Documentation
¶
Overview ¶
Package logincreds implements AWS credential provision for sessions created via an `aws login` command.
Index ¶
Constants ¶
const ProviderName = "LoginProvider"
ProviderName identifies the login provider.
Variables ¶
This section is empty.
Functions ¶
func StandardCachedTokenFilepath ¶
StandardCachedTokenFilepath returns the filepath for the cached login token file. Key that will be used to compute a SHA256 value that is hex encoded.
An overriden root dir can be provided, if not set the path defaults to ~/.aws/sso/cache.
Types ¶
type Options ¶
type Options struct {
Client TokenAPIClient
// APIOptions to pass to the underlying CreateOAuth2Token operation.
ClientOptions []func(*signin.Options)
// The path to the cached login token.
CachedTokenFilepath string
// Whether to restrict file permissions on newly-written cache files.
// When true, files are created with 0600 on Unix.
RestrictPermissions bool
// The chain of providers that was used to create this provider.
//
// These values are for reporting purposes and are not meant to be set up
// directly.
CredentialSources []aws.CredentialSource
}
Options configures the Provider.
type Provider ¶
type Provider struct {
// contains filtered or unexported fields
}
Provider supplies credentials for an `aws login` session.
func New ¶
func New(client TokenAPIClient, path string, opts ...func(*Options)) *Provider
New returns a new login session credentials provider.
func (*Provider) ProviderSources ¶
func (p *Provider) ProviderSources() []aws.CredentialSource
ProviderSources returns the credential chain that was used to construct this provider.
type TokenAPIClient ¶
type TokenAPIClient interface {
CreateOAuth2Token(context.Context, *signin.CreateOAuth2TokenInput, ...func(*signin.Options)) (*signin.CreateOAuth2TokenOutput, error)
}
TokenAPIClient provides the interface for the login session's token retrieval operation.