
||||
const defaultConfigProvider = () => defaultsMode().then(loadConfigsForDefaultMode);
|
||||
const clientSharedValues = getSharedRuntimeConfig(config);
|
||||
return {
|
||||
...clientSharedValues,
|
||||
...config,
|
||||
runtime: "browser",
|
||||
defaultsMode,
|
||||
bodyLengthChecker: config?.bodyLengthChecker ?? calculateBodyLength,
|
||||
credentialDefaultProvider: config?.credentialDefaultProvider ?? ((_) => () => Promise.reject(new Error("Credential is missing"))),
|
||||
defaultUserAgentProvider: config?.defaultUserAgentProvider ??
|
||||
defaultUserAgent({ serviceId: clientSharedValues.serviceId, clientVersion: packageInfo.version }),
|
||||
maxAttempts: config?.maxAttempts ?? DEFAULT_MAX_ATTEMPTS,
|
||||
region: config?.region ?? invalidProvider("Region is missing"),
|
||||
requestHandler: config?.requestHandler ?? new RequestHandler(defaultConfigProvider),
|
||||
retryMode: config?.retryMode ?? (async () => (await defaultConfigProvider()).retryMode || DEFAULT_RETRY_MODE),
|
||||
sha256: config?.sha256 ?? Sha256,
|
||||
streamCollector: config?.streamCollector ?? streamCollector,
|
||||
useDualstackEndpoint: config?.useDualstackEndpoint ?? (() => Promise.resolve(DEFAULT_USE_DUALSTACK_ENDPOINT)),
|
||||
useFipsEndpoint: config?.useFipsEndpoint ?? (() => Promise.resolve(DEFAULT_USE_FIPS_ENDPOINT)),
|
||||
};
|
||||
};
|
||||
-45
@@ -1,45 +0,0 @@
|
||||
import packageInfo from "../package.json";
|
||||
import { decorateDefaultCredentialProvider } from "./defaultStsRoleAssumers";
|
||||
import { emitWarningIfUnsupportedVersion as awsCheckVersion } from "@aws-sdk/core";
|
||||
import { defaultProvider as credentialDefaultProvider } from "@aws-sdk/credential-provider-node";
|
||||
import { defaultUserAgent } from "@aws-sdk/util-user-agent-node";
|
||||
import { NODE_REGION_CONFIG_FILE_OPTIONS, NODE_REGION_CONFIG_OPTIONS, NODE_USE_DUALSTACK_ENDPOINT_CONFIG_OPTIONS, NODE_USE_FIPS_ENDPOINT_CONFIG_OPTIONS, } from "@smithy/config-resolver";
|
||||
import { Hash } from "@smithy/hash-node";
|
||||
import { NODE_MAX_ATTEMPT_CONFIG_OPTIONS, NODE_RETRY_MODE_CONFIG_OPTIONS } from "@smithy/middleware-retry";
|
||||
import { loadConfig as loadNodeConfig } from "@smithy/node-config-provider";
|
||||
import { NodeHttpHandler as RequestHandler, streamCollector } from "@smithy/node-http-handler";
|
||||
import { calculateBodyLength } from "@smithy/util-body-length-node";
|
||||
import { DEFAULT_RETRY_MODE } from "@smithy/util-retry";
|
||||
import { getRuntimeConfig as getSharedRuntimeConfig } from "./runtimeConfig.shared";
|
||||
import { loadConfigsForDefaultMode } from "@smithy/smithy-client";
|
||||
import { resolveDefaultsModeConfig } from "@smithy/util-defaults-mode-node";
|
||||
import { emitWarningIfUnsupportedVersion } from "@smithy/smithy-client";
|
||||
export const getRuntimeConfig = (config) => {
|
||||
emitWarningIfUnsupportedVersion(process.version);
|
||||
const defaultsMode = resolveDefaultsModeConfig(config);
|
||||
const defaultConfigProvider = () => defaultsMode().then(loadConfigsForDefaultMode);
|
||||
const clientSharedValues = getSharedRuntimeConfig(config);
|
||||
awsCheckVersion(process.version);
|
||||
return {
|
||||
...clientSharedValues,
|
||||
...config,
|
||||
runtime: "node",
|
||||
defaultsMode,
|
||||
bodyLengthChecker: config?.bodyLengthChecker ?? calculateBodyLength,
|
||||
credentialDefaultProvider: config?.credentialDefaultProvider ?? decorateDefaultCredentialProvider(credentialDefaultProvider),
|
||||
defaultUserAgentProvider: config?.defaultUserAgentProvider ??
|
||||
defaultUserAgent({ serviceId: clientSharedValues.serviceId, clientVersion: packageInfo.version }),
|
||||
maxAttempts: config?.maxAttempts ?? loadNodeConfig(NODE_MAX_ATTEMPT_CONFIG_OPTIONS),
|
||||
region: config?.region ?? loadNodeConfig(NODE_REGION_CONFIG_OPTIONS, NODE_REGION_CONFIG_FILE_OPTIONS),
|
||||
requestHandler: config?.requestHandler ?? new RequestHandler(defaultConfigProvider),
|
||||
retryMode: config?.retryMode ??
|
||||
loadNodeConfig({
|
||||
...NODE_RETRY_MODE_CONFIG_OPTIONS,
|
||||
default: async () => (await defaultConfigProvider()).retryMode || DEFAULT_RETRY_MODE,
|
||||
}),
|
||||
sha256: config?.sha256 ?? Hash.bind(null, "sha256"),
|
||||
streamCollector: config?.streamCollector ?? streamCollector,
|
||||
useDualstackEndpoint: config?.useDualstackEndpoint ?? loadNodeConfig(NODE_USE_DUALSTACK_ENDPOINT_CONFIG_OPTIONS),
|
||||
useFipsEndpoint: config?.useFipsEndpoint ?? loadNodeConfig(NODE_USE_FIPS_ENDPOINT_CONFIG_OPTIONS),
|
||||
};
|
||||
};
|
||||
-11
@@ -1,11 +0,0 @@
|
||||
import { Sha256 } from "@aws-crypto/sha256-js";
|
||||
import { getRuntimeConfig as getBrowserRuntimeConfig } from "./runtimeConfig.browser";
|
||||
export const getRuntimeConfig = (config) => {
|
||||
const browserDefaults = getBrowserRuntimeConfig(config);
|
||||
return {
|
||||
...browserDefaults,
|
||||
...config,
|
||||
runtime: "react-native",
|
||||
sha256: config?.sha256 ?? Sha256,
|
||||
};
|
||||
};
|
||||
-20
@@ -1,20 +0,0 @@
|
||||
import { NoOpLogger } from "@smithy/smithy-client";
|
||||
import { parseUrl } from "@smithy/url-parser";
|
||||
import { fromBase64, toBase64 } from "@smithy/util-base64";
|
||||
import { fromUtf8, toUtf8 } from "@smithy/util-utf8";
|
||||
import { defaultEndpointResolver } from "./endpoint/endpointResolver";
|
||||
export const getRuntimeConfig = (config) => {
|
||||
return {
|
||||
apiVersion: "2011-06-15",
|
||||
base64Decoder: config?.base64Decoder ?? fromBase64,
|
||||
base64Encoder: config?.base64Encoder ?? toBase64,
|
||||
disableHostPrefix: config?.disableHostPrefix ?? false,
|
||||
endpointProvider: config?.endpointProvider ?? defaultEndpointResolver,
|
||||
extensions: config?.extensions ?? [],
|
||||
logger: config?.logger ?? new NoOpLogger(),
|
||||
serviceId: config?.serviceId ?? "STS",
|
||||
urlParser: config?.urlParser ?? parseUrl,
|
||||
utf8Decoder: config?.utf8Decoder ?? fromUtf8,
|
||||
utf8Encoder: config?.utf8Encoder ?? toUtf8,
|
||||
};
|
||||
};
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
import { getAwsRegionExtensionConfiguration, resolveAwsRegionExtensionConfiguration, } from "@aws-sdk/region-config-resolver";
|
||||
import { getHttpHandlerExtensionConfiguration, resolveHttpHandlerRuntimeConfig } from "@smithy/protocol-http";
|
||||
import { getDefaultExtensionConfiguration, resolveDefaultRuntimeConfig } from "@smithy/smithy-client";
|
||||
const asPartial = (t) => t;
|
||||
export const resolveRuntimeExtensions = (runtimeConfig, extensions) => {
|
||||
const extensionConfiguration = {
|
||||
...asPartial(getAwsRegionExtensionConfiguration(runtimeConfig)),
|
||||
...asPartial(getDefaultExtensionConfiguration(runtimeConfig)),
|
||||
...asPartial(getHttpHandlerExtensionConfiguration(runtimeConfig)),
|
||||
};
|
||||
extensions.forEach((extension) => extension.configure(extensionConfiguration));
|
||||
return {
|
||||
...runtimeConfig,
|
||||
...resolveAwsRegionExtensionConfiguration(extensionConfiguration),
|
||||
...resolveDefaultRuntimeConfig(extensionConfiguration),
|
||||
...resolveHttpHandlerRuntimeConfig(extensionConfiguration),
|
||||
};
|
||||
};
|
||||
-69
@@ -1,69 +0,0 @@
|
||||
import { HttpHandlerOptions as __HttpHandlerOptions } from "@smithy/types";
|
||||
import { AssumeRoleCommandInput, AssumeRoleCommandOutput } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput } from "./commands/AssumeRoleWithSAMLCommand";
|
||||
import { AssumeRoleWithWebIdentityCommandInput, AssumeRoleWithWebIdentityCommandOutput } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import { DecodeAuthorizationMessageCommandInput, DecodeAuthorizationMessageCommandOutput } from "./commands/DecodeAuthorizationMessageCommand";
|
||||
import { GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput } from "./commands/GetAccessKeyInfoCommand";
|
||||
import { GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput } from "./commands/GetCallerIdentityCommand";
|
||||
import { GetFederationTokenCommandInput, GetFederationTokenCommandOutput } from "./commands/GetFederationTokenCommand";
|
||||
import { GetSessionTokenCommandInput, GetSessionTokenCommandOutput } from "./commands/GetSessionTokenCommand";
|
||||
import { STSClient } from "./STSClient";
|
||||
export interface STS {
|
||||
/**
|
||||
* @see {@link AssumeRoleCommand}
|
||||
*/
|
||||
assumeRole(args: AssumeRoleCommandInput, options?: __HttpHandlerOptions): Promise<AssumeRoleCommandOutput>;
|
||||
assumeRole(args: AssumeRoleCommandInput, cb: (err: any, data?: AssumeRoleCommandOutput) => void): void;
|
||||
assumeRole(args: AssumeRoleCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: AssumeRoleCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link AssumeRoleWithSAMLCommand}
|
||||
*/
|
||||
assumeRoleWithSAML(args: AssumeRoleWithSAMLCommandInput, options?: __HttpHandlerOptions): Promise<AssumeRoleWithSAMLCommandOutput>;
|
||||
assumeRoleWithSAML(args: AssumeRoleWithSAMLCommandInput, cb: (err: any, data?: AssumeRoleWithSAMLCommandOutput) => void): void;
|
||||
assumeRoleWithSAML(args: AssumeRoleWithSAMLCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: AssumeRoleWithSAMLCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link AssumeRoleWithWebIdentityCommand}
|
||||
*/
|
||||
assumeRoleWithWebIdentity(args: AssumeRoleWithWebIdentityCommandInput, options?: __HttpHandlerOptions): Promise<AssumeRoleWithWebIdentityCommandOutput>;
|
||||
assumeRoleWithWebIdentity(args: AssumeRoleWithWebIdentityCommandInput, cb: (err: any, data?: AssumeRoleWithWebIdentityCommandOutput) => void): void;
|
||||
assumeRoleWithWebIdentity(args: AssumeRoleWithWebIdentityCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: AssumeRoleWithWebIdentityCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link DecodeAuthorizationMessageCommand}
|
||||
*/
|
||||
decodeAuthorizationMessage(args: DecodeAuthorizationMessageCommandInput, options?: __HttpHandlerOptions): Promise<DecodeAuthorizationMessageCommandOutput>;
|
||||
decodeAuthorizationMessage(args: DecodeAuthorizationMessageCommandInput, cb: (err: any, data?: DecodeAuthorizationMessageCommandOutput) => void): void;
|
||||
decodeAuthorizationMessage(args: DecodeAuthorizationMessageCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: DecodeAuthorizationMessageCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link GetAccessKeyInfoCommand}
|
||||
*/
|
||||
getAccessKeyInfo(args: GetAccessKeyInfoCommandInput, options?: __HttpHandlerOptions): Promise<GetAccessKeyInfoCommandOutput>;
|
||||
getAccessKeyInfo(args: GetAccessKeyInfoCommandInput, cb: (err: any, data?: GetAccessKeyInfoCommandOutput) => void): void;
|
||||
getAccessKeyInfo(args: GetAccessKeyInfoCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: GetAccessKeyInfoCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link GetCallerIdentityCommand}
|
||||
*/
|
||||
getCallerIdentity(args: GetCallerIdentityCommandInput, options?: __HttpHandlerOptions): Promise<GetCallerIdentityCommandOutput>;
|
||||
getCallerIdentity(args: GetCallerIdentityCommandInput, cb: (err: any, data?: GetCallerIdentityCommandOutput) => void): void;
|
||||
getCallerIdentity(args: GetCallerIdentityCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: GetCallerIdentityCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link GetFederationTokenCommand}
|
||||
*/
|
||||
getFederationToken(args: GetFederationTokenCommandInput, options?: __HttpHandlerOptions): Promise<GetFederationTokenCommandOutput>;
|
||||
getFederationToken(args: GetFederationTokenCommandInput, cb: (err: any, data?: GetFederationTokenCommandOutput) => void): void;
|
||||
getFederationToken(args: GetFederationTokenCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: GetFederationTokenCommandOutput) => void): void;
|
||||
/**
|
||||
* @see {@link GetSessionTokenCommand}
|
||||
*/
|
||||
getSessionToken(args: GetSessionTokenCommandInput, options?: __HttpHandlerOptions): Promise<GetSessionTokenCommandOutput>;
|
||||
getSessionToken(args: GetSessionTokenCommandInput, cb: (err: any, data?: GetSessionTokenCommandOutput) => void): void;
|
||||
getSessionToken(args: GetSessionTokenCommandInput, options: __HttpHandlerOptions, cb: (err: any, data?: GetSessionTokenCommandOutput) => void): void;
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <fullname>Security Token Service</fullname>
|
||||
* <p>Security Token Service (STS) enables you to request temporary, limited-privilege
|
||||
* credentials for users. This guide provides descriptions of the STS API. For
|
||||
* more information about using this service, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html">Temporary Security Credentials</a>.</p>
|
||||
*/
|
||||
export declare class STS extends STSClient implements STS {
|
||||
}
|
||||
-180
@@ -1,180 +0,0 @@
|
||||
import { HostHeaderInputConfig, HostHeaderResolvedConfig } from "@aws-sdk/middleware-host-header";
|
||||
import { StsAuthInputConfig, StsAuthResolvedConfig } from "@aws-sdk/middleware-sdk-sts";
|
||||
import { UserAgentInputConfig, UserAgentResolvedConfig } from "@aws-sdk/middleware-user-agent";
|
||||
import { Credentials as __Credentials } from "@aws-sdk/types";
|
||||
import { RegionInputConfig, RegionResolvedConfig } from "@smithy/config-resolver";
|
||||
import { EndpointInputConfig, EndpointResolvedConfig } from "@smithy/middleware-endpoint";
|
||||
import { RetryInputConfig, RetryResolvedConfig } from "@smithy/middleware-retry";
|
||||
import { HttpHandler as __HttpHandler } from "@smithy/protocol-http";
|
||||
import { Client as __Client, DefaultsMode as __DefaultsMode, SmithyConfiguration as __SmithyConfiguration, SmithyResolvedConfiguration as __SmithyResolvedConfiguration } from "@smithy/smithy-client";
|
||||
import { BodyLengthCalculator as __BodyLengthCalculator, CheckOptionalClientConfig as __CheckOptionalClientConfig, ChecksumConstructor as __ChecksumConstructor, Decoder as __Decoder, Encoder as __Encoder, HashConstructor as __HashConstructor, HttpHandlerOptions as __HttpHandlerOptions, Logger as __Logger, Provider as __Provider, Provider, StreamCollector as __StreamCollector, UrlParser as __UrlParser, UserAgent as __UserAgent } from "@smithy/types";
|
||||
import { AssumeRoleCommandInput, AssumeRoleCommandOutput } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput } from "./commands/AssumeRoleWithSAMLCommand";
|
||||
import { AssumeRoleWithWebIdentityCommandInput, AssumeRoleWithWebIdentityCommandOutput } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import { DecodeAuthorizationMessageCommandInput, DecodeAuthorizationMessageCommandOutput } from "./commands/DecodeAuthorizationMessageCommand";
|
||||
import { GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput } from "./commands/GetAccessKeyInfoCommand";
|
||||
import { GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput } from "./commands/GetCallerIdentityCommand";
|
||||
import { GetFederationTokenCommandInput, GetFederationTokenCommandOutput } from "./commands/GetFederationTokenCommand";
|
||||
import { GetSessionTokenCommandInput, GetSessionTokenCommandOutput } from "./commands/GetSessionTokenCommand";
|
||||
import { ClientInputEndpointParameters, ClientResolvedEndpointParameters, EndpointParameters } from "./endpoint/EndpointParameters";
|
||||
import { RuntimeExtension, RuntimeExtensionsConfig } from "./runtimeExtensions";
|
||||
export { __Client };
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export type ServiceInputTypes = AssumeRoleCommandInput | AssumeRoleWithSAMLCommandInput | AssumeRoleWithWebIdentityCommandInput | DecodeAuthorizationMessageCommandInput | GetAccessKeyInfoCommandInput | GetCallerIdentityCommandInput | GetFederationTokenCommandInput | GetSessionTokenCommandInput;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export type ServiceOutputTypes = AssumeRoleCommandOutput | AssumeRoleWithSAMLCommandOutput | AssumeRoleWithWebIdentityCommandOutput | DecodeAuthorizationMessageCommandOutput | GetAccessKeyInfoCommandOutput | GetCallerIdentityCommandOutput | GetFederationTokenCommandOutput | GetSessionTokenCommandOutput;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export interface ClientDefaults extends Partial<__SmithyResolvedConfiguration<__HttpHandlerOptions>> {
|
||||
/**
|
||||
* The HTTP handler to use. Fetch in browser and Https in Nodejs.
|
||||
*/
|
||||
requestHandler?: __HttpHandler;
|
||||
/**
|
||||
* A constructor for a class implementing the {@link @smithy/types#ChecksumConstructor} interface
|
||||
* that computes the SHA-256 HMAC or checksum of a string or binary buffer.
|
||||
* @internal
|
||||
*/
|
||||
sha256?: __ChecksumConstructor | __HashConstructor;
|
||||
/**
|
||||
* The function that will be used to convert strings into HTTP endpoints.
|
||||
* @internal
|
||||
*/
|
||||
urlParser?: __UrlParser;
|
||||
/**
|
||||
* A function that can calculate the length of a request body.
|
||||
* @internal
|
||||
*/
|
||||
bodyLengthChecker?: __BodyLengthCalculator;
|
||||
/**
|
||||
* A function that converts a stream into an array of bytes.
|
||||
* @internal
|
||||
*/
|
||||
streamCollector?: __StreamCollector;
|
||||
/**
|
||||
* The function that will be used to convert a base64-encoded string to a byte array.
|
||||
* @internal
|
||||
*/
|
||||
base64Decoder?: __Decoder;
|
||||
/**
|
||||
* The function that will be used to convert binary data to a base64-encoded string.
|
||||
* @internal
|
||||
*/
|
||||
base64Encoder?: __Encoder;
|
||||
/**
|
||||
* The function that will be used to convert a UTF8-encoded string to a byte array.
|
||||
* @internal
|
||||
*/
|
||||
utf8Decoder?: __Decoder;
|
||||
/**
|
||||
* The function that will be used to convert binary data to a UTF-8 encoded string.
|
||||
* @internal
|
||||
*/
|
||||
utf8Encoder?: __Encoder;
|
||||
/**
|
||||
* The runtime environment.
|
||||
* @internal
|
||||
*/
|
||||
runtime?: string;
|
||||
/**
|
||||
* Disable dynamically changing the endpoint of the client based on the hostPrefix
|
||||
* trait of an operation.
|
||||
*/
|
||||
disableHostPrefix?: boolean;
|
||||
/**
|
||||
* Unique service identifier.
|
||||
* @internal
|
||||
*/
|
||||
serviceId?: string;
|
||||
/**
|
||||
* Enables IPv6/IPv4 dualstack endpoint.
|
||||
*/
|
||||
useDualstackEndpoint?: boolean | __Provider<boolean>;
|
||||
/**
|
||||
* Enables FIPS compatible endpoints.
|
||||
*/
|
||||
useFipsEndpoint?: boolean | __Provider<boolean>;
|
||||
/**
|
||||
* The AWS region to which this client will send requests
|
||||
*/
|
||||
region?: string | __Provider<string>;
|
||||
/**
|
||||
* Default credentials provider; Not available in browser runtime.
|
||||
* @internal
|
||||
*/
|
||||
credentialDefaultProvider?: (input: any) => __Provider<__Credentials>;
|
||||
/**
|
||||
* The provider populating default tracking information to be sent with `user-agent`, `x-amz-user-agent` header
|
||||
* @internal
|
||||
*/
|
||||
defaultUserAgentProvider?: Provider<__UserAgent>;
|
||||
/**
|
||||
* Value for how many times a request will be made at most in case of retry.
|
||||
*/
|
||||
maxAttempts?: number | __Provider<number>;
|
||||
/**
|
||||
* Specifies which retry algorithm to use.
|
||||
* @see https://docs.aws.amazon.com/AWSJavaScriptSDK/v3/latest/Package/-smithy-util-retry/Enum/RETRY_MODES/
|
||||
*
|
||||
*/
|
||||
retryMode?: string | __Provider<string>;
|
||||
/**
|
||||
* Optional logger for logging debug/info/warn/error.
|
||||
*/
|
||||
logger?: __Logger;
|
||||
/**
|
||||
* Optional extensions
|
||||
*/
|
||||
extensions?: RuntimeExtension[];
|
||||
/**
|
||||
* The {@link @smithy/smithy-client#DefaultsMode} that will be used to determine how certain default configuration options are resolved in the SDK.
|
||||
*/
|
||||
defaultsMode?: __DefaultsMode | __Provider<__DefaultsMode>;
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export type STSClientConfigType = Partial<__SmithyConfiguration<__HttpHandlerOptions>> & ClientDefaults & RegionInputConfig & EndpointInputConfig<EndpointParameters> & RetryInputConfig & HostHeaderInputConfig & StsAuthInputConfig & UserAgentInputConfig & ClientInputEndpointParameters;
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The configuration interface of STSClient class constructor that set the region, credentials and other options.
|
||||
*/
|
||||
export interface STSClientConfig extends STSClientConfigType {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export type STSClientResolvedConfigType = __SmithyResolvedConfiguration<__HttpHandlerOptions> & Required<ClientDefaults> & RuntimeExtensionsConfig & RegionResolvedConfig & EndpointResolvedConfig<EndpointParameters> & RetryResolvedConfig & HostHeaderResolvedConfig & StsAuthResolvedConfig & UserAgentResolvedConfig & ClientResolvedEndpointParameters;
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The resolved configuration interface of STSClient class. This is resolved and normalized from the {@link STSClientConfig | constructor configuration interface}.
|
||||
*/
|
||||
export interface STSClientResolvedConfig extends STSClientResolvedConfigType {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <fullname>Security Token Service</fullname>
|
||||
* <p>Security Token Service (STS) enables you to request temporary, limited-privilege
|
||||
* credentials for users. This guide provides descriptions of the STS API. For
|
||||
* more information about using this service, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html">Temporary Security Credentials</a>.</p>
|
||||
*/
|
||||
export declare class STSClient extends __Client<__HttpHandlerOptions, ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig> {
|
||||
/**
|
||||
* The resolved configuration of STSClient class. This is resolved and normalized from the {@link STSClientConfig | constructor configuration interface}.
|
||||
*/
|
||||
readonly config: STSClientResolvedConfig;
|
||||
constructor(...[configuration]: __CheckOptionalClientConfig<STSClientConfig>);
|
||||
/**
|
||||
* Destroy underlying resources, like sockets. It's usually not necessary to do this.
|
||||
* However in Node.js, it's best to explicitly shut down the client's agent when it is no longer needed.
|
||||
* Otherwise, sockets might stay open for quite a long time before the server terminates them.
|
||||
*/
|
||||
destroy(): void;
|
||||
}
|
||||
-271
@@ -1,271 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { AssumeRoleRequest, AssumeRoleResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link AssumeRoleCommand}.
|
||||
*/
|
||||
export interface AssumeRoleCommandInput extends AssumeRoleRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link AssumeRoleCommand}.
|
||||
*/
|
||||
export interface AssumeRoleCommandOutput extends AssumeRoleResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns a set of temporary security credentials that you can use to access Amazon Web Services
|
||||
* resources. These temporary credentials consist of an access key ID, a secret access key,
|
||||
* and a security token. Typically, you use <code>AssumeRole</code> within your account or for
|
||||
* cross-account access. For a comparison of <code>AssumeRole</code> with other API operations
|
||||
* that produce temporary credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html">Requesting Temporary Security
|
||||
* Credentials</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#stsapi_comparison">Comparing the
|
||||
* Amazon Web Services STS API operations</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>Permissions</b>
|
||||
* </p>
|
||||
* <p>The temporary security credentials created by <code>AssumeRole</code> can be used to
|
||||
* make API calls to any Amazon Web Services service with the following exception: You cannot call the
|
||||
* Amazon Web Services STS <code>GetFederationToken</code> or <code>GetSessionToken</code> API
|
||||
* operations.</p>
|
||||
* <p>(Optional) You can pass inline or managed <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">session policies</a> to
|
||||
* this operation. You can pass a single JSON policy document to use as an inline session
|
||||
* policy. You can also specify up to 10 managed policy Amazon Resource Names (ARNs) to use as
|
||||
* managed session policies. The plaintext that you use for both inline and managed session
|
||||
* policies can't exceed 2,048 characters. Passing policies to this operation returns new
|
||||
* temporary credentials. The resulting session's permissions are the intersection of the
|
||||
* role's identity-based policy and the session policies. You can use the role's temporary
|
||||
* credentials in subsequent Amazon Web Services API calls to access resources in the account that owns
|
||||
* the role. You cannot use session policies to grant more permissions than those allowed
|
||||
* by the identity-based policy of the role that is being assumed. For more information, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">Session
|
||||
* Policies</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>When you create a role, you create two policies: a role trust policy that specifies
|
||||
* <i>who</i> can assume the role, and a permissions policy that specifies
|
||||
* <i>what</i> can be done with the role. You specify the trusted principal
|
||||
* that is allowed to assume the role in the role trust policy.</p>
|
||||
* <p>To assume a role from a different account, your Amazon Web Services account must be trusted by the
|
||||
* role. The trust relationship is defined in the role's trust policy when the role is
|
||||
* created. That trust policy states which accounts are allowed to delegate that access to
|
||||
* users in the account. </p>
|
||||
* <p>A user who wants to access a role in a different account must also have permissions that
|
||||
* are delegated from the account administrator. The administrator must attach a policy that
|
||||
* allows the user to call <code>AssumeRole</code> for the ARN of the role in the other
|
||||
* account.</p>
|
||||
* <p>To allow a user to assume a role in the same account, you can do either of the
|
||||
* following:</p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>Attach a policy to the user that allows the user to call <code>AssumeRole</code>
|
||||
* (as long as the role's trust policy trusts the account).</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>Add the user as a principal directly in the role's trust policy.</p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* <p>You can do either because the role’s trust policy acts as an IAM resource-based
|
||||
* policy. When a resource-based policy grants access to a principal in the same account, no
|
||||
* additional identity-based policy is required. For more information about trust policies and
|
||||
* resource-based policies, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html">IAM Policies</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>Tags</b>
|
||||
* </p>
|
||||
* <p>(Optional) You can pass tag key-value pairs to your session. These tags are called
|
||||
* session tags. For more information about session tags, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>An administrator must grant you the permissions necessary to pass session tags. The
|
||||
* administrator can also create granular permissions to allow you to pass only specific
|
||||
* session tags. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_attribute-based-access-control.html">Tutorial: Using Tags
|
||||
* for Attribute-Based Access Control</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>You can set the session tags as transitive. Transitive tags persist during role
|
||||
* chaining. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html#id_session-tags_role-chaining">Chaining Roles
|
||||
* with Session Tags</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>Using MFA with AssumeRole</b>
|
||||
* </p>
|
||||
* <p>(Optional) You can include multi-factor authentication (MFA) information when you call
|
||||
* <code>AssumeRole</code>. This is useful for cross-account scenarios to ensure that the
|
||||
* user that assumes the role has been authenticated with an Amazon Web Services MFA device. In that
|
||||
* scenario, the trust policy of the role being assumed includes a condition that tests for
|
||||
* MFA authentication. If the caller does not include valid MFA information, the request to
|
||||
* assume the role is denied. The condition in a trust policy that tests for MFA
|
||||
* authentication might look like the following example.</p>
|
||||
* <p>
|
||||
* <code>"Condition": \{"Bool": \{"aws:MultiFactorAuthPresent": true\}\}</code>
|
||||
* </p>
|
||||
* <p>For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/MFAProtectedAPI.html">Configuring MFA-Protected API Access</a>
|
||||
* in the <i>IAM User Guide</i> guide.</p>
|
||||
* <p>To use MFA with <code>AssumeRole</code>, you pass values for the
|
||||
* <code>SerialNumber</code> and <code>TokenCode</code> parameters. The
|
||||
* <code>SerialNumber</code> value identifies the user's hardware or virtual MFA device.
|
||||
* The <code>TokenCode</code> is the time-based one-time password (TOTP) that the MFA device
|
||||
* produces. </p>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, AssumeRoleCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, AssumeRoleCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // AssumeRoleRequest
|
||||
* RoleArn: "STRING_VALUE", // required
|
||||
* RoleSessionName: "STRING_VALUE", // required
|
||||
* PolicyArns: [ // policyDescriptorListType
|
||||
* { // PolicyDescriptorType
|
||||
* arn: "STRING_VALUE",
|
||||
* },
|
||||
* ],
|
||||
* Policy: "STRING_VALUE",
|
||||
* DurationSeconds: Number("int"),
|
||||
* Tags: [ // tagListType
|
||||
* { // Tag
|
||||
* Key: "STRING_VALUE", // required
|
||||
* Value: "STRING_VALUE", // required
|
||||
* },
|
||||
* ],
|
||||
* TransitiveTagKeys: [ // tagKeyListType
|
||||
* "STRING_VALUE",
|
||||
* ],
|
||||
* ExternalId: "STRING_VALUE",
|
||||
* SerialNumber: "STRING_VALUE",
|
||||
* TokenCode: "STRING_VALUE",
|
||||
* SourceIdentity: "STRING_VALUE",
|
||||
* ProvidedContexts: [ // ProvidedContextsListType
|
||||
* { // ProvidedContext
|
||||
* ProviderArn: "STRING_VALUE",
|
||||
* ContextAssertion: "STRING_VALUE",
|
||||
* },
|
||||
* ],
|
||||
* };
|
||||
* const command = new AssumeRoleCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // AssumeRoleResponse
|
||||
* // Credentials: { // Credentials
|
||||
* // AccessKeyId: "STRING_VALUE", // required
|
||||
* // SecretAccessKey: "STRING_VALUE", // required
|
||||
* // SessionToken: "STRING_VALUE", // required
|
||||
* // Expiration: new Date("TIMESTAMP"), // required
|
||||
* // },
|
||||
* // AssumedRoleUser: { // AssumedRoleUser
|
||||
* // AssumedRoleId: "STRING_VALUE", // required
|
||||
* // Arn: "STRING_VALUE", // required
|
||||
* // },
|
||||
* // PackedPolicySize: Number("int"),
|
||||
* // SourceIdentity: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param AssumeRoleCommandInput - {@link AssumeRoleCommandInput}
|
||||
* @returns {@link AssumeRoleCommandOutput}
|
||||
* @see {@link AssumeRoleCommandInput} for command's `input` shape.
|
||||
* @see {@link AssumeRoleCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link ExpiredTokenException} (client fault)
|
||||
* <p>The web identity token that was passed is expired or is not valid. Get a new identity
|
||||
* token from the identity provider and then retry the request.</p>
|
||||
*
|
||||
* @throws {@link MalformedPolicyDocumentException} (client fault)
|
||||
* <p>The request was rejected because the policy document was malformed. The error message
|
||||
* describes the specific error.</p>
|
||||
*
|
||||
* @throws {@link PackedPolicyTooLargeException} (client fault)
|
||||
* <p>The request was rejected because the total packed size of the session policies and
|
||||
* session tags combined was too large. An Amazon Web Services conversion compresses the session policy
|
||||
* document, session policy ARNs, and session tags into a packed binary format that has a
|
||||
* separate limit. The error message indicates by percentage how close the policies and
|
||||
* tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in
|
||||
* the <i>IAM User Guide</i>.</p>
|
||||
* <p>You could receive this error even though you meet other defined session policy and
|
||||
* session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity
|
||||
* Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link RegionDisabledException} (client fault)
|
||||
* <p>STS is not activated in the requested region for the account that is being asked to
|
||||
* generate credentials. The account administrator must use the IAM console to activate STS
|
||||
* in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and
|
||||
* Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User
|
||||
* Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To assume a role
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "ExternalId": "123ABC",
|
||||
* "Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"Stmt1\",\"Effect\":\"Allow\",\"Action\":\"s3:ListAllMyBuckets\",\"Resource\":\"*\"}]}",
|
||||
* "RoleArn": "arn:aws:iam::123456789012:role/demo",
|
||||
* "RoleSessionName": "testAssumeRoleSession",
|
||||
* "Tags": [
|
||||
* {
|
||||
* "Key": "Project",
|
||||
* "Value": "Unicorn"
|
||||
* },
|
||||
* {
|
||||
* "Key": "Team",
|
||||
* "Value": "Automation"
|
||||
* },
|
||||
* {
|
||||
* "Key": "Cost-Center",
|
||||
* "Value": "12345"
|
||||
* }
|
||||
* ],
|
||||
* "TransitiveTagKeys": [
|
||||
* "Project",
|
||||
* "Cost-Center"
|
||||
* ]
|
||||
* };
|
||||
* const command = new AssumeRoleCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "AssumedRoleUser": {
|
||||
* "Arn": "arn:aws:sts::123456789012:assumed-role/demo/Bob",
|
||||
* "AssumedRoleId": "ARO123EXAMPLE123:Bob"
|
||||
* },
|
||||
* "Credentials": {
|
||||
* "AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
|
||||
* "Expiration": "2011-07-15T23:28:33.359Z",
|
||||
* "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY",
|
||||
* "SessionToken": "AQoDYXdzEPT//////////wEXAMPLEtc764bNrC9SAPBSM22wDOk4x4HIZ8j4FZTwdQWLWsKWHGBuFqwAeMicRXmxfpSPfIeoIYRqTflfKD8YUuwthAx7mSEI/qkPpKPi/kMcGdQrmGdeehM4IC1NtBmUpp2wUE8phUZampKsburEDy0KPkyQDYwT7WZ0wq5VSXDvp75YU9HFvlRd8Tx6q6fE8YQcHNVXAkiY9q6d+xo0rKwT38xVqr7ZD0u0iPPkUL64lIZbqBAz+scqKmlzm8FDrypNC9Yjc8fPOLn9FX9KSYvKTr4rvx3iSIlTJabIQwj2ICCR/oLxBA=="
|
||||
* },
|
||||
* "PackedPolicySize": 8
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-assume-a-role-1480532402212
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class AssumeRoleCommand extends $Command<AssumeRoleCommandInput, AssumeRoleCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: AssumeRoleCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: AssumeRoleCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<AssumeRoleCommandInput, AssumeRoleCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-296
@@ -1,296 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { AssumeRoleWithSAMLRequest, AssumeRoleWithSAMLResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link AssumeRoleWithSAMLCommand}.
|
||||
*/
|
||||
export interface AssumeRoleWithSAMLCommandInput extends AssumeRoleWithSAMLRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link AssumeRoleWithSAMLCommand}.
|
||||
*/
|
||||
export interface AssumeRoleWithSAMLCommandOutput extends AssumeRoleWithSAMLResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns a set of temporary security credentials for users who have been authenticated
|
||||
* via a SAML authentication response. This operation provides a mechanism for tying an
|
||||
* enterprise identity store or directory to role-based Amazon Web Services access without user-specific
|
||||
* credentials or configuration. For a comparison of <code>AssumeRoleWithSAML</code> with the
|
||||
* other API operations that produce temporary credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html">Requesting Temporary Security
|
||||
* Credentials</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#stsapi_comparison">Comparing the
|
||||
* Amazon Web Services STS API operations</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>The temporary security credentials returned by this operation consist of an access key
|
||||
* ID, a secret access key, and a security token. Applications can use these temporary
|
||||
* security credentials to sign calls to Amazon Web Services services.</p>
|
||||
* <p>
|
||||
* <b>Session Duration</b>
|
||||
* </p>
|
||||
* <p>By default, the temporary security credentials created by
|
||||
* <code>AssumeRoleWithSAML</code> last for one hour. However, you can use the optional
|
||||
* <code>DurationSeconds</code> parameter to specify the duration of your session. Your
|
||||
* role session lasts for the duration that you specify, or until the time specified in the
|
||||
* SAML authentication response's <code>SessionNotOnOrAfter</code> value, whichever is
|
||||
* shorter. You can provide a <code>DurationSeconds</code> value from 900 seconds (15 minutes)
|
||||
* up to the maximum session duration setting for the role. This setting can have a value from
|
||||
* 1 hour to 12 hours. To learn how to view the maximum value for your role, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use.html#id_roles_use_view-role-max-session">View the
|
||||
* Maximum Session Duration Setting for a Role</a> in the
|
||||
* <i>IAM User Guide</i>. The maximum session duration limit applies when
|
||||
* you use the <code>AssumeRole*</code> API operations or the <code>assume-role*</code> CLI
|
||||
* commands. However the limit does not apply when you use those operations to create a
|
||||
* console URL. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use.html">Using IAM Roles</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <note>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_terms-and-concepts.html#iam-term-role-chaining">Role chaining</a> limits your CLI or Amazon Web Services API role
|
||||
* session to a maximum of one hour. When you use the <code>AssumeRole</code> API operation
|
||||
* to assume a role, you can specify the duration of your role session with the
|
||||
* <code>DurationSeconds</code> parameter. You can specify a parameter value of up to
|
||||
* 43200 seconds (12 hours), depending on the maximum session duration setting for your
|
||||
* role. However, if you assume a role using role chaining and provide a
|
||||
* <code>DurationSeconds</code> parameter value greater than one hour, the operation
|
||||
* fails.</p>
|
||||
* </note>
|
||||
* <p>
|
||||
* <b>Permissions</b>
|
||||
* </p>
|
||||
* <p>The temporary security credentials created by <code>AssumeRoleWithSAML</code> can be
|
||||
* used to make API calls to any Amazon Web Services service with the following exception: you cannot call
|
||||
* the STS <code>GetFederationToken</code> or <code>GetSessionToken</code> API
|
||||
* operations.</p>
|
||||
* <p>(Optional) You can pass inline or managed <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">session policies</a> to
|
||||
* this operation. You can pass a single JSON policy document to use as an inline session
|
||||
* policy. You can also specify up to 10 managed policy Amazon Resource Names (ARNs) to use as
|
||||
* managed session policies. The plaintext that you use for both inline and managed session
|
||||
* policies can't exceed 2,048 characters. Passing policies to this operation returns new
|
||||
* temporary credentials. The resulting session's permissions are the intersection of the
|
||||
* role's identity-based policy and the session policies. You can use the role's temporary
|
||||
* credentials in subsequent Amazon Web Services API calls to access resources in the account that owns
|
||||
* the role. You cannot use session policies to grant more permissions than those allowed
|
||||
* by the identity-based policy of the role that is being assumed. For more information, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">Session
|
||||
* Policies</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>Calling <code>AssumeRoleWithSAML</code> does not require the use of Amazon Web Services security
|
||||
* credentials. The identity of the caller is validated by using keys in the metadata document
|
||||
* that is uploaded for the SAML provider entity for your identity provider. </p>
|
||||
* <important>
|
||||
* <p>Calling <code>AssumeRoleWithSAML</code> can result in an entry in your CloudTrail logs.
|
||||
* The entry includes the value in the <code>NameID</code> element of the SAML assertion.
|
||||
* We recommend that you use a <code>NameIDType</code> that is not associated with any
|
||||
* personally identifiable information (PII). For example, you could instead use the
|
||||
* persistent identifier
|
||||
* (<code>urn:oasis:names:tc:SAML:2.0:nameid-format:persistent</code>).</p>
|
||||
* </important>
|
||||
* <p>
|
||||
* <b>Tags</b>
|
||||
* </p>
|
||||
* <p>(Optional) You can configure your IdP to pass attributes into your SAML assertion as
|
||||
* session tags. Each session tag consists of a key name and an associated value. For more
|
||||
* information about session tags, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>You can pass up to 50 session tags. The plaintext session tag keys can’t exceed 128
|
||||
* characters and the values can’t exceed 256 characters. For these and additional limits, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-limits.html#reference_iam-limits-entity-length">IAM
|
||||
* and STS Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <note>
|
||||
* <p>An Amazon Web Services conversion compresses the passed inline session policy, managed policy ARNs,
|
||||
* and session tags into a packed binary format that has a separate limit. Your request can
|
||||
* fail for this limit even if your plaintext meets the other requirements. The
|
||||
* <code>PackedPolicySize</code> response element indicates by percentage how close the
|
||||
* policies and tags for your request are to the upper size limit.</p>
|
||||
* </note>
|
||||
* <p>You can pass a session tag with the same key as a tag that is attached to the role. When
|
||||
* you do, session tags override the role's tags with the same key.</p>
|
||||
* <p>An administrator must grant you the permissions necessary to pass session tags. The
|
||||
* administrator can also create granular permissions to allow you to pass only specific
|
||||
* session tags. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_attribute-based-access-control.html">Tutorial: Using Tags
|
||||
* for Attribute-Based Access Control</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>You can set the session tags as transitive. Transitive tags persist during role
|
||||
* chaining. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html#id_session-tags_role-chaining">Chaining Roles
|
||||
* with Session Tags</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>SAML Configuration</b>
|
||||
* </p>
|
||||
* <p>Before your application can call <code>AssumeRoleWithSAML</code>, you must configure
|
||||
* your SAML identity provider (IdP) to issue the claims required by Amazon Web Services. Additionally, you
|
||||
* must use Identity and Access Management (IAM) to create a SAML provider entity in your Amazon Web Services account that
|
||||
* represents your identity provider. You must also create an IAM role that specifies this
|
||||
* SAML provider in its trust policy. </p>
|
||||
* <p>For more information, see the following resources:</p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_saml.html">About
|
||||
* SAML 2.0-based Federation</a> in the <i>IAM User Guide</i>.
|
||||
* </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_saml.html">Creating SAML Identity Providers</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_create_saml_relying-party.html">Configuring
|
||||
* a Relying Party and Claims</a> in the <i>IAM User Guide</i>.
|
||||
* </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_create_for-idp_saml.html">Creating a Role for SAML 2.0 Federation</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, AssumeRoleWithSAMLCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, AssumeRoleWithSAMLCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // AssumeRoleWithSAMLRequest
|
||||
* RoleArn: "STRING_VALUE", // required
|
||||
* PrincipalArn: "STRING_VALUE", // required
|
||||
* SAMLAssertion: "STRING_VALUE", // required
|
||||
* PolicyArns: [ // policyDescriptorListType
|
||||
* { // PolicyDescriptorType
|
||||
* arn: "STRING_VALUE",
|
||||
* },
|
||||
* ],
|
||||
* Policy: "STRING_VALUE",
|
||||
* DurationSeconds: Number("int"),
|
||||
* };
|
||||
* const command = new AssumeRoleWithSAMLCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // AssumeRoleWithSAMLResponse
|
||||
* // Credentials: { // Credentials
|
||||
* // AccessKeyId: "STRING_VALUE", // required
|
||||
* // SecretAccessKey: "STRING_VALUE", // required
|
||||
* // SessionToken: "STRING_VALUE", // required
|
||||
* // Expiration: new Date("TIMESTAMP"), // required
|
||||
* // },
|
||||
* // AssumedRoleUser: { // AssumedRoleUser
|
||||
* // AssumedRoleId: "STRING_VALUE", // required
|
||||
* // Arn: "STRING_VALUE", // required
|
||||
* // },
|
||||
* // PackedPolicySize: Number("int"),
|
||||
* // Subject: "STRING_VALUE",
|
||||
* // SubjectType: "STRING_VALUE",
|
||||
* // Issuer: "STRING_VALUE",
|
||||
* // Audience: "STRING_VALUE",
|
||||
* // NameQualifier: "STRING_VALUE",
|
||||
* // SourceIdentity: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param AssumeRoleWithSAMLCommandInput - {@link AssumeRoleWithSAMLCommandInput}
|
||||
* @returns {@link AssumeRoleWithSAMLCommandOutput}
|
||||
* @see {@link AssumeRoleWithSAMLCommandInput} for command's `input` shape.
|
||||
* @see {@link AssumeRoleWithSAMLCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link ExpiredTokenException} (client fault)
|
||||
* <p>The web identity token that was passed is expired or is not valid. Get a new identity
|
||||
* token from the identity provider and then retry the request.</p>
|
||||
*
|
||||
* @throws {@link IDPRejectedClaimException} (client fault)
|
||||
* <p>The identity provider (IdP) reported that authentication failed. This might be because
|
||||
* the claim is invalid.</p>
|
||||
* <p>If this error is returned for the <code>AssumeRoleWithWebIdentity</code> operation, it
|
||||
* can also mean that the claim has expired or has been explicitly revoked. </p>
|
||||
*
|
||||
* @throws {@link InvalidIdentityTokenException} (client fault)
|
||||
* <p>The web identity token that was passed could not be validated by Amazon Web Services. Get a new
|
||||
* identity token from the identity provider and then retry the request.</p>
|
||||
*
|
||||
* @throws {@link MalformedPolicyDocumentException} (client fault)
|
||||
* <p>The request was rejected because the policy document was malformed. The error message
|
||||
* describes the specific error.</p>
|
||||
*
|
||||
* @throws {@link PackedPolicyTooLargeException} (client fault)
|
||||
* <p>The request was rejected because the total packed size of the session policies and
|
||||
* session tags combined was too large. An Amazon Web Services conversion compresses the session policy
|
||||
* document, session policy ARNs, and session tags into a packed binary format that has a
|
||||
* separate limit. The error message indicates by percentage how close the policies and
|
||||
* tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in
|
||||
* the <i>IAM User Guide</i>.</p>
|
||||
* <p>You could receive this error even though you meet other defined session policy and
|
||||
* session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity
|
||||
* Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link RegionDisabledException} (client fault)
|
||||
* <p>STS is not activated in the requested region for the account that is being asked to
|
||||
* generate credentials. The account administrator must use the IAM console to activate STS
|
||||
* in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and
|
||||
* Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User
|
||||
* Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To assume a role using a SAML assertion
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "DurationSeconds": 3600,
|
||||
* "PrincipalArn": "arn:aws:iam::123456789012:saml-provider/SAML-test",
|
||||
* "RoleArn": "arn:aws:iam::123456789012:role/TestSaml",
|
||||
* "SAMLAssertion": "VERYLONGENCODEDASSERTIONEXAMPLExzYW1sOkF1ZGllbmNlPmJsYW5rPC9zYW1sOkF1ZGllbmNlPjwvc2FtbDpBdWRpZW5jZVJlc3RyaWN0aW9uPjwvc2FtbDpDb25kaXRpb25zPjxzYW1sOlN1YmplY3Q+PHNhbWw6TmFtZUlEIEZvcm1hdD0idXJuOm9hc2lzOm5hbWVzOnRjOlNBTUw6Mi4wOm5hbWVpZC1mb3JtYXQ6dHJhbnNpZW50Ij5TYW1sRXhhbXBsZTwvc2FtbDpOYW1lSUQ+PHNhbWw6U3ViamVjdENvbmZpcm1hdGlvbiBNZXRob2Q9InVybjpvYXNpczpuYW1lczp0YzpTQU1MOjIuMDpjbTpiZWFyZXIiPjxzYW1sOlN1YmplY3RDb25maXJtYXRpb25EYXRhIE5vdE9uT3JBZnRlcj0iMjAxOS0xMS0wMVQyMDoyNTowNS4xNDVaIiBSZWNpcGllbnQ9Imh0dHBzOi8vc2lnbmluLmF3cy5hbWF6b24uY29tL3NhbWwiLz48L3NhbWw6U3ViamVjdENvbmZpcm1hdGlvbj48L3NhbWw6U3ViamVjdD48c2FtbDpBdXRoblN0YXRlbWVudCBBdXRoPD94bWwgdmpSZXNwb25zZT4="
|
||||
* };
|
||||
* const command = new AssumeRoleWithSAMLCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "AssumedRoleUser": {
|
||||
* "Arn": "arn:aws:sts::123456789012:assumed-role/TestSaml",
|
||||
* "AssumedRoleId": "ARO456EXAMPLE789:TestSaml"
|
||||
* },
|
||||
* "Audience": "https://signin.aws.amazon.com/saml",
|
||||
* "Credentials": {
|
||||
* "AccessKeyId": "ASIAV3ZUEFP6EXAMPLE",
|
||||
* "Expiration": "2019-11-01T20:26:47Z",
|
||||
* "SecretAccessKey": "8P+SQvWIuLnKhh8d++jpw0nNmQRBZvNEXAMPLEKEY",
|
||||
* "SessionToken": "IQoJb3JpZ2luX2VjEOz////////////////////wEXAMPLEtMSJHMEUCIDoKK3JH9uGQE1z0sINr5M4jk+Na8KHDcCYRVjJCZEvOAiEA3OvJGtw1EcViOleS2vhs8VdCKFJQWPQrmGdeehM4IC1NtBmUpp2wUE8phUZampKsburEDy0KPkyQDYwT7WZ0wq5VSXDvp75YU9HFvlRd8Tx6q6fE8YQcHNVXAkiY9q6d+xo0rKwT38xVqr7ZD0u0iPPkUL64lIZbqBAz+scqKmlzm8FDrypNC9Yjc8fPOLn9FX9KSYvKTr4rvx3iSIlTJabIQwj2ICCR/oLxBA=="
|
||||
* },
|
||||
* "Issuer": "https://integ.example.com/idp/shibboleth",
|
||||
* "NameQualifier": "SbdGOnUkh1i4+EXAMPLExL/jEvs=",
|
||||
* "PackedPolicySize": 6,
|
||||
* "Subject": "SamlExample",
|
||||
* "SubjectType": "transient"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-assume-role-with-saml-14882749597814
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class AssumeRoleWithSAMLCommand extends $Command<AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: AssumeRoleWithSAMLCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: AssumeRoleWithSAMLCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-305
@@ -1,305 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { AssumeRoleWithWebIdentityRequest, AssumeRoleWithWebIdentityResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link AssumeRoleWithWebIdentityCommand}.
|
||||
*/
|
||||
export interface AssumeRoleWithWebIdentityCommandInput extends AssumeRoleWithWebIdentityRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link AssumeRoleWithWebIdentityCommand}.
|
||||
*/
|
||||
export interface AssumeRoleWithWebIdentityCommandOutput extends AssumeRoleWithWebIdentityResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns a set of temporary security credentials for users who have been authenticated in
|
||||
* a mobile or web application with a web identity provider. Example providers include the
|
||||
* OAuth 2.0 providers Login with Amazon and Facebook, or any OpenID Connect-compatible
|
||||
* identity provider such as Google or <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-identity.html">Amazon Cognito federated identities</a>.</p>
|
||||
* <note>
|
||||
* <p>For mobile applications, we recommend that you use Amazon Cognito. You can use Amazon Cognito with the
|
||||
* <a href="http://aws.amazon.com/sdkforios/">Amazon Web Services SDK for iOS Developer Guide</a> and the <a href="http://aws.amazon.com/sdkforandroid/">Amazon Web Services SDK for Android Developer Guide</a> to uniquely
|
||||
* identify a user. You can also supply the user with a consistent identity throughout the
|
||||
* lifetime of an application.</p>
|
||||
* <p>To learn more about Amazon Cognito, see <a href="https://docs.aws.amazon.com/cognito/latest/developerguide/cognito-identity.html">Amazon Cognito identity
|
||||
* pools</a> in <i>Amazon Cognito Developer Guide</i>.</p>
|
||||
* </note>
|
||||
* <p>Calling <code>AssumeRoleWithWebIdentity</code> does not require the use of Amazon Web Services
|
||||
* security credentials. Therefore, you can distribute an application (for example, on mobile
|
||||
* devices) that requests temporary security credentials without including long-term Amazon Web Services
|
||||
* credentials in the application. You also don't need to deploy server-based proxy services
|
||||
* that use long-term Amazon Web Services credentials. Instead, the identity of the caller is validated by
|
||||
* using a token from the web identity provider. For a comparison of
|
||||
* <code>AssumeRoleWithWebIdentity</code> with the other API operations that produce
|
||||
* temporary credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html">Requesting Temporary Security
|
||||
* Credentials</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#stsapi_comparison">Comparing the
|
||||
* Amazon Web Services STS API operations</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>The temporary security credentials returned by this API consist of an access key ID, a
|
||||
* secret access key, and a security token. Applications can use these temporary security
|
||||
* credentials to sign calls to Amazon Web Services service API operations.</p>
|
||||
* <p>
|
||||
* <b>Session Duration</b>
|
||||
* </p>
|
||||
* <p>By default, the temporary security credentials created by
|
||||
* <code>AssumeRoleWithWebIdentity</code> last for one hour. However, you can use the
|
||||
* optional <code>DurationSeconds</code> parameter to specify the duration of your session.
|
||||
* You can provide a value from 900 seconds (15 minutes) up to the maximum session duration
|
||||
* setting for the role. This setting can have a value from 1 hour to 12 hours. To learn how
|
||||
* to view the maximum value for your role, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use.html#id_roles_use_view-role-max-session">View the
|
||||
* Maximum Session Duration Setting for a Role</a> in the
|
||||
* <i>IAM User Guide</i>. The maximum session duration limit applies when
|
||||
* you use the <code>AssumeRole*</code> API operations or the <code>assume-role*</code> CLI
|
||||
* commands. However the limit does not apply when you use those operations to create a
|
||||
* console URL. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use.html">Using IAM Roles</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* <p>
|
||||
* <b>Permissions</b>
|
||||
* </p>
|
||||
* <p>The temporary security credentials created by <code>AssumeRoleWithWebIdentity</code> can
|
||||
* be used to make API calls to any Amazon Web Services service with the following exception: you cannot
|
||||
* call the STS <code>GetFederationToken</code> or <code>GetSessionToken</code> API
|
||||
* operations.</p>
|
||||
* <p>(Optional) You can pass inline or managed <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">session policies</a> to
|
||||
* this operation. You can pass a single JSON policy document to use as an inline session
|
||||
* policy. You can also specify up to 10 managed policy Amazon Resource Names (ARNs) to use as
|
||||
* managed session policies. The plaintext that you use for both inline and managed session
|
||||
* policies can't exceed 2,048 characters. Passing policies to this operation returns new
|
||||
* temporary credentials. The resulting session's permissions are the intersection of the
|
||||
* role's identity-based policy and the session policies. You can use the role's temporary
|
||||
* credentials in subsequent Amazon Web Services API calls to access resources in the account that owns
|
||||
* the role. You cannot use session policies to grant more permissions than those allowed
|
||||
* by the identity-based policy of the role that is being assumed. For more information, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">Session
|
||||
* Policies</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>Tags</b>
|
||||
* </p>
|
||||
* <p>(Optional) You can configure your IdP to pass attributes into your web identity token as
|
||||
* session tags. Each session tag consists of a key name and an associated value. For more
|
||||
* information about session tags, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>You can pass up to 50 session tags. The plaintext session tag keys can’t exceed 128
|
||||
* characters and the values can’t exceed 256 characters. For these and additional limits, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-limits.html#reference_iam-limits-entity-length">IAM
|
||||
* and STS Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <note>
|
||||
* <p>An Amazon Web Services conversion compresses the passed inline session policy, managed policy ARNs,
|
||||
* and session tags into a packed binary format that has a separate limit. Your request can
|
||||
* fail for this limit even if your plaintext meets the other requirements. The
|
||||
* <code>PackedPolicySize</code> response element indicates by percentage how close the
|
||||
* policies and tags for your request are to the upper size limit.</p>
|
||||
* </note>
|
||||
* <p>You can pass a session tag with the same key as a tag that is attached to the role. When
|
||||
* you do, the session tag overrides the role tag with the same key.</p>
|
||||
* <p>An administrator must grant you the permissions necessary to pass session tags. The
|
||||
* administrator can also create granular permissions to allow you to pass only specific
|
||||
* session tags. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_attribute-based-access-control.html">Tutorial: Using Tags
|
||||
* for Attribute-Based Access Control</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>You can set the session tags as transitive. Transitive tags persist during role
|
||||
* chaining. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html#id_session-tags_role-chaining">Chaining Roles
|
||||
* with Session Tags</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>
|
||||
* <b>Identities</b>
|
||||
* </p>
|
||||
* <p>Before your application can call <code>AssumeRoleWithWebIdentity</code>, you must have
|
||||
* an identity token from a supported identity provider and create a role that the application
|
||||
* can assume. The role that your application assumes must trust the identity provider that is
|
||||
* associated with the identity token. In other words, the identity provider must be specified
|
||||
* in the role's trust policy. </p>
|
||||
* <important>
|
||||
* <p>Calling <code>AssumeRoleWithWebIdentity</code> can result in an entry in your
|
||||
* CloudTrail logs. The entry includes the <a href="http://openid.net/specs/openid-connect-core-1_0.html#Claims">Subject</a> of
|
||||
* the provided web identity token. We recommend that you avoid using any personally
|
||||
* identifiable information (PII) in this field. For example, you could instead use a GUID
|
||||
* or a pairwise identifier, as <a href="http://openid.net/specs/openid-connect-core-1_0.html#SubjectIDTypes">suggested
|
||||
* in the OIDC specification</a>.</p>
|
||||
* </important>
|
||||
* <p>For more information about how to use web identity federation and the
|
||||
* <code>AssumeRoleWithWebIdentity</code> API, see the following resources: </p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_providers_oidc_manual.html">Using Web Identity Federation API Operations for Mobile Apps</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#api_assumerolewithwebidentity">Federation Through a Web-based Identity Provider</a>. </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="https://aws.amazon.com/blogs/aws/the-aws-web-identity-federation-playground/"> Web Identity Federation Playground</a>. Walk through the process of
|
||||
* authenticating through Login with Amazon, Facebook, or Google, getting temporary
|
||||
* security credentials, and then using those credentials to make a request to Amazon Web Services.
|
||||
* </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="http://aws.amazon.com/sdkforios/">Amazon Web Services SDK for iOS Developer Guide</a> and <a href="http://aws.amazon.com/sdkforandroid/">Amazon Web Services SDK for Android Developer Guide</a>. These toolkits
|
||||
* contain sample apps that show how to invoke the identity providers. The toolkits then
|
||||
* show how to use the information from these providers to get and use temporary
|
||||
* security credentials. </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>
|
||||
* <a href="http://aws.amazon.com/articles/web-identity-federation-with-mobile-applications">Web Identity
|
||||
* Federation with Mobile Applications</a>. This article discusses web identity
|
||||
* federation and shows an example of how to use web identity federation to get access
|
||||
* to content in Amazon S3. </p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, AssumeRoleWithWebIdentityCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, AssumeRoleWithWebIdentityCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // AssumeRoleWithWebIdentityRequest
|
||||
* RoleArn: "STRING_VALUE", // required
|
||||
* RoleSessionName: "STRING_VALUE", // required
|
||||
* WebIdentityToken: "STRING_VALUE", // required
|
||||
* ProviderId: "STRING_VALUE",
|
||||
* PolicyArns: [ // policyDescriptorListType
|
||||
* { // PolicyDescriptorType
|
||||
* arn: "STRING_VALUE",
|
||||
* },
|
||||
* ],
|
||||
* Policy: "STRING_VALUE",
|
||||
* DurationSeconds: Number("int"),
|
||||
* };
|
||||
* const command = new AssumeRoleWithWebIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // AssumeRoleWithWebIdentityResponse
|
||||
* // Credentials: { // Credentials
|
||||
* // AccessKeyId: "STRING_VALUE", // required
|
||||
* // SecretAccessKey: "STRING_VALUE", // required
|
||||
* // SessionToken: "STRING_VALUE", // required
|
||||
* // Expiration: new Date("TIMESTAMP"), // required
|
||||
* // },
|
||||
* // SubjectFromWebIdentityToken: "STRING_VALUE",
|
||||
* // AssumedRoleUser: { // AssumedRoleUser
|
||||
* // AssumedRoleId: "STRING_VALUE", // required
|
||||
* // Arn: "STRING_VALUE", // required
|
||||
* // },
|
||||
* // PackedPolicySize: Number("int"),
|
||||
* // Provider: "STRING_VALUE",
|
||||
* // Audience: "STRING_VALUE",
|
||||
* // SourceIdentity: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param AssumeRoleWithWebIdentityCommandInput - {@link AssumeRoleWithWebIdentityCommandInput}
|
||||
* @returns {@link AssumeRoleWithWebIdentityCommandOutput}
|
||||
* @see {@link AssumeRoleWithWebIdentityCommandInput} for command's `input` shape.
|
||||
* @see {@link AssumeRoleWithWebIdentityCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link ExpiredTokenException} (client fault)
|
||||
* <p>The web identity token that was passed is expired or is not valid. Get a new identity
|
||||
* token from the identity provider and then retry the request.</p>
|
||||
*
|
||||
* @throws {@link IDPCommunicationErrorException} (client fault)
|
||||
* <p>The request could not be fulfilled because the identity provider (IDP) that
|
||||
* was asked to verify the incoming identity token could not be reached. This is often a
|
||||
* transient error caused by network conditions. Retry the request a limited number of
|
||||
* times so that you don't exceed the request rate. If the error persists, the
|
||||
* identity provider might be down or not responding.</p>
|
||||
*
|
||||
* @throws {@link IDPRejectedClaimException} (client fault)
|
||||
* <p>The identity provider (IdP) reported that authentication failed. This might be because
|
||||
* the claim is invalid.</p>
|
||||
* <p>If this error is returned for the <code>AssumeRoleWithWebIdentity</code> operation, it
|
||||
* can also mean that the claim has expired or has been explicitly revoked. </p>
|
||||
*
|
||||
* @throws {@link InvalidIdentityTokenException} (client fault)
|
||||
* <p>The web identity token that was passed could not be validated by Amazon Web Services. Get a new
|
||||
* identity token from the identity provider and then retry the request.</p>
|
||||
*
|
||||
* @throws {@link MalformedPolicyDocumentException} (client fault)
|
||||
* <p>The request was rejected because the policy document was malformed. The error message
|
||||
* describes the specific error.</p>
|
||||
*
|
||||
* @throws {@link PackedPolicyTooLargeException} (client fault)
|
||||
* <p>The request was rejected because the total packed size of the session policies and
|
||||
* session tags combined was too large. An Amazon Web Services conversion compresses the session policy
|
||||
* document, session policy ARNs, and session tags into a packed binary format that has a
|
||||
* separate limit. The error message indicates by percentage how close the policies and
|
||||
* tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in
|
||||
* the <i>IAM User Guide</i>.</p>
|
||||
* <p>You could receive this error even though you meet other defined session policy and
|
||||
* session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity
|
||||
* Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link RegionDisabledException} (client fault)
|
||||
* <p>STS is not activated in the requested region for the account that is being asked to
|
||||
* generate credentials. The account administrator must use the IAM console to activate STS
|
||||
* in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and
|
||||
* Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User
|
||||
* Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To assume a role as an OpenID Connect-federated user
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "DurationSeconds": 3600,
|
||||
* "Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"Stmt1\",\"Effect\":\"Allow\",\"Action\":\"s3:ListAllMyBuckets\",\"Resource\":\"*\"}]}",
|
||||
* "ProviderId": "www.amazon.com",
|
||||
* "RoleArn": "arn:aws:iam::123456789012:role/FederatedWebIdentityRole",
|
||||
* "RoleSessionName": "app1",
|
||||
* "WebIdentityToken": "Atza%7CIQEBLjAsAhRFiXuWpUXuRvQ9PZL3GMFcYevydwIUFAHZwXZXXXXXXXXJnrulxKDHwy87oGKPznh0D6bEQZTSCzyoCtL_8S07pLpr0zMbn6w1lfVZKNTBdDansFBmtGnIsIapjI6xKR02Yc_2bQ8LZbUXSGm6Ry6_BG7PrtLZtj_dfCTj92xNGed-CrKqjG7nPBjNIL016GGvuS5gSvPRUxWES3VYfm1wl7WTI7jn-Pcb6M-buCgHhFOzTQxod27L9CqnOLio7N3gZAGpsp6n1-AJBOCJckcyXe2c6uD0srOJeZlKUm2eTDVMf8IehDVI0r1QOnTV6KzzAI3OY87Vd_cVMQ"
|
||||
* };
|
||||
* const command = new AssumeRoleWithWebIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "AssumedRoleUser": {
|
||||
* "Arn": "arn:aws:sts::123456789012:assumed-role/FederatedWebIdentityRole/app1",
|
||||
* "AssumedRoleId": "AROACLKWSDQRAOEXAMPLE:app1"
|
||||
* },
|
||||
* "Audience": "client.5498841531868486423.1548@apps.example.com",
|
||||
* "Credentials": {
|
||||
* "AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
|
||||
* "Expiration": "2014-10-24T23:00:23Z",
|
||||
* "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY",
|
||||
* "SessionToken": "AQoDYXdzEE0a8ANXXXXXXXXNO1ewxE5TijQyp+IEXAMPLE"
|
||||
* },
|
||||
* "PackedPolicySize": 123,
|
||||
* "Provider": "www.amazon.com",
|
||||
* "SubjectFromWebIdentityToken": "amzn1.account.AF6RHO7KZU5XRVQJGXK6HEXAMPLE"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-assume-a-role-as-an-openid-connect-federated-user-1480533445696
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class AssumeRoleWithWebIdentityCommand extends $Command<AssumeRoleWithWebIdentityCommandInput, AssumeRoleWithWebIdentityCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: AssumeRoleWithWebIdentityCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: AssumeRoleWithWebIdentityCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<AssumeRoleWithWebIdentityCommandInput, AssumeRoleWithWebIdentityCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-129
@@ -1,129 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { DecodeAuthorizationMessageRequest, DecodeAuthorizationMessageResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link DecodeAuthorizationMessageCommand}.
|
||||
*/
|
||||
export interface DecodeAuthorizationMessageCommandInput extends DecodeAuthorizationMessageRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link DecodeAuthorizationMessageCommand}.
|
||||
*/
|
||||
export interface DecodeAuthorizationMessageCommandOutput extends DecodeAuthorizationMessageResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Decodes additional information about the authorization status of a request from an
|
||||
* encoded message returned in response to an Amazon Web Services request.</p>
|
||||
* <p>For example, if a user is not authorized to perform an operation that he or she has
|
||||
* requested, the request returns a <code>Client.UnauthorizedOperation</code> response (an
|
||||
* HTTP 403 response). Some Amazon Web Services operations additionally return an encoded message that can
|
||||
* provide details about this authorization failure. </p>
|
||||
* <note>
|
||||
* <p>Only certain Amazon Web Services operations return an encoded authorization message. The
|
||||
* documentation for an individual operation indicates whether that operation returns an
|
||||
* encoded message in addition to returning an HTTP code.</p>
|
||||
* </note>
|
||||
* <p>The message is encoded because the details of the authorization status can contain
|
||||
* privileged information that the user who requested the operation should not see. To decode
|
||||
* an authorization status message, a user must be granted permissions through an IAM <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html">policy</a> to
|
||||
* request the <code>DecodeAuthorizationMessage</code>
|
||||
* (<code>sts:DecodeAuthorizationMessage</code>) action. </p>
|
||||
* <p>The decoded message includes the following type of information:</p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>Whether the request was denied due to an explicit deny or due to the absence of an
|
||||
* explicit allow. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_policies_evaluation-logic.html#policy-eval-denyallow">Determining Whether a Request is Allowed or Denied</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>The principal who made the request.</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>The requested action.</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>The requested resource.</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>The values of condition keys in the context of the user's request.</p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, DecodeAuthorizationMessageCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, DecodeAuthorizationMessageCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // DecodeAuthorizationMessageRequest
|
||||
* EncodedMessage: "STRING_VALUE", // required
|
||||
* };
|
||||
* const command = new DecodeAuthorizationMessageCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // DecodeAuthorizationMessageResponse
|
||||
* // DecodedMessage: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param DecodeAuthorizationMessageCommandInput - {@link DecodeAuthorizationMessageCommandInput}
|
||||
* @returns {@link DecodeAuthorizationMessageCommandOutput}
|
||||
* @see {@link DecodeAuthorizationMessageCommandInput} for command's `input` shape.
|
||||
* @see {@link DecodeAuthorizationMessageCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link InvalidAuthorizationMessageException} (client fault)
|
||||
* <p>The error returned if the message passed to <code>DecodeAuthorizationMessage</code>
|
||||
* was invalid. This can happen if the token contains invalid characters, such as
|
||||
* linebreaks. </p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To decode information about an authorization status of a request
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "EncodedMessage": "<encoded-message>"
|
||||
* };
|
||||
* const command = new DecodeAuthorizationMessageCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "DecodedMessage": "{\"allowed\": \"false\",\"explicitDeny\": \"false\",\"matchedStatements\": \"\",\"failures\": \"\",\"context\": {\"principal\": {\"id\": \"AIDACKCEVSQ6C2EXAMPLE\",\"name\": \"Bob\",\"arn\": \"arn:aws:iam::123456789012:user/Bob\"},\"action\": \"ec2:StopInstances\",\"resource\": \"arn:aws:ec2:us-east-1:123456789012:instance/i-dd01c9bd\",\"conditions\": [{\"item\": {\"key\": \"ec2:Tenancy\",\"values\": [\"default\"]},{\"item\": {\"key\": \"ec2:ResourceTag/elasticbeanstalk:environment-name\",\"values\": [\"Default-Environment\"]}},(Additional items ...)]}}"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-decode-information-about-an-authorization-status-of-a-request-1480533854499
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class DecodeAuthorizationMessageCommand extends $Command<DecodeAuthorizationMessageCommandInput, DecodeAuthorizationMessageCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: DecodeAuthorizationMessageCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: DecodeAuthorizationMessageCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<DecodeAuthorizationMessageCommandInput, DecodeAuthorizationMessageCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-89
@@ -1,89 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { GetAccessKeyInfoRequest, GetAccessKeyInfoResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link GetAccessKeyInfoCommand}.
|
||||
*/
|
||||
export interface GetAccessKeyInfoCommandInput extends GetAccessKeyInfoRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link GetAccessKeyInfoCommand}.
|
||||
*/
|
||||
export interface GetAccessKeyInfoCommandOutput extends GetAccessKeyInfoResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns the account identifier for the specified access key ID.</p>
|
||||
* <p>Access keys consist of two parts: an access key ID (for example,
|
||||
* <code>AKIAIOSFODNN7EXAMPLE</code>) and a secret access key (for example,
|
||||
* <code>wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY</code>). For more information about
|
||||
* access keys, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_access-keys.html">Managing Access Keys for IAM
|
||||
* Users</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>When you pass an access key ID to this operation, it returns the ID of the Amazon Web Services account
|
||||
* to which the keys belong. Access key IDs beginning with <code>AKIA</code> are long-term
|
||||
* credentials for an IAM user or the Amazon Web Services account root user. Access key IDs
|
||||
* beginning with <code>ASIA</code> are temporary credentials that are created using STS
|
||||
* operations. If the account in the response belongs to you, you can sign in as the root user and review your root user access keys. Then, you can pull a <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_getting-report.html">credentials
|
||||
* report</a> to learn which IAM user owns the keys. To learn who
|
||||
* requested the temporary credentials for an <code>ASIA</code> access key, view the STS
|
||||
* events in your <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html">CloudTrail logs</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>This operation does not indicate the state of the access key. The key might be active,
|
||||
* inactive, or deleted. Active keys might not have permissions to perform an operation.
|
||||
* Providing a deleted access key might return an error that the key doesn't exist.</p>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, GetAccessKeyInfoCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, GetAccessKeyInfoCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // GetAccessKeyInfoRequest
|
||||
* AccessKeyId: "STRING_VALUE", // required
|
||||
* };
|
||||
* const command = new GetAccessKeyInfoCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // GetAccessKeyInfoResponse
|
||||
* // Account: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param GetAccessKeyInfoCommandInput - {@link GetAccessKeyInfoCommandInput}
|
||||
* @returns {@link GetAccessKeyInfoCommandOutput}
|
||||
* @see {@link GetAccessKeyInfoCommandInput} for command's `input` shape.
|
||||
* @see {@link GetAccessKeyInfoCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
*/
|
||||
export declare class GetAccessKeyInfoCommand extends $Command<GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: GetAccessKeyInfoCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: GetAccessKeyInfoCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-130
@@ -1,130 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { GetCallerIdentityRequest, GetCallerIdentityResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link GetCallerIdentityCommand}.
|
||||
*/
|
||||
export interface GetCallerIdentityCommandInput extends GetCallerIdentityRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link GetCallerIdentityCommand}.
|
||||
*/
|
||||
export interface GetCallerIdentityCommandOutput extends GetCallerIdentityResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns details about the IAM user or role whose credentials are used to
|
||||
* call the operation.</p>
|
||||
* <note>
|
||||
* <p>No permissions are required to perform this operation. If an administrator attaches a
|
||||
* policy to your identity that explicitly denies access to the
|
||||
* <code>sts:GetCallerIdentity</code> action, you can still perform this operation.
|
||||
* Permissions are not required because the same information is returned when access is
|
||||
* denied. To view an example response, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_general.html#troubleshoot_general_access-denied-delete-mfa">I Am Not Authorized to Perform: iam:DeleteVirtualMFADevice</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* </note>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, GetCallerIdentityCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, GetCallerIdentityCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = {};
|
||||
* const command = new GetCallerIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // GetCallerIdentityResponse
|
||||
* // UserId: "STRING_VALUE",
|
||||
* // Account: "STRING_VALUE",
|
||||
* // Arn: "STRING_VALUE",
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param GetCallerIdentityCommandInput - {@link GetCallerIdentityCommandInput}
|
||||
* @returns {@link GetCallerIdentityCommandOutput}
|
||||
* @see {@link GetCallerIdentityCommandInput} for command's `input` shape.
|
||||
* @see {@link GetCallerIdentityCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To get details about a calling IAM user
|
||||
* ```javascript
|
||||
* // This example shows a request and response made with the credentials for a user named Alice in the AWS account 123456789012.
|
||||
* const input = {};
|
||||
* const command = new GetCallerIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "Account": "123456789012",
|
||||
* "Arn": "arn:aws:iam::123456789012:user/Alice",
|
||||
* "UserId": "AKIAI44QH8DHBEXAMPLE"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-get-details-about-a-calling-iam-user-1480540050376
|
||||
* ```
|
||||
*
|
||||
* @example To get details about a calling user federated with AssumeRole
|
||||
* ```javascript
|
||||
* // This example shows a request and response made with temporary credentials created by AssumeRole. The name of the assumed role is my-role-name, and the RoleSessionName is set to my-role-session-name.
|
||||
* const input = {};
|
||||
* const command = new GetCallerIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "Account": "123456789012",
|
||||
* "Arn": "arn:aws:sts::123456789012:assumed-role/my-role-name/my-role-session-name",
|
||||
* "UserId": "AKIAI44QH8DHBEXAMPLE:my-role-session-name"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-get-details-about-a-calling-user-federated-with-assumerole-1480540158545
|
||||
* ```
|
||||
*
|
||||
* @example To get details about a calling user federated with GetFederationToken
|
||||
* ```javascript
|
||||
* // This example shows a request and response made with temporary credentials created by using GetFederationToken. The Name parameter is set to my-federated-user-name.
|
||||
* const input = {};
|
||||
* const command = new GetCallerIdentityCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "Account": "123456789012",
|
||||
* "Arn": "arn:aws:sts::123456789012:federated-user/my-federated-user-name",
|
||||
* "UserId": "123456789012:my-federated-user-name"
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-get-details-about-a-calling-user-federated-with-getfederationtoken-1480540231316
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class GetCallerIdentityCommand extends $Command<GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: GetCallerIdentityCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: GetCallerIdentityCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-244
@@ -1,244 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { GetFederationTokenRequest, GetFederationTokenResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link GetFederationTokenCommand}.
|
||||
*/
|
||||
export interface GetFederationTokenCommandInput extends GetFederationTokenRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link GetFederationTokenCommand}.
|
||||
*/
|
||||
export interface GetFederationTokenCommandOutput extends GetFederationTokenResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns a set of temporary security credentials (consisting of an access key ID, a
|
||||
* secret access key, and a security token) for a user. A typical use is in a proxy
|
||||
* application that gets temporary security credentials on behalf of distributed applications
|
||||
* inside a corporate network.</p>
|
||||
* <p>You must call the <code>GetFederationToken</code> operation using the long-term security
|
||||
* credentials of an IAM user. As a result, this call is appropriate in
|
||||
* contexts where those credentials can be safeguarded, usually in a server-based application.
|
||||
* For a comparison of <code>GetFederationToken</code> with the other API operations that
|
||||
* produce temporary credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html">Requesting Temporary Security
|
||||
* Credentials</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#stsapi_comparison">Comparing the
|
||||
* Amazon Web Services STS API operations</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <p>Although it is possible to call <code>GetFederationToken</code> using the security
|
||||
* credentials of an Amazon Web Services account root user rather than an IAM user that you
|
||||
* create for the purpose of a proxy application, we do not recommend it. For more
|
||||
* information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#lock-away-credentials">Safeguard your root user credentials and don't use them for everyday tasks</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* <note>
|
||||
* <p>You can create a mobile-based or browser-based app that can authenticate users using
|
||||
* a web identity provider like Login with Amazon, Facebook, Google, or an OpenID
|
||||
* Connect-compatible identity provider. In this case, we recommend that you use <a href="http://aws.amazon.com/cognito/">Amazon Cognito</a> or
|
||||
* <code>AssumeRoleWithWebIdentity</code>. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#api_assumerolewithwebidentity">Federation Through a Web-based Identity Provider</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* </note>
|
||||
* <p>
|
||||
* <b>Session duration</b>
|
||||
* </p>
|
||||
* <p>The temporary credentials are valid for the specified duration, from 900 seconds (15
|
||||
* minutes) up to a maximum of 129,600 seconds (36 hours). The default session duration is
|
||||
* 43,200 seconds (12 hours). Temporary credentials obtained by using the root user
|
||||
* credentials have a maximum duration of 3,600 seconds (1 hour).</p>
|
||||
* <p>
|
||||
* <b>Permissions</b>
|
||||
* </p>
|
||||
* <p>You can use the temporary credentials created by <code>GetFederationToken</code> in any
|
||||
* Amazon Web Services service with the following exceptions:</p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>You cannot call any IAM operations using the CLI or the Amazon Web Services API. This
|
||||
* limitation does not apply to console sessions.</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>You cannot call any STS operations except <code>GetCallerIdentity</code>.</p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* <p>You can use temporary credentials for single sign-on (SSO) to the console.</p>
|
||||
* <p>You must pass an inline or managed <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">session policy</a> to
|
||||
* this operation. You can pass a single JSON policy document to use as an inline session
|
||||
* policy. You can also specify up to 10 managed policy Amazon Resource Names (ARNs) to use as
|
||||
* managed session policies. The plaintext that you use for both inline and managed session
|
||||
* policies can't exceed 2,048 characters.</p>
|
||||
* <p>Though the session policy parameters are optional, if you do not pass a policy, then the
|
||||
* resulting federated user session has no permissions. When you pass session policies, the
|
||||
* session permissions are the intersection of the IAM user policies and the
|
||||
* session policies that you pass. This gives you a way to further restrict the permissions
|
||||
* for a federated user. You cannot use session policies to grant more permissions than those
|
||||
* that are defined in the permissions policy of the IAM user. For more
|
||||
* information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies.html#policies_session">Session Policies</a> in
|
||||
* the <i>IAM User Guide</i>. For information about using
|
||||
* <code>GetFederationToken</code> to create temporary security credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#api_getfederationtoken">GetFederationToken—Federation Through a Custom Identity Broker</a>. </p>
|
||||
* <p>You can use the credentials to access a resource that has a resource-based policy. If
|
||||
* that policy specifically references the federated user session in the
|
||||
* <code>Principal</code> element of the policy, the session has the permissions allowed by
|
||||
* the policy. These permissions are granted in addition to the permissions granted by the
|
||||
* session policies.</p>
|
||||
* <p>
|
||||
* <b>Tags</b>
|
||||
* </p>
|
||||
* <p>(Optional) You can pass tag key-value pairs to your session. These are called session
|
||||
* tags. For more information about session tags, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <note>
|
||||
* <p>You can create a mobile-based or browser-based app that can authenticate users using
|
||||
* a web identity provider like Login with Amazon, Facebook, Google, or an OpenID
|
||||
* Connect-compatible identity provider. In this case, we recommend that you use <a href="http://aws.amazon.com/cognito/">Amazon Cognito</a> or
|
||||
* <code>AssumeRoleWithWebIdentity</code>. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#api_assumerolewithwebidentity">Federation Through a Web-based Identity Provider</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* </note>
|
||||
* <p>An administrator must grant you the permissions necessary to pass session tags. The
|
||||
* administrator can also create granular permissions to allow you to pass only specific
|
||||
* session tags. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/tutorial_attribute-based-access-control.html">Tutorial: Using Tags
|
||||
* for Attribute-Based Access Control</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* <p>Tag key–value pairs are not case sensitive, but case is preserved. This means that you
|
||||
* cannot have separate <code>Department</code> and <code>department</code> tag keys. Assume
|
||||
* that the user that you are federating has the
|
||||
* <code>Department</code>=<code>Marketing</code> tag and you pass the
|
||||
* <code>department</code>=<code>engineering</code> session tag. <code>Department</code>
|
||||
* and <code>department</code> are not saved as separate tags, and the session tag passed in
|
||||
* the request takes precedence over the user tag.</p>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, GetFederationTokenCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, GetFederationTokenCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // GetFederationTokenRequest
|
||||
* Name: "STRING_VALUE", // required
|
||||
* Policy: "STRING_VALUE",
|
||||
* PolicyArns: [ // policyDescriptorListType
|
||||
* { // PolicyDescriptorType
|
||||
* arn: "STRING_VALUE",
|
||||
* },
|
||||
* ],
|
||||
* DurationSeconds: Number("int"),
|
||||
* Tags: [ // tagListType
|
||||
* { // Tag
|
||||
* Key: "STRING_VALUE", // required
|
||||
* Value: "STRING_VALUE", // required
|
||||
* },
|
||||
* ],
|
||||
* };
|
||||
* const command = new GetFederationTokenCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // GetFederationTokenResponse
|
||||
* // Credentials: { // Credentials
|
||||
* // AccessKeyId: "STRING_VALUE", // required
|
||||
* // SecretAccessKey: "STRING_VALUE", // required
|
||||
* // SessionToken: "STRING_VALUE", // required
|
||||
* // Expiration: new Date("TIMESTAMP"), // required
|
||||
* // },
|
||||
* // FederatedUser: { // FederatedUser
|
||||
* // FederatedUserId: "STRING_VALUE", // required
|
||||
* // Arn: "STRING_VALUE", // required
|
||||
* // },
|
||||
* // PackedPolicySize: Number("int"),
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param GetFederationTokenCommandInput - {@link GetFederationTokenCommandInput}
|
||||
* @returns {@link GetFederationTokenCommandOutput}
|
||||
* @see {@link GetFederationTokenCommandInput} for command's `input` shape.
|
||||
* @see {@link GetFederationTokenCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link MalformedPolicyDocumentException} (client fault)
|
||||
* <p>The request was rejected because the policy document was malformed. The error message
|
||||
* describes the specific error.</p>
|
||||
*
|
||||
* @throws {@link PackedPolicyTooLargeException} (client fault)
|
||||
* <p>The request was rejected because the total packed size of the session policies and
|
||||
* session tags combined was too large. An Amazon Web Services conversion compresses the session policy
|
||||
* document, session policy ARNs, and session tags into a packed binary format that has a
|
||||
* separate limit. The error message indicates by percentage how close the policies and
|
||||
* tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in
|
||||
* the <i>IAM User Guide</i>.</p>
|
||||
* <p>You could receive this error even though you meet other defined session policy and
|
||||
* session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity
|
||||
* Character Limits</a> in the <i>IAM User Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link RegionDisabledException} (client fault)
|
||||
* <p>STS is not activated in the requested region for the account that is being asked to
|
||||
* generate credentials. The account administrator must use the IAM console to activate STS
|
||||
* in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and
|
||||
* Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User
|
||||
* Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To get temporary credentials for a role by using GetFederationToken
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "DurationSeconds": 3600,
|
||||
* "Name": "testFedUserSession",
|
||||
* "Policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Sid\":\"Stmt1\",\"Effect\":\"Allow\",\"Action\":\"s3:ListAllMyBuckets\",\"Resource\":\"*\"}]}",
|
||||
* "Tags": [
|
||||
* {
|
||||
* "Key": "Project",
|
||||
* "Value": "Pegasus"
|
||||
* },
|
||||
* {
|
||||
* "Key": "Cost-Center",
|
||||
* "Value": "98765"
|
||||
* }
|
||||
* ]
|
||||
* };
|
||||
* const command = new GetFederationTokenCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "Credentials": {
|
||||
* "AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
|
||||
* "Expiration": "2011-07-15T23:28:33.359Z",
|
||||
* "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY",
|
||||
* "SessionToken": "AQoDYXdzEPT//////////wEXAMPLEtc764bNrC9SAPBSM22wDOk4x4HIZ8j4FZTwdQWLWsKWHGBuFqwAeMicRXmxfpSPfIeoIYRqTflfKD8YUuwthAx7mSEI/qkPpKPi/kMcGdQrmGdeehM4IC1NtBmUpp2wUE8phUZampKsburEDy0KPkyQDYwT7WZ0wq5VSXDvp75YU9HFvlRd8Tx6q6fE8YQcHNVXAkiY9q6d+xo0rKwT38xVqr7ZD0u0iPPkUL64lIZbqBAz+scqKmlzm8FDrypNC9Yjc8fPOLn9FX9KSYvKTr4rvx3iSIlTJabIQwj2ICCR/oLxBA=="
|
||||
* },
|
||||
* "FederatedUser": {
|
||||
* "Arn": "arn:aws:sts::123456789012:federated-user/Bob",
|
||||
* "FederatedUserId": "123456789012:Bob"
|
||||
* },
|
||||
* "PackedPolicySize": 8
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-get-temporary-credentials-for-a-role-by-using-getfederationtoken-1480540749900
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class GetFederationTokenCommand extends $Command<GetFederationTokenCommandInput, GetFederationTokenCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: GetFederationTokenCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: GetFederationTokenCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<GetFederationTokenCommandInput, GetFederationTokenCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
-168
@@ -1,168 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import { Handler, HttpHandlerOptions as __HttpHandlerOptions, MetadataBearer as __MetadataBearer, MiddlewareStack } from "@smithy/types";
|
||||
import { GetSessionTokenRequest, GetSessionTokenResponse } from "../models/models_0";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientResolvedConfig } from "../STSClient";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export { __MetadataBearer, $Command };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The input for {@link GetSessionTokenCommand}.
|
||||
*/
|
||||
export interface GetSessionTokenCommandInput extends GetSessionTokenRequest {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* The output of {@link GetSessionTokenCommand}.
|
||||
*/
|
||||
export interface GetSessionTokenCommandOutput extends GetSessionTokenResponse, __MetadataBearer {
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
* <p>Returns a set of temporary credentials for an Amazon Web Services account or IAM user.
|
||||
* The credentials consist of an access key ID, a secret access key, and a security token.
|
||||
* Typically, you use <code>GetSessionToken</code> if you want to use MFA to protect
|
||||
* programmatic calls to specific Amazon Web Services API operations like Amazon EC2
|
||||
* <code>StopInstances</code>.</p>
|
||||
* <p>MFA-enabled IAM users must call <code>GetSessionToken</code> and submit
|
||||
* an MFA code that is associated with their MFA device. Using the temporary security
|
||||
* credentials that the call returns, IAM users can then make programmatic
|
||||
* calls to API operations that require MFA authentication. An incorrect MFA code causes the
|
||||
* API to return an access denied error. For a comparison of <code>GetSessionToken</code> with
|
||||
* the other API operations that produce temporary credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html">Requesting
|
||||
* Temporary Security Credentials</a> and <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#stsapi_comparison">Comparing the
|
||||
* Amazon Web Services STS API operations</a> in the <i>IAM User Guide</i>.</p>
|
||||
* <note>
|
||||
* <p>No permissions are required for users to perform this operation. The purpose of the
|
||||
* <code>sts:GetSessionToken</code> operation is to authenticate the user using MFA. You
|
||||
* cannot use policies to control authentication operations. For more information, see
|
||||
* <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_control-access_getsessiontoken.html">Permissions for GetSessionToken</a> in the
|
||||
* <i>IAM User Guide</i>.</p>
|
||||
* </note>
|
||||
* <p>
|
||||
* <b>Session Duration</b>
|
||||
* </p>
|
||||
* <p>The <code>GetSessionToken</code> operation must be called by using the long-term Amazon Web Services
|
||||
* security credentials of an IAM user. Credentials that are created by IAM users are valid for the duration that you specify. This duration can range
|
||||
* from 900 seconds (15 minutes) up to a maximum of 129,600 seconds (36 hours), with a default
|
||||
* of 43,200 seconds (12 hours). Credentials based on account credentials can range from 900
|
||||
* seconds (15 minutes) up to 3,600 seconds (1 hour), with a default of 1 hour. </p>
|
||||
* <p>
|
||||
* <b>Permissions</b>
|
||||
* </p>
|
||||
* <p>The temporary security credentials created by <code>GetSessionToken</code> can be used
|
||||
* to make API calls to any Amazon Web Services service with the following exceptions:</p>
|
||||
* <ul>
|
||||
* <li>
|
||||
* <p>You cannot call any IAM API operations unless MFA authentication information is
|
||||
* included in the request.</p>
|
||||
* </li>
|
||||
* <li>
|
||||
* <p>You cannot call any STS API <i>except</i>
|
||||
* <code>AssumeRole</code> or <code>GetCallerIdentity</code>.</p>
|
||||
* </li>
|
||||
* </ul>
|
||||
* <p>The credentials that <code>GetSessionToken</code> returns are based on permissions
|
||||
* associated with the IAM user whose credentials were used to call the
|
||||
* operation. The temporary credentials have the same permissions as the IAM user.</p>
|
||||
* <note>
|
||||
* <p>Although it is possible to call <code>GetSessionToken</code> using the security
|
||||
* credentials of an Amazon Web Services account root user rather than an IAM user, we do
|
||||
* not recommend it. If <code>GetSessionToken</code> is called using root user
|
||||
* credentials, the temporary credentials have root user permissions. For more
|
||||
* information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#lock-away-credentials">Safeguard your root user credentials and don't use them for everyday tasks</a> in the
|
||||
* <i>IAM User Guide</i>
|
||||
* </p>
|
||||
* </note>
|
||||
* <p>For more information about using <code>GetSessionToken</code> to create temporary
|
||||
* credentials, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_request.html#api_getsessiontoken">Temporary
|
||||
* Credentials for Users in Untrusted Environments</a> in the
|
||||
* <i>IAM User Guide</i>. </p>
|
||||
* @example
|
||||
* Use a bare-bones client and the command you need to make an API call.
|
||||
* ```javascript
|
||||
* import { STSClient, GetSessionTokenCommand } from "@aws-sdk/client-sts"; // ES Modules import
|
||||
* // const { STSClient, GetSessionTokenCommand } = require("@aws-sdk/client-sts"); // CommonJS import
|
||||
* const client = new STSClient(config);
|
||||
* const input = { // GetSessionTokenRequest
|
||||
* DurationSeconds: Number("int"),
|
||||
* SerialNumber: "STRING_VALUE",
|
||||
* TokenCode: "STRING_VALUE",
|
||||
* };
|
||||
* const command = new GetSessionTokenCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* // { // GetSessionTokenResponse
|
||||
* // Credentials: { // Credentials
|
||||
* // AccessKeyId: "STRING_VALUE", // required
|
||||
* // SecretAccessKey: "STRING_VALUE", // required
|
||||
* // SessionToken: "STRING_VALUE", // required
|
||||
* // Expiration: new Date("TIMESTAMP"), // required
|
||||
* // },
|
||||
* // };
|
||||
*
|
||||
* ```
|
||||
*
|
||||
* @param GetSessionTokenCommandInput - {@link GetSessionTokenCommandInput}
|
||||
* @returns {@link GetSessionTokenCommandOutput}
|
||||
* @see {@link GetSessionTokenCommandInput} for command's `input` shape.
|
||||
* @see {@link GetSessionTokenCommandOutput} for command's `response` shape.
|
||||
* @see {@link STSClientResolvedConfig | config} for STSClient's `config` shape.
|
||||
*
|
||||
* @throws {@link RegionDisabledException} (client fault)
|
||||
* <p>STS is not activated in the requested region for the account that is being asked to
|
||||
* generate credentials. The account administrator must use the IAM console to activate STS
|
||||
* in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and
|
||||
* Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User
|
||||
* Guide</i>.</p>
|
||||
*
|
||||
* @throws {@link STSServiceException}
|
||||
* <p>Base exception class for all service exceptions from STS service.</p>
|
||||
*
|
||||
* @example To get temporary credentials for an IAM user or an AWS account
|
||||
* ```javascript
|
||||
* //
|
||||
* const input = {
|
||||
* "DurationSeconds": 3600,
|
||||
* "SerialNumber": "YourMFASerialNumber",
|
||||
* "TokenCode": "123456"
|
||||
* };
|
||||
* const command = new GetSessionTokenCommand(input);
|
||||
* const response = await client.send(command);
|
||||
* /* response ==
|
||||
* {
|
||||
* "Credentials": {
|
||||
* "AccessKeyId": "AKIAIOSFODNN7EXAMPLE",
|
||||
* "Expiration": "2011-07-11T19:55:29.611Z",
|
||||
* "SecretAccessKey": "wJalrXUtnFEMI/K7MDENG/bPxRfiCYzEXAMPLEKEY",
|
||||
* "SessionToken": "AQoEXAMPLEH4aoAH0gNCAPyJxz4BlCFFxWNE1OPTgk5TthT+FvwqnKwRcOIfrRh3c/LTo6UDdyJwOOvEVPvLXCrrrUtdnniCEXAMPLE/IvU1dYUg2RVAJBanLiHb4IgRmpRV3zrkuWJOgQs8IZZaIv2BXIa2R4OlgkBN9bkUDNCJiBeb/AXlzBBko7b15fjrBs2+cTQtpZ3CYWFXG8C5zqx37wnOE49mRl/+OtkIKGO7fAE"
|
||||
* }
|
||||
* }
|
||||
* *\/
|
||||
* // example id: to-get-temporary-credentials-for-an-iam-user-or-an-aws-account-1480540814038
|
||||
* ```
|
||||
*
|
||||
*/
|
||||
export declare class GetSessionTokenCommand extends $Command<GetSessionTokenCommandInput, GetSessionTokenCommandOutput, STSClientResolvedConfig> {
|
||||
readonly input: GetSessionTokenCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
constructor(input: GetSessionTokenCommandInput);
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
resolveMiddleware(clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>, configuration: STSClientResolvedConfig, options?: __HttpHandlerOptions): Handler<GetSessionTokenCommandInput, GetSessionTokenCommandOutput>;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private serialize;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
private deserialize;
|
||||
}
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
export * from "./AssumeRoleCommand";
|
||||
export * from "./AssumeRoleWithSAMLCommand";
|
||||
export * from "./AssumeRoleWithWebIdentityCommand";
|
||||
export * from "./DecodeAuthorizationMessageCommand";
|
||||
export * from "./GetAccessKeyInfoCommand";
|
||||
export * from "./GetCallerIdentityCommand";
|
||||
export * from "./GetFederationTokenCommand";
|
||||
export * from "./GetSessionTokenCommand";
|
||||
-20
@@ -1,20 +0,0 @@
|
||||
import { Pluggable } from "@smithy/types";
|
||||
import { DefaultCredentialProvider, RoleAssumer, RoleAssumerWithWebIdentity } from "./defaultStsRoleAssumers";
|
||||
import { ServiceInputTypes, ServiceOutputTypes, STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* The default role assumer that used by credential providers when sts:AssumeRole API is needed.
|
||||
*/
|
||||
export declare const getDefaultRoleAssumer: (stsOptions?: Pick<STSClientConfig, "logger" | "region" | "requestHandler">, stsPlugins?: Pluggable<ServiceInputTypes, ServiceOutputTypes>[]) => RoleAssumer;
|
||||
/**
|
||||
* The default role assumer that used by credential providers when sts:AssumeRoleWithWebIdentity API is needed.
|
||||
*/
|
||||
export declare const getDefaultRoleAssumerWithWebIdentity: (stsOptions?: Pick<STSClientConfig, "logger" | "region" | "requestHandler">, stsPlugins?: Pluggable<ServiceInputTypes, ServiceOutputTypes>[]) => RoleAssumerWithWebIdentity;
|
||||
/**
|
||||
* The default credential providers depend STS client to assume role with desired API: sts:assumeRole,
|
||||
* sts:assumeRoleWithWebIdentity, etc. This function decorates the default credential provider with role assumers which
|
||||
* encapsulates the process of calling STS commands. This can only be imported by AWS client packages to avoid circular
|
||||
* dependencies.
|
||||
*
|
||||
* @internal
|
||||
*/
|
||||
export declare const decorateDefaultCredentialProvider: (provider: DefaultCredentialProvider) => DefaultCredentialProvider;
|
||||
-36
@@ -1,36 +0,0 @@
|
||||
import { Credentials } from "@aws-sdk/types";
|
||||
import { Provider } from "@smithy/types";
|
||||
import { AssumeRoleCommandInput } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithWebIdentityCommandInput } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import type { STSClient, STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export type RoleAssumer = (sourceCreds: Credentials, params: AssumeRoleCommandInput) => Promise<Credentials>;
|
||||
/**
|
||||
* The default role assumer that used by credential providers when sts:AssumeRole API is needed.
|
||||
* @internal
|
||||
*/
|
||||
export declare const getDefaultRoleAssumer: (stsOptions: Pick<STSClientConfig, "logger" | "region" | "requestHandler">, stsClientCtor: new (options: STSClientConfig) => STSClient) => RoleAssumer;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export type RoleAssumerWithWebIdentity = (params: AssumeRoleWithWebIdentityCommandInput) => Promise<Credentials>;
|
||||
/**
|
||||
* The default role assumer that used by credential providers when sts:AssumeRoleWithWebIdentity API is needed.
|
||||
* @internal
|
||||
*/
|
||||
export declare const getDefaultRoleAssumerWithWebIdentity: (stsOptions: Pick<STSClientConfig, "logger" | "region" | "requestHandler">, stsClientCtor: new (options: STSClientConfig) => STSClient) => RoleAssumerWithWebIdentity;
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export type DefaultCredentialProvider = (input: any) => Provider<Credentials>;
|
||||
/**
|
||||
* The default credential providers depend STS client to assume role with desired API: sts:assumeRole,
|
||||
* sts:assumeRoleWithWebIdentity, etc. This function decorates the default credential provider with role assumers which
|
||||
* encapsulates the process of calling STS commands. This can only be imported by AWS client packages to avoid circular
|
||||
* dependencies.
|
||||
*
|
||||
* @internal
|
||||
*/
|
||||
export declare const decorateDefaultCredentialProvider: (provider: DefaultCredentialProvider) => DefaultCredentialProvider;
|
||||
-24
@@ -1,24 +0,0 @@
|
||||
import { Endpoint, EndpointParameters as __EndpointParameters, EndpointV2, Provider } from "@smithy/types";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export interface ClientInputEndpointParameters {
|
||||
region?: string | Provider<string>;
|
||||
useDualstackEndpoint?: boolean | Provider<boolean>;
|
||||
useFipsEndpoint?: boolean | Provider<boolean>;
|
||||
endpoint?: string | Provider<string> | Endpoint | Provider<Endpoint> | EndpointV2 | Provider<EndpointV2>;
|
||||
useGlobalEndpoint?: boolean | Provider<boolean>;
|
||||
}
|
||||
export type ClientResolvedEndpointParameters = ClientInputEndpointParameters & {
|
||||
defaultSigningName: string;
|
||||
};
|
||||
export declare const resolveClientEndpointParameters: <T>(options: T & ClientInputEndpointParameters) => T & ClientInputEndpointParameters & {
|
||||
defaultSigningName: string;
|
||||
};
|
||||
export interface EndpointParameters extends __EndpointParameters {
|
||||
Region?: string;
|
||||
UseDualStack?: boolean;
|
||||
UseFIPS?: boolean;
|
||||
Endpoint?: string;
|
||||
UseGlobalEndpoint?: boolean;
|
||||
}
|
||||
-5
@@ -1,5 +0,0 @@
|
||||
import { EndpointV2, Logger } from "@smithy/types";
|
||||
import { EndpointParameters } from "./EndpointParameters";
|
||||
export declare const defaultEndpointResolver: (endpointParams: EndpointParameters, context?: {
|
||||
logger?: Logger;
|
||||
}) => EndpointV2;
|
||||
-2
@@ -1,2 +0,0 @@
|
||||
import { RuleSetObject } from "@smithy/types";
|
||||
export declare const ruleSet: RuleSetObject;
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
import { AwsRegionExtensionConfiguration } from "@aws-sdk/types";
|
||||
import { HttpHandlerExtensionConfiguration } from "@smithy/protocol-http";
|
||||
import { DefaultExtensionConfiguration } from "@smithy/types";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export interface STSExtensionConfiguration extends HttpHandlerExtensionConfiguration, DefaultExtensionConfiguration, AwsRegionExtensionConfiguration {
|
||||
}
|
||||
-18
@@ -1,18 +0,0 @@
|
||||
/**
|
||||
* <fullname>Security Token Service</fullname>
|
||||
* <p>Security Token Service (STS) enables you to request temporary, limited-privilege
|
||||
* credentials for users. This guide provides descriptions of the STS API. For
|
||||
* more information about using this service, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp.html">Temporary Security Credentials</a>.</p>
|
||||
*
|
||||
* @packageDocumentation
|
||||
*/
|
||||
export * from "./STSClient";
|
||||
export * from "./STS";
|
||||
export { ClientInputEndpointParameters } from "./endpoint/EndpointParameters";
|
||||
export { RuntimeExtension } from "./runtimeExtensions";
|
||||
export { STSExtensionConfiguration } from "./extensionConfiguration";
|
||||
export * from "./commands";
|
||||
export * from "./models";
|
||||
export * from "./defaultRoleAssumers";
|
||||
import "@aws-sdk/util-endpoints";
|
||||
export { STSServiceException } from "./models/STSServiceException";
|
||||
-13
@@ -1,13 +0,0 @@
|
||||
import { ServiceException as __ServiceException, ServiceExceptionOptions as __ServiceExceptionOptions } from "@smithy/smithy-client";
|
||||
export { __ServiceException, __ServiceExceptionOptions };
|
||||
/**
|
||||
* @public
|
||||
*
|
||||
* Base exception class for all service exceptions from STS service.
|
||||
*/
|
||||
export declare class STSServiceException extends __ServiceException {
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
constructor(options: __ServiceExceptionOptions);
|
||||
}
|
||||
-1
@@ -1 +0,0 @@
|
||||
export * from "./models_0";
|
||||
-1213
File diff suppressed because it is too large
Load Diff
-74
@@ -1,74 +0,0 @@
|
||||
import { HttpRequest as __HttpRequest, HttpResponse as __HttpResponse } from "@smithy/protocol-http";
|
||||
import { SerdeContext as __SerdeContext } from "@smithy/types";
|
||||
import { AssumeRoleCommandInput, AssumeRoleCommandOutput } from "../commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput } from "../commands/AssumeRoleWithSAMLCommand";
|
||||
import { AssumeRoleWithWebIdentityCommandInput, AssumeRoleWithWebIdentityCommandOutput } from "../commands/AssumeRoleWithWebIdentityCommand";
|
||||
import { DecodeAuthorizationMessageCommandInput, DecodeAuthorizationMessageCommandOutput } from "../commands/DecodeAuthorizationMessageCommand";
|
||||
import { GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput } from "../commands/GetAccessKeyInfoCommand";
|
||||
import { GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput } from "../commands/GetCallerIdentityCommand";
|
||||
import { GetFederationTokenCommandInput, GetFederationTokenCommandOutput } from "../commands/GetFederationTokenCommand";
|
||||
import { GetSessionTokenCommandInput, GetSessionTokenCommandOutput } from "../commands/GetSessionTokenCommand";
|
||||
/**
|
||||
* serializeAws_queryAssumeRoleCommand
|
||||
*/
|
||||
export declare const se_AssumeRoleCommand: (input: AssumeRoleCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryAssumeRoleWithSAMLCommand
|
||||
*/
|
||||
export declare const se_AssumeRoleWithSAMLCommand: (input: AssumeRoleWithSAMLCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryAssumeRoleWithWebIdentityCommand
|
||||
*/
|
||||
export declare const se_AssumeRoleWithWebIdentityCommand: (input: AssumeRoleWithWebIdentityCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryDecodeAuthorizationMessageCommand
|
||||
*/
|
||||
export declare const se_DecodeAuthorizationMessageCommand: (input: DecodeAuthorizationMessageCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryGetAccessKeyInfoCommand
|
||||
*/
|
||||
export declare const se_GetAccessKeyInfoCommand: (input: GetAccessKeyInfoCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryGetCallerIdentityCommand
|
||||
*/
|
||||
export declare const se_GetCallerIdentityCommand: (input: GetCallerIdentityCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryGetFederationTokenCommand
|
||||
*/
|
||||
export declare const se_GetFederationTokenCommand: (input: GetFederationTokenCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* serializeAws_queryGetSessionTokenCommand
|
||||
*/
|
||||
export declare const se_GetSessionTokenCommand: (input: GetSessionTokenCommandInput, context: __SerdeContext) => Promise<__HttpRequest>;
|
||||
/**
|
||||
* deserializeAws_queryAssumeRoleCommand
|
||||
*/
|
||||
export declare const de_AssumeRoleCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<AssumeRoleCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryAssumeRoleWithSAMLCommand
|
||||
*/
|
||||
export declare const de_AssumeRoleWithSAMLCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<AssumeRoleWithSAMLCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryAssumeRoleWithWebIdentityCommand
|
||||
*/
|
||||
export declare const de_AssumeRoleWithWebIdentityCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<AssumeRoleWithWebIdentityCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryDecodeAuthorizationMessageCommand
|
||||
*/
|
||||
export declare const de_DecodeAuthorizationMessageCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<DecodeAuthorizationMessageCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryGetAccessKeyInfoCommand
|
||||
*/
|
||||
export declare const de_GetAccessKeyInfoCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<GetAccessKeyInfoCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryGetCallerIdentityCommand
|
||||
*/
|
||||
export declare const de_GetCallerIdentityCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<GetCallerIdentityCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryGetFederationTokenCommand
|
||||
*/
|
||||
export declare const de_GetFederationTokenCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<GetFederationTokenCommandOutput>;
|
||||
/**
|
||||
* deserializeAws_queryGetSessionTokenCommand
|
||||
*/
|
||||
export declare const de_GetSessionTokenCommand: (output: __HttpResponse, context: __SerdeContext) => Promise<GetSessionTokenCommandOutput>;
|
||||
-47
@@ -1,47 +0,0 @@
|
||||
import { FetchHttpHandler as RequestHandler } from "@smithy/fetch-http-handler";
|
||||
import { STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export declare const getRuntimeConfig: (config: STSClientConfig) => {
|
||||
runtime: string;
|
||||
defaultsMode: import("@smithy/types").Provider<import("@smithy/smithy-client").ResolvedDefaultsMode>;
|
||||
bodyLengthChecker: import("@smithy/types").BodyLengthCalculator;
|
||||
credentialDefaultProvider: (input: any) => import("@smithy/types").Provider<import("@aws-sdk/types").Credentials>;
|
||||
defaultUserAgentProvider: import("@smithy/types").Provider<import("@smithy/types").UserAgent>;
|
||||
maxAttempts: number | import("@smithy/types").Provider<number>;
|
||||
region: string | import("@smithy/types").Provider<any>;
|
||||
requestHandler: (import("@smithy/types").RequestHandler<any, any, import("@smithy/types").HttpHandlerOptions> & import("@smithy/types").RequestHandler<import("@smithy/protocol-http").HttpRequest, import("@smithy/protocol-http").HttpResponse, import("@smithy/types").HttpHandlerOptions> & {
|
||||
updateHttpClientConfig(key: never, value: never): void;
|
||||
httpHandlerConfigs(): {};
|
||||
}) | RequestHandler;
|
||||
retryMode: string | import("@smithy/types").Provider<string>;
|
||||
sha256: import("@smithy/types").HashConstructor;
|
||||
streamCollector: import("@smithy/types").StreamCollector;
|
||||
useDualstackEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
useFipsEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
apiVersion: string;
|
||||
urlParser: import("@smithy/types").UrlParser;
|
||||
base64Decoder: import("@smithy/types").Decoder;
|
||||
base64Encoder: import("@smithy/types").Encoder;
|
||||
utf8Decoder: import("@smithy/types").Decoder;
|
||||
utf8Encoder: import("@smithy/types").Encoder;
|
||||
disableHostPrefix: boolean;
|
||||
serviceId: string;
|
||||
logger: import("@smithy/types").Logger;
|
||||
extensions: import("./runtimeExtensions").RuntimeExtension[];
|
||||
endpoint?: ((string | import("@smithy/types").Endpoint | import("@smithy/types").Provider<import("@smithy/types").Endpoint> | import("@smithy/types").EndpointV2 | import("@smithy/types").Provider<import("@smithy/types").EndpointV2>) & (string | import("@smithy/types").Provider<string> | import("@smithy/types").Endpoint | import("@smithy/types").Provider<import("@smithy/types").Endpoint> | import("@smithy/types").EndpointV2 | import("@smithy/types").Provider<import("@smithy/types").EndpointV2>)) | undefined;
|
||||
endpointProvider: (endpointParams: import("./endpoint/EndpointParameters").EndpointParameters, context?: {
|
||||
logger?: import("@smithy/types").Logger | undefined;
|
||||
}) => import("@smithy/types").EndpointV2;
|
||||
tls?: boolean | undefined;
|
||||
retryStrategy?: import("@smithy/types").RetryStrategy | import("@smithy/types").RetryStrategyV2 | undefined;
|
||||
credentials?: import("@smithy/types").AwsCredentialIdentity | import("@smithy/types").Provider<import("@smithy/types").AwsCredentialIdentity> | undefined;
|
||||
signer?: import("@smithy/types").RequestSigner | ((authScheme?: import("@smithy/types").AuthScheme | undefined) => Promise<import("@smithy/types").RequestSigner>) | undefined;
|
||||
signingEscapePath?: boolean | undefined;
|
||||
systemClockOffset?: number | undefined;
|
||||
signingRegion?: string | undefined;
|
||||
signerConstructor?: (new (options: import("@smithy/signature-v4").SignatureV4Init & import("@smithy/signature-v4").SignatureV4CryptoInit) => import("@smithy/types").RequestSigner) | undefined;
|
||||
customUserAgent?: string | import("@smithy/types").UserAgent | undefined;
|
||||
useGlobalEndpoint?: boolean | import("@smithy/types").Provider<boolean> | undefined;
|
||||
};
|
||||
-47
@@ -1,47 +0,0 @@
|
||||
import { NodeHttpHandler as RequestHandler } from "@smithy/node-http-handler";
|
||||
import { STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export declare const getRuntimeConfig: (config: STSClientConfig) => {
|
||||
runtime: string;
|
||||
defaultsMode: import("@smithy/types").Provider<import("@smithy/smithy-client").ResolvedDefaultsMode>;
|
||||
bodyLengthChecker: import("@smithy/types").BodyLengthCalculator;
|
||||
credentialDefaultProvider: import("./defaultStsRoleAssumers").DefaultCredentialProvider;
|
||||
defaultUserAgentProvider: import("@smithy/types").Provider<import("@smithy/types").UserAgent>;
|
||||
maxAttempts: number | import("@smithy/types").Provider<number>;
|
||||
region: string | import("@smithy/types").Provider<string>;
|
||||
requestHandler: (import("@smithy/types").RequestHandler<any, any, import("@smithy/types").HttpHandlerOptions> & import("@smithy/types").RequestHandler<import("@smithy/protocol-http").HttpRequest, import("@smithy/protocol-http").HttpResponse, import("@smithy/types").HttpHandlerOptions> & {
|
||||
updateHttpClientConfig(key: never, value: never): void;
|
||||
httpHandlerConfigs(): {};
|
||||
}) | RequestHandler;
|
||||
retryMode: string | import("@smithy/types").Provider<string>;
|
||||
sha256: import("@smithy/types").HashConstructor;
|
||||
streamCollector: import("@smithy/types").StreamCollector;
|
||||
useDualstackEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
useFipsEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
apiVersion: string;
|
||||
urlParser: import("@smithy/types").UrlParser;
|
||||
base64Decoder: import("@smithy/types").Decoder;
|
||||
base64Encoder: import("@smithy/types").Encoder;
|
||||
utf8Decoder: import("@smithy/types").Decoder;
|
||||
utf8Encoder: import("@smithy/types").Encoder;
|
||||
disableHostPrefix: boolean;
|
||||
serviceId: string;
|
||||
logger: import("@smithy/types").Logger;
|
||||
extensions: import("./runtimeExtensions").RuntimeExtension[];
|
||||
endpoint?: ((string | import("@smithy/types").Endpoint | import("@smithy/types").Provider<import("@smithy/types").Endpoint> | import("@smithy/types").EndpointV2 | import("@smithy/types").Provider<import("@smithy/types").EndpointV2>) & (string | import("@smithy/types").Provider<string> | import("@smithy/types").Endpoint | import("@smithy/types").Provider<import("@smithy/types").Endpoint> | import("@smithy/types").EndpointV2 | import("@smithy/types").Provider<import("@smithy/types").EndpointV2>)) | undefined;
|
||||
endpointProvider: (endpointParams: import("./endpoint/EndpointParameters").EndpointParameters, context?: {
|
||||
logger?: import("@smithy/types").Logger | undefined;
|
||||
}) => import("@smithy/types").EndpointV2;
|
||||
tls?: boolean | undefined;
|
||||
retryStrategy?: import("@smithy/types").RetryStrategy | import("@smithy/types").RetryStrategyV2 | undefined;
|
||||
credentials?: import("@smithy/types").AwsCredentialIdentity | import("@smithy/types").Provider<import("@smithy/types").AwsCredentialIdentity> | undefined;
|
||||
signer?: import("@smithy/types").RequestSigner | ((authScheme?: import("@smithy/types").AuthScheme | undefined) => Promise<import("@smithy/types").RequestSigner>) | undefined;
|
||||
signingEscapePath?: boolean | undefined;
|
||||
systemClockOffset?: number | undefined;
|
||||
signingRegion?: string | undefined;
|
||||
signerConstructor?: (new (options: import("@smithy/signature-v4").SignatureV4Init & import("@smithy/signature-v4").SignatureV4CryptoInit) => import("@smithy/types").RequestSigner) | undefined;
|
||||
customUserAgent?: string | import("@smithy/types").UserAgent | undefined;
|
||||
useGlobalEndpoint?: boolean | import("@smithy/types").Provider<boolean> | undefined;
|
||||
};
|
||||
-46
@@ -1,46 +0,0 @@
|
||||
import { STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export declare const getRuntimeConfig: (config: STSClientConfig) => {
|
||||
runtime: string;
|
||||
sha256: import("@smithy/types").HashConstructor;
|
||||
requestHandler: (import("@smithy/types").RequestHandler<any, any, import("@smithy/types").HttpHandlerOptions> & import("@smithy/types").RequestHandler<import("@smithy/protocol-http").HttpRequest, import("@smithy/protocol-http").HttpResponse, import("@smithy/types").HttpHandlerOptions> & {
|
||||
updateHttpClientConfig(key: never, value: never): void;
|
||||
httpHandlerConfigs(): {};
|
||||
}) | import("@smithy/fetch-http-handler").FetchHttpHandler;
|
||||
apiVersion: string;
|
||||
urlParser: import("@smithy/types").UrlParser;
|
||||
bodyLengthChecker: import("@smithy/types").BodyLengthCalculator;
|
||||
streamCollector: import("@smithy/types").StreamCollector;
|
||||
base64Decoder: import("@smithy/types").Decoder;
|
||||
base64Encoder: import("@smithy/types").Encoder;
|
||||
utf8Decoder: import("@smithy/types").Decoder;
|
||||
utf8Encoder: import("@smithy/types").Encoder;
|
||||
disableHostPrefix: boolean;
|
||||
serviceId: string;
|
||||
useDualstackEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
useFipsEndpoint: boolean | import("@smithy/types").Provider<boolean>;
|
||||
region: string | import("@smithy/types").Provider<any>;
|
||||
credentialDefaultProvider: (input: any) => import("@smithy/types").Provider<import("@aws-sdk/types").Credentials>;
|
||||
defaultUserAgentProvider: import("@smithy/types").Provider<import("@smithy/types").UserAgent>;
|
||||
maxAttempts: number | import("@smithy/types").Provider<number>;
|
||||
retryMode: string | import("@smithy/types").Provider<string>;
|
||||
logger: import("@smithy/types").Logger;
|
||||
extensions: import("./runtimeExtensions").RuntimeExtension[];
|
||||
defaultsMode: import("@smithy/smithy-client").DefaultsMode | import("@smithy/types").Provider<import("@smithy/smithy-client").DefaultsMode>;
|
||||
endpoint?: string | import("@smithy/types").Endpoint | import("@smithy/types").Provider<import("@smithy/types").Endpoint> | import("@smithy/types").EndpointV2 | import("@smithy/types").Provider<import("@smithy/types").EndpointV2> | undefined;
|
||||
endpointProvider: (endpointParams: import("./endpoint/EndpointParameters").EndpointParameters, context?: {
|
||||
logger?: import("@smithy/types").Logger | undefined;
|
||||
}) => import("@smithy/types").EndpointV2;
|
||||
tls?: boolean | undefined;
|
||||
retryStrategy?: import("@smithy/types").RetryStrategy | import("@smithy/types").RetryStrategyV2 | undefined;
|
||||
credentials?: import("@smithy/types").AwsCredentialIdentity | import("@smithy/types").Provider<import("@smithy/types").AwsCredentialIdentity> | undefined;
|
||||
signer?: import("@smithy/types").RequestSigner | ((authScheme?: import("@smithy/types").AuthScheme | undefined) => Promise<import("@smithy/types").RequestSigner>) | undefined;
|
||||
signingEscapePath?: boolean | undefined;
|
||||
systemClockOffset?: number | undefined;
|
||||
signingRegion?: string | undefined;
|
||||
signerConstructor?: (new (options: import("@smithy/signature-v4").SignatureV4Init & import("@smithy/signature-v4").SignatureV4CryptoInit) => import("@smithy/types").RequestSigner) | undefined;
|
||||
customUserAgent?: string | import("@smithy/types").UserAgent | undefined;
|
||||
useGlobalEndpoint?: boolean | import("@smithy/types").Provider<boolean> | undefined;
|
||||
};
|
||||
-19
@@ -1,19 +0,0 @@
|
||||
import { STSClientConfig } from "./STSClient";
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export declare const getRuntimeConfig: (config: STSClientConfig) => {
|
||||
apiVersion: string;
|
||||
base64Decoder: import("@smithy/types").Decoder;
|
||||
base64Encoder: import("@smithy/types").Encoder;
|
||||
disableHostPrefix: boolean;
|
||||
endpointProvider: (endpointParams: import("./endpoint/EndpointParameters").EndpointParameters, context?: {
|
||||
logger?: import("@smithy/types").Logger | undefined;
|
||||
}) => import("@smithy/types").EndpointV2;
|
||||
extensions: import("./runtimeExtensions").RuntimeExtension[];
|
||||
logger: import("@smithy/types").Logger;
|
||||
serviceId: string;
|
||||
urlParser: import("@smithy/types").UrlParser;
|
||||
utf8Decoder: import("@smithy/types").Decoder;
|
||||
utf8Encoder: import("@smithy/types").Encoder;
|
||||
};
|
||||
-17
@@ -1,17 +0,0 @@
|
||||
import { STSExtensionConfiguration } from "./extensionConfiguration";
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export interface RuntimeExtension {
|
||||
configure(extensionConfiguration: STSExtensionConfiguration): void;
|
||||
}
|
||||
/**
|
||||
* @public
|
||||
*/
|
||||
export interface RuntimeExtensionsConfig {
|
||||
extensions: RuntimeExtension[];
|
||||
}
|
||||
/**
|
||||
* @internal
|
||||
*/
|
||||
export declare const resolveRuntimeExtensions: (runtimeConfig: any, extensions: RuntimeExtension[]) => any;
|
||||
-141
@@ -1,141 +0,0 @@
|
||||
import { HttpHandlerOptions as __HttpHandlerOptions } from "@smithy/types";
|
||||
import {
|
||||
AssumeRoleCommandInput,
|
||||
AssumeRoleCommandOutput,
|
||||
} from "./commands/AssumeRoleCommand";
|
||||
import {
|
||||
AssumeRoleWithSAMLCommandInput,
|
||||
AssumeRoleWithSAMLCommandOutput,
|
||||
} from "./commands/AssumeRoleWithSAMLCommand";
|
||||
import {
|
||||
AssumeRoleWithWebIdentityCommandInput,
|
||||
AssumeRoleWithWebIdentityCommandOutput,
|
||||
} from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import {
|
||||
DecodeAuthorizationMessageCommandInput,
|
||||
DecodeAuthorizationMessageCommandOutput,
|
||||
} from "./commands/DecodeAuthorizationMessageCommand";
|
||||
import {
|
||||
GetAccessKeyInfoCommandInput,
|
||||
GetAccessKeyInfoCommandOutput,
|
||||
} from "./commands/GetAccessKeyInfoCommand";
|
||||
import {
|
||||
GetCallerIdentityCommandInput,
|
||||
GetCallerIdentityCommandOutput,
|
||||
} from "./commands/GetCallerIdentityCommand";
|
||||
import {
|
||||
GetFederationTokenCommandInput,
|
||||
GetFederationTokenCommandOutput,
|
||||
} from "./commands/GetFederationTokenCommand";
|
||||
import {
|
||||
GetSessionTokenCommandInput,
|
||||
GetSessionTokenCommandOutput,
|
||||
} from "./commands/GetSessionTokenCommand";
|
||||
import { STSClient } from "./STSClient";
|
||||
export interface STS {
|
||||
assumeRole(
|
||||
args: AssumeRoleCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<AssumeRoleCommandOutput>;
|
||||
assumeRole(
|
||||
args: AssumeRoleCommandInput,
|
||||
cb: (err: any, data?: AssumeRoleCommandOutput) => void
|
||||
): void;
|
||||
assumeRole(
|
||||
args: AssumeRoleCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: AssumeRoleCommandOutput) => void
|
||||
): void;
|
||||
assumeRoleWithSAML(
|
||||
args: AssumeRoleWithSAMLCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<AssumeRoleWithSAMLCommandOutput>;
|
||||
assumeRoleWithSAML(
|
||||
args: AssumeRoleWithSAMLCommandInput,
|
||||
cb: (err: any, data?: AssumeRoleWithSAMLCommandOutput) => void
|
||||
): void;
|
||||
assumeRoleWithSAML(
|
||||
args: AssumeRoleWithSAMLCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: AssumeRoleWithSAMLCommandOutput) => void
|
||||
): void;
|
||||
assumeRoleWithWebIdentity(
|
||||
args: AssumeRoleWithWebIdentityCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<AssumeRoleWithWebIdentityCommandOutput>;
|
||||
assumeRoleWithWebIdentity(
|
||||
args: AssumeRoleWithWebIdentityCommandInput,
|
||||
cb: (err: any, data?: AssumeRoleWithWebIdentityCommandOutput) => void
|
||||
): void;
|
||||
assumeRoleWithWebIdentity(
|
||||
args: AssumeRoleWithWebIdentityCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: AssumeRoleWithWebIdentityCommandOutput) => void
|
||||
): void;
|
||||
decodeAuthorizationMessage(
|
||||
args: DecodeAuthorizationMessageCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<DecodeAuthorizationMessageCommandOutput>;
|
||||
decodeAuthorizationMessage(
|
||||
args: DecodeAuthorizationMessageCommandInput,
|
||||
cb: (err: any, data?: DecodeAuthorizationMessageCommandOutput) => void
|
||||
): void;
|
||||
decodeAuthorizationMessage(
|
||||
args: DecodeAuthorizationMessageCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: DecodeAuthorizationMessageCommandOutput) => void
|
||||
): void;
|
||||
getAccessKeyInfo(
|
||||
args: GetAccessKeyInfoCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<GetAccessKeyInfoCommandOutput>;
|
||||
getAccessKeyInfo(
|
||||
args: GetAccessKeyInfoCommandInput,
|
||||
cb: (err: any, data?: GetAccessKeyInfoCommandOutput) => void
|
||||
): void;
|
||||
getAccessKeyInfo(
|
||||
args: GetAccessKeyInfoCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: GetAccessKeyInfoCommandOutput) => void
|
||||
): void;
|
||||
getCallerIdentity(
|
||||
args: GetCallerIdentityCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<GetCallerIdentityCommandOutput>;
|
||||
getCallerIdentity(
|
||||
args: GetCallerIdentityCommandInput,
|
||||
cb: (err: any, data?: GetCallerIdentityCommandOutput) => void
|
||||
): void;
|
||||
getCallerIdentity(
|
||||
args: GetCallerIdentityCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: GetCallerIdentityCommandOutput) => void
|
||||
): void;
|
||||
getFederationToken(
|
||||
args: GetFederationTokenCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<GetFederationTokenCommandOutput>;
|
||||
getFederationToken(
|
||||
args: GetFederationTokenCommandInput,
|
||||
cb: (err: any, data?: GetFederationTokenCommandOutput) => void
|
||||
): void;
|
||||
getFederationToken(
|
||||
args: GetFederationTokenCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: GetFederationTokenCommandOutput) => void
|
||||
): void;
|
||||
getSessionToken(
|
||||
args: GetSessionTokenCommandInput,
|
||||
options?: __HttpHandlerOptions
|
||||
): Promise<GetSessionTokenCommandOutput>;
|
||||
getSessionToken(
|
||||
args: GetSessionTokenCommandInput,
|
||||
cb: (err: any, data?: GetSessionTokenCommandOutput) => void
|
||||
): void;
|
||||
getSessionToken(
|
||||
args: GetSessionTokenCommandInput,
|
||||
options: __HttpHandlerOptions,
|
||||
cb: (err: any, data?: GetSessionTokenCommandOutput) => void
|
||||
): void;
|
||||
}
|
||||
export declare class STS extends STSClient implements STS {}
|
||||
-163
@@ -1,163 +0,0 @@
|
||||
import {
|
||||
HostHeaderInputConfig,
|
||||
HostHeaderResolvedConfig,
|
||||
} from "@aws-sdk/middleware-host-header";
|
||||
import {
|
||||
StsAuthInputConfig,
|
||||
StsAuthResolvedConfig,
|
||||
} from "@aws-sdk/middleware-sdk-sts";
|
||||
import {
|
||||
UserAgentInputConfig,
|
||||
UserAgentResolvedConfig,
|
||||
} from "@aws-sdk/middleware-user-agent";
|
||||
import { Credentials as __Credentials } from "@aws-sdk/types";
|
||||
import {
|
||||
RegionInputConfig,
|
||||
RegionResolvedConfig,
|
||||
} from "@smithy/config-resolver";
|
||||
import {
|
||||
EndpointInputConfig,
|
||||
EndpointResolvedConfig,
|
||||
} from "@smithy/middleware-endpoint";
|
||||
import {
|
||||
RetryInputConfig,
|
||||
RetryResolvedConfig,
|
||||
} from "@smithy/middleware-retry";
|
||||
import { HttpHandler as __HttpHandler } from "@smithy/protocol-http";
|
||||
import {
|
||||
Client as __Client,
|
||||
DefaultsMode as __DefaultsMode,
|
||||
SmithyConfiguration as __SmithyConfiguration,
|
||||
SmithyResolvedConfiguration as __SmithyResolvedConfiguration,
|
||||
} from "@smithy/smithy-client";
|
||||
import {
|
||||
BodyLengthCalculator as __BodyLengthCalculator,
|
||||
CheckOptionalClientConfig as __CheckOptionalClientConfig,
|
||||
ChecksumConstructor as __ChecksumConstructor,
|
||||
Decoder as __Decoder,
|
||||
Encoder as __Encoder,
|
||||
HashConstructor as __HashConstructor,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
Logger as __Logger,
|
||||
Provider as __Provider,
|
||||
Provider,
|
||||
StreamCollector as __StreamCollector,
|
||||
UrlParser as __UrlParser,
|
||||
UserAgent as __UserAgent,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
AssumeRoleCommandInput,
|
||||
AssumeRoleCommandOutput,
|
||||
} from "./commands/AssumeRoleCommand";
|
||||
import {
|
||||
AssumeRoleWithSAMLCommandInput,
|
||||
AssumeRoleWithSAMLCommandOutput,
|
||||
} from "./commands/AssumeRoleWithSAMLCommand";
|
||||
import {
|
||||
AssumeRoleWithWebIdentityCommandInput,
|
||||
AssumeRoleWithWebIdentityCommandOutput,
|
||||
} from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import {
|
||||
DecodeAuthorizationMessageCommandInput,
|
||||
DecodeAuthorizationMessageCommandOutput,
|
||||
} from "./commands/DecodeAuthorizationMessageCommand";
|
||||
import {
|
||||
GetAccessKeyInfoCommandInput,
|
||||
GetAccessKeyInfoCommandOutput,
|
||||
} from "./commands/GetAccessKeyInfoCommand";
|
||||
import {
|
||||
GetCallerIdentityCommandInput,
|
||||
GetCallerIdentityCommandOutput,
|
||||
} from "./commands/GetCallerIdentityCommand";
|
||||
import {
|
||||
GetFederationTokenCommandInput,
|
||||
GetFederationTokenCommandOutput,
|
||||
} from "./commands/GetFederationTokenCommand";
|
||||
import {
|
||||
GetSessionTokenCommandInput,
|
||||
GetSessionTokenCommandOutput,
|
||||
} from "./commands/GetSessionTokenCommand";
|
||||
import {
|
||||
ClientInputEndpointParameters,
|
||||
ClientResolvedEndpointParameters,
|
||||
EndpointParameters,
|
||||
} from "./endpoint/EndpointParameters";
|
||||
import { RuntimeExtension, RuntimeExtensionsConfig } from "./runtimeExtensions";
|
||||
export { __Client };
|
||||
export type ServiceInputTypes =
|
||||
| AssumeRoleCommandInput
|
||||
| AssumeRoleWithSAMLCommandInput
|
||||
| AssumeRoleWithWebIdentityCommandInput
|
||||
| DecodeAuthorizationMessageCommandInput
|
||||
| GetAccessKeyInfoCommandInput
|
||||
| GetCallerIdentityCommandInput
|
||||
| GetFederationTokenCommandInput
|
||||
| GetSessionTokenCommandInput;
|
||||
export type ServiceOutputTypes =
|
||||
| AssumeRoleCommandOutput
|
||||
| AssumeRoleWithSAMLCommandOutput
|
||||
| AssumeRoleWithWebIdentityCommandOutput
|
||||
| DecodeAuthorizationMessageCommandOutput
|
||||
| GetAccessKeyInfoCommandOutput
|
||||
| GetCallerIdentityCommandOutput
|
||||
| GetFederationTokenCommandOutput
|
||||
| GetSessionTokenCommandOutput;
|
||||
export interface ClientDefaults
|
||||
extends Partial<__SmithyResolvedConfiguration<__HttpHandlerOptions>> {
|
||||
requestHandler?: __HttpHandler;
|
||||
sha256?: __ChecksumConstructor | __HashConstructor;
|
||||
urlParser?: __UrlParser;
|
||||
bodyLengthChecker?: __BodyLengthCalculator;
|
||||
streamCollector?: __StreamCollector;
|
||||
base64Decoder?: __Decoder;
|
||||
base64Encoder?: __Encoder;
|
||||
utf8Decoder?: __Decoder;
|
||||
utf8Encoder?: __Encoder;
|
||||
runtime?: string;
|
||||
disableHostPrefix?: boolean;
|
||||
serviceId?: string;
|
||||
useDualstackEndpoint?: boolean | __Provider<boolean>;
|
||||
useFipsEndpoint?: boolean | __Provider<boolean>;
|
||||
region?: string | __Provider<string>;
|
||||
credentialDefaultProvider?: (input: any) => __Provider<__Credentials>;
|
||||
defaultUserAgentProvider?: Provider<__UserAgent>;
|
||||
maxAttempts?: number | __Provider<number>;
|
||||
retryMode?: string | __Provider<string>;
|
||||
logger?: __Logger;
|
||||
extensions?: RuntimeExtension[];
|
||||
defaultsMode?: __DefaultsMode | __Provider<__DefaultsMode>;
|
||||
}
|
||||
export type STSClientConfigType = Partial<
|
||||
__SmithyConfiguration<__HttpHandlerOptions>
|
||||
> &
|
||||
ClientDefaults &
|
||||
RegionInputConfig &
|
||||
EndpointInputConfig<EndpointParameters> &
|
||||
RetryInputConfig &
|
||||
HostHeaderInputConfig &
|
||||
StsAuthInputConfig &
|
||||
UserAgentInputConfig &
|
||||
ClientInputEndpointParameters;
|
||||
export interface STSClientConfig extends STSClientConfigType {}
|
||||
export type STSClientResolvedConfigType =
|
||||
__SmithyResolvedConfiguration<__HttpHandlerOptions> &
|
||||
Required<ClientDefaults> &
|
||||
RuntimeExtensionsConfig &
|
||||
RegionResolvedConfig &
|
||||
EndpointResolvedConfig<EndpointParameters> &
|
||||
RetryResolvedConfig &
|
||||
HostHeaderResolvedConfig &
|
||||
StsAuthResolvedConfig &
|
||||
UserAgentResolvedConfig &
|
||||
ClientResolvedEndpointParameters;
|
||||
export interface STSClientResolvedConfig extends STSClientResolvedConfigType {}
|
||||
export declare class STSClient extends __Client<
|
||||
__HttpHandlerOptions,
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly config: STSClientResolvedConfig;
|
||||
constructor(...[configuration]: __CheckOptionalClientConfig<STSClientConfig>);
|
||||
destroy(): void;
|
||||
}
|
||||
Generated
Vendored
-35
@@ -1,35 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import { AssumeRoleRequest, AssumeRoleResponse } from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface AssumeRoleCommandInput extends AssumeRoleRequest {}
|
||||
export interface AssumeRoleCommandOutput
|
||||
extends AssumeRoleResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class AssumeRoleCommand extends $Command<
|
||||
AssumeRoleCommandInput,
|
||||
AssumeRoleCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: AssumeRoleCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: AssumeRoleCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<AssumeRoleCommandInput, AssumeRoleCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-39
@@ -1,39 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
AssumeRoleWithSAMLRequest,
|
||||
AssumeRoleWithSAMLResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface AssumeRoleWithSAMLCommandInput
|
||||
extends AssumeRoleWithSAMLRequest {}
|
||||
export interface AssumeRoleWithSAMLCommandOutput
|
||||
extends AssumeRoleWithSAMLResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class AssumeRoleWithSAMLCommand extends $Command<
|
||||
AssumeRoleWithSAMLCommandInput,
|
||||
AssumeRoleWithSAMLCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: AssumeRoleWithSAMLCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: AssumeRoleWithSAMLCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<AssumeRoleWithSAMLCommandInput, AssumeRoleWithSAMLCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-42
@@ -1,42 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
AssumeRoleWithWebIdentityRequest,
|
||||
AssumeRoleWithWebIdentityResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface AssumeRoleWithWebIdentityCommandInput
|
||||
extends AssumeRoleWithWebIdentityRequest {}
|
||||
export interface AssumeRoleWithWebIdentityCommandOutput
|
||||
extends AssumeRoleWithWebIdentityResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class AssumeRoleWithWebIdentityCommand extends $Command<
|
||||
AssumeRoleWithWebIdentityCommandInput,
|
||||
AssumeRoleWithWebIdentityCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: AssumeRoleWithWebIdentityCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: AssumeRoleWithWebIdentityCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<
|
||||
AssumeRoleWithWebIdentityCommandInput,
|
||||
AssumeRoleWithWebIdentityCommandOutput
|
||||
>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-42
@@ -1,42 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
DecodeAuthorizationMessageRequest,
|
||||
DecodeAuthorizationMessageResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface DecodeAuthorizationMessageCommandInput
|
||||
extends DecodeAuthorizationMessageRequest {}
|
||||
export interface DecodeAuthorizationMessageCommandOutput
|
||||
extends DecodeAuthorizationMessageResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class DecodeAuthorizationMessageCommand extends $Command<
|
||||
DecodeAuthorizationMessageCommandInput,
|
||||
DecodeAuthorizationMessageCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: DecodeAuthorizationMessageCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: DecodeAuthorizationMessageCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<
|
||||
DecodeAuthorizationMessageCommandInput,
|
||||
DecodeAuthorizationMessageCommandOutput
|
||||
>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-38
@@ -1,38 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
GetAccessKeyInfoRequest,
|
||||
GetAccessKeyInfoResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface GetAccessKeyInfoCommandInput extends GetAccessKeyInfoRequest {}
|
||||
export interface GetAccessKeyInfoCommandOutput
|
||||
extends GetAccessKeyInfoResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class GetAccessKeyInfoCommand extends $Command<
|
||||
GetAccessKeyInfoCommandInput,
|
||||
GetAccessKeyInfoCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: GetAccessKeyInfoCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: GetAccessKeyInfoCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<GetAccessKeyInfoCommandInput, GetAccessKeyInfoCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-39
@@ -1,39 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
GetCallerIdentityRequest,
|
||||
GetCallerIdentityResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface GetCallerIdentityCommandInput
|
||||
extends GetCallerIdentityRequest {}
|
||||
export interface GetCallerIdentityCommandOutput
|
||||
extends GetCallerIdentityResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class GetCallerIdentityCommand extends $Command<
|
||||
GetCallerIdentityCommandInput,
|
||||
GetCallerIdentityCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: GetCallerIdentityCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: GetCallerIdentityCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<GetCallerIdentityCommandInput, GetCallerIdentityCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-39
@@ -1,39 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
GetFederationTokenRequest,
|
||||
GetFederationTokenResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface GetFederationTokenCommandInput
|
||||
extends GetFederationTokenRequest {}
|
||||
export interface GetFederationTokenCommandOutput
|
||||
extends GetFederationTokenResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class GetFederationTokenCommand extends $Command<
|
||||
GetFederationTokenCommandInput,
|
||||
GetFederationTokenCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: GetFederationTokenCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: GetFederationTokenCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<GetFederationTokenCommandInput, GetFederationTokenCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
Generated
Vendored
-38
@@ -1,38 +0,0 @@
|
||||
import { EndpointParameterInstructions } from "@smithy/middleware-endpoint";
|
||||
import { Command as $Command } from "@smithy/smithy-client";
|
||||
import {
|
||||
Handler,
|
||||
HttpHandlerOptions as __HttpHandlerOptions,
|
||||
MetadataBearer as __MetadataBearer,
|
||||
MiddlewareStack,
|
||||
} from "@smithy/types";
|
||||
import {
|
||||
GetSessionTokenRequest,
|
||||
GetSessionTokenResponse,
|
||||
} from "../models/models_0";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientResolvedConfig,
|
||||
} from "../STSClient";
|
||||
export { __MetadataBearer, $Command };
|
||||
export interface GetSessionTokenCommandInput extends GetSessionTokenRequest {}
|
||||
export interface GetSessionTokenCommandOutput
|
||||
extends GetSessionTokenResponse,
|
||||
__MetadataBearer {}
|
||||
export declare class GetSessionTokenCommand extends $Command<
|
||||
GetSessionTokenCommandInput,
|
||||
GetSessionTokenCommandOutput,
|
||||
STSClientResolvedConfig
|
||||
> {
|
||||
readonly input: GetSessionTokenCommandInput;
|
||||
static getEndpointParameterInstructions(): EndpointParameterInstructions;
|
||||
constructor(input: GetSessionTokenCommandInput);
|
||||
resolveMiddleware(
|
||||
clientStack: MiddlewareStack<ServiceInputTypes, ServiceOutputTypes>,
|
||||
configuration: STSClientResolvedConfig,
|
||||
options?: __HttpHandlerOptions
|
||||
): Handler<GetSessionTokenCommandInput, GetSessionTokenCommandOutput>;
|
||||
private serialize;
|
||||
private deserialize;
|
||||
}
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
export * from "./AssumeRoleCommand";
|
||||
export * from "./AssumeRoleWithSAMLCommand";
|
||||
export * from "./AssumeRoleWithWebIdentityCommand";
|
||||
export * from "./DecodeAuthorizationMessageCommand";
|
||||
export * from "./GetAccessKeyInfoCommand";
|
||||
export * from "./GetCallerIdentityCommand";
|
||||
export * from "./GetFederationTokenCommand";
|
||||
export * from "./GetSessionTokenCommand";
|
||||
-22
@@ -1,22 +0,0 @@
|
||||
import { Pluggable } from "@smithy/types";
|
||||
import {
|
||||
DefaultCredentialProvider,
|
||||
RoleAssumer,
|
||||
RoleAssumerWithWebIdentity,
|
||||
} from "./defaultStsRoleAssumers";
|
||||
import {
|
||||
ServiceInputTypes,
|
||||
ServiceOutputTypes,
|
||||
STSClientConfig,
|
||||
} from "./STSClient";
|
||||
export declare const getDefaultRoleAssumer: (
|
||||
stsOptions?: Pick<STSClientConfig, "logger" | "region" | "requestHandler">,
|
||||
stsPlugins?: Pluggable<ServiceInputTypes, ServiceOutputTypes>[]
|
||||
) => RoleAssumer;
|
||||
export declare const getDefaultRoleAssumerWithWebIdentity: (
|
||||
stsOptions?: Pick<STSClientConfig, "logger" | "region" | "requestHandler">,
|
||||
stsPlugins?: Pluggable<ServiceInputTypes, ServiceOutputTypes>[]
|
||||
) => RoleAssumerWithWebIdentity;
|
||||
export declare const decorateDefaultCredentialProvider: (
|
||||
provider: DefaultCredentialProvider
|
||||
) => DefaultCredentialProvider;
|
||||
-24
@@ -1,24 +0,0 @@
|
||||
import { Credentials } from "@aws-sdk/types";
|
||||
import { Provider } from "@smithy/types";
|
||||
import { AssumeRoleCommandInput } from "./commands/AssumeRoleCommand";
|
||||
import { AssumeRoleWithWebIdentityCommandInput } from "./commands/AssumeRoleWithWebIdentityCommand";
|
||||
import { STSClient, STSClientConfig } from "./STSClient";
|
||||
export type RoleAssumer = (
|
||||
sourceCreds: Credentials,
|
||||
params: AssumeRoleCommandInput
|
||||
) => Promise<Credentials>;
|
||||
export declare const getDefaultRoleAssumer: (
|
||||
stsOptions: Pick<STSClientConfig, "logger" | "region" | "requestHandler">,
|
||||
stsClientCtor: new (options: STSClientConfig) => STSClient
|
||||
) => RoleAssumer;
|
||||
export type RoleAssumerWithWebIdentity = (
|
||||
params: AssumeRoleWithWebIdentityCommandInput
|
||||
) => Promise<Credentials>;
|
||||
export declare const getDefaultRoleAssumerWithWebIdentity: (
|
||||
stsOptions: Pick<STSClientConfig, "logger" | "region" | "requestHandler">,
|
||||
stsClientCtor: new (options: STSClientConfig) => STSClient
|
||||
) => RoleAssumerWithWebIdentity;
|
||||
export type DefaultCredentialProvider = (input: any) => Provider<Credentials>;
|
||||
export declare const decorateDefaultCredentialProvider: (
|
||||
provider: DefaultCredentialProvider
|
||||
) => DefaultCredentialProvider;
|
||||
Generated
Vendored
-35
@@ -1,35 +0,0 @@
|
||||
import {
|
||||
Endpoint,
|
||||
EndpointParameters as __EndpointParameters,
|
||||
EndpointV2,
|
||||
Provider,
|
||||
} from "@smithy/types";
|
||||
export interface ClientInputEndpointParameters {
|
||||
region?: string | Provider<string>;
|
||||
useDualstackEndpoint?: boolean | Provider<boolean>;
|
||||
useFipsEndpoint?: boolean | Provider<boolean>;
|
||||
endpoint?:
|
||||
| string
|
||||
| Provider<string>
|
||||
| Endpoint
|
||||
| Provider<Endpoint>
|
||||
| EndpointV2
|
||||
| Provider<EndpointV2>;
|
||||
useGlobalEndpoint?: boolean | Provider<boolean>;
|
||||
}
|
||||
export type ClientResolvedEndpointParameters = ClientInputEndpointParameters & {
|
||||
defaultSigningName: string;
|
||||
};
|
||||
export declare const resolveClientEndpointParameters: <T>(
|
||||
options: T & ClientInputEndpointParameters
|
||||
) => T &
|
||||
ClientInputEndpointParameters & {
|
||||
defaultSigningName: string;
|
||||
};
|
||||
export interface EndpointParameters extends __EndpointParameters {
|
||||
Region?: string;
|
||||
UseDualStack?: boolean;
|
||||
UseFIPS?: boolean;
|
||||
Endpoint?: string;
|
||||
UseGlobalEndpoint?: boolean;
|
||||
}
|
||||
-8
@@ -1,8 +0,0 @@
|
||||
import { EndpointV2, Logger } from "@smithy/types";
|
||||
import { EndpointParameters } from "./EndpointParameters";
|
||||
export declare const defaultEndpointResolver: (
|
||||
endpointParams: EndpointParameters,
|
||||
context?: {
|
||||
logger?: Logger;
|
||||
}
|
||||
) => EndpointV2;
|
||||
-2
@@ -1,2 +0,0 @@
|
||||
import { RuleSetObject } from "@smithy/types";
|
||||
export declare const ruleSet: RuleSetObject;
|
||||
-7
@@ -1,7 +0,0 @@
|
||||
import { AwsRegionExtensionConfiguration } from "@aws-sdk/types";
|
||||
import { HttpHandlerExtensionConfiguration } from "@smithy/protocol-http";
|
||||
import { DefaultExtensionConfiguration } from "@smithy/types";
|
||||
export interface STSExtensionConfiguration
|
||||
extends HttpHandlerExtensionConfiguration,
|
||||
DefaultExtensionConfiguration,
|
||||
AwsRegionExtensionConfiguration {}
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user