logincreds

package
v1.19.23 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Jul 20, 2026 License: Apache-2.0 Imports: 0 Imported by: 0

Documentation

Overview

Package logincreds implements AWS credential provision for sessions created via an `aws login` command.

Index

Constants

View Source
const ProviderName = "LoginProvider"

ProviderName identifies the login provider.

Variables

This section is empty.

Functions

func StandardCachedTokenFilepath

func StandardCachedTokenFilepath(session, dir string) (string, error)

StandardCachedTokenFilepath returns the filepath for the cached login token file. Key that will be used to compute a SHA256 value that is hex encoded.

An overriden root dir can be provided, if not set the path defaults to ~/.aws/sso/cache.

Types

type Options

type Options struct {
	Client TokenAPIClient

	// APIOptions to pass to the underlying CreateOAuth2Token operation.
	ClientOptions []func(*signin.Options)

	// The path to the cached login token.
	CachedTokenFilepath string

	// Whether to restrict file permissions on newly-written cache files.
	// When true, files are created with 0600 on Unix.
	RestrictPermissions bool

	// The chain of providers that was used to create this provider.
	//
	// These values are for reporting purposes and are not meant to be set up
	// directly.
	CredentialSources []aws.CredentialSource
}

Options configures the Provider.

type Provider

type Provider struct {
	// contains filtered or unexported fields
}

Provider supplies credentials for an `aws login` session.

func New

func New(client TokenAPIClient, path string, opts ...func(*Options)) *Provider

New returns a new login session credentials provider.

func (*Provider) ProviderSources

func (p *Provider) ProviderSources() []aws.CredentialSource

ProviderSources returns the credential chain that was used to construct this provider.

func (*Provider) Retrieve

func (p *Provider) Retrieve(ctx context.Context) (aws.Credentials, error)

Retrieve generates a new set of temporary credentials using an `aws login` session.

type TokenAPIClient

type TokenAPIClient interface {
	CreateOAuth2Token(context.Context, *signin.CreateOAuth2TokenInput, ...func(*signin.Options)) (*signin.CreateOAuth2TokenOutput, error)
}

TokenAPIClient provides the interface for the login session's token retrieval operation.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL