Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type AccessDeniedException ¶
type AccessDeniedException struct {
Message *string
ErrorCodeOverride *string
Error_ OAuth2ErrorCode
// contains filtered or unexported fields
}
Error thrown for access denied scenarios with flexible HTTP status mapping
Runtime HTTP Status Code Mapping:
- HTTP 401 (Unauthorized): TOKEN_EXPIRED, AUTHCODE_EXPIRED
- HTTP 403 (Forbidden): USER_CREDENTIALS_CHANGED, INSUFFICIENT_PERMISSIONS
The specific HTTP status code is determined at runtime based on the error enum value. Consumers should use the error field to determine the specific access denial reason.
func (*AccessDeniedException) Error ¶
func (e *AccessDeniedException) Error() string
func (*AccessDeniedException) ErrorCode ¶
func (e *AccessDeniedException) ErrorCode() string
func (*AccessDeniedException) ErrorFault ¶
func (e *AccessDeniedException) ErrorFault() smithy.ErrorFault
func (*AccessDeniedException) ErrorMessage ¶
func (e *AccessDeniedException) ErrorMessage() string
type AccessToken ¶
type AccessToken struct {
// AWS access key ID for temporary credentials
//
// This member is required.
AccessKeyId *string
// AWS secret access key for temporary credentials
//
// This member is required.
SecretAccessKey *string
// AWS session token for temporary credentials
//
// This member is required.
SessionToken *string
// contains filtered or unexported fields
}
AWS credentials structure containing temporary access credentials
The scoped-down, 15 minute duration AWS credentials. Scoping down will be based on CLI policy (CLI team needs to create it). Similar to cloud shell implementation.
type CreateOAuth2TokenRequestBody ¶
type CreateOAuth2TokenRequestBody struct {
// The client identifier (ARN) used during Sign-In onboarding Required for both
// authorization code and refresh token flows
//
// This member is required.
ClientId *string
// OAuth 2.0 grant type - determines which flow is used Must be
// "authorization_code" or "refresh_token"
//
// This member is required.
GrantType *string
// The authorization code received from /v1/authorize Required only when
// grant_type=authorization_code
Code *string
// PKCE code verifier to prove possession of the original code challenge Required
// only when grant_type=authorization_code
CodeVerifier *string
// The redirect URI that must match the original authorization request Required
// only when grant_type=authorization_code
RedirectUri *string
// The refresh token returned from auth_code redemption Required only when
// grant_type=refresh_token
RefreshToken *string
// contains filtered or unexported fields
}
Request body payload for CreateOAuth2Token operation
The operation type is determined by the grant_type parameter:
- grant_type=authorization_code: Requires code, redirect_uri, code_verifier
- grant_type=refresh_token: Requires refresh_token
type CreateOAuth2TokenResponseBody ¶
type CreateOAuth2TokenResponseBody struct {
// Scoped-down AWS credentials (15 minute duration) Present for both authorization
// code redemption and token refresh
//
// This member is required.
AccessToken *AccessToken
// Time to expiry in seconds (maximum 900) Present for both authorization code
// redemption and token refresh
//
// This member is required.
ExpiresIn *int32
// Encrypted refresh token with cnf.jkt (SHA-256 thumbprint of presented jwk)
// Always present in responses (required for both flows)
//
// This member is required.
RefreshToken *string
// Token type indicating this is AWS SigV4 credentials Value is "aws_sigv4" for
// both flows
//
// This member is required.
TokenType *string
// ID token containing user identity information Present only in authorization
// code redemption response (grant_type=authorization_code) Not included in token
// refresh responses
IdToken *string
// contains filtered or unexported fields
}
Response body payload for CreateOAuth2Token operation
The response content depends on the grant_type from the request:
- grant_type=authorization_code: Returns all fields including refresh_token and id_token
- grant_type=refresh_token: Returns access_token, token_type, expires_in, refresh_token (no id_token)
type InternalServerException ¶
type InternalServerException struct {
Message *string
ErrorCodeOverride *string
Error_ OAuth2ErrorCode
// contains filtered or unexported fields
}
Error thrown when an internal server error occurs
HTTP Status Code: 500 Internal Server Error
Used for unexpected server-side errors that prevent request processing.
func (*InternalServerException) Error ¶
func (e *InternalServerException) Error() string
func (*InternalServerException) ErrorCode ¶
func (e *InternalServerException) ErrorCode() string
func (*InternalServerException) ErrorFault ¶
func (e *InternalServerException) ErrorFault() smithy.ErrorFault
func (*InternalServerException) ErrorMessage ¶
func (e *InternalServerException) ErrorMessage() string
type OAuth2ErrorCode ¶
type OAuth2ErrorCode string
const ( // Token has expired and needs to be refreshed OAuth2ErrorCodeTokenExpired OAuth2ErrorCode = "TOKEN_EXPIRED" // User credentials have been changed OAuth2ErrorCodeUserCredentialsChanged OAuth2ErrorCode = "USER_CREDENTIALS_CHANGED" // Insufficient permissions to perform this operation OAuth2ErrorCodeInsufficientPermissions OAuth2ErrorCode = "INSUFFICIENT_PERMISSIONS" // Authorization code has expired OAuth2ErrorCodeAuthcodeExpired OAuth2ErrorCode = "AUTHCODE_EXPIRED" // Internal server error occurred OAuth2ErrorCodeServerError OAuth2ErrorCode = "server_error" // The request is missing a required parameter, includes an invalid parameter // value, or is otherwise malformed OAuth2ErrorCodeInvalidRequest OAuth2ErrorCode = "INVALID_REQUEST" )
Enum values for OAuth2ErrorCode
func (OAuth2ErrorCode) Values ¶
func (OAuth2ErrorCode) Values() []OAuth2ErrorCode
Values returns all known values for OAuth2ErrorCode. Note that this can be expanded in the future, and so it is only as up to date as the client.
The ordering of this slice is not guaranteed to be stable across updates.
type TooManyRequestsError ¶
type TooManyRequestsError struct {
Message *string
ErrorCodeOverride *string
Error_ OAuth2ErrorCode
// contains filtered or unexported fields
}
Error thrown when rate limit is exceeded
HTTP Status Code: 429 Too Many Requests
Possible OAuth2ErrorCode values:
- INVALID_REQUEST: Rate limiting, too many requests, abuse prevention
Possible causes:
- Too many token requests from the same client
- Rate limiting based on client_id or IP address
- Abuse prevention mechanisms triggered
- Service protection against excessive token generation
func (*TooManyRequestsError) Error ¶
func (e *TooManyRequestsError) Error() string
func (*TooManyRequestsError) ErrorCode ¶
func (e *TooManyRequestsError) ErrorCode() string
func (*TooManyRequestsError) ErrorFault ¶
func (e *TooManyRequestsError) ErrorFault() smithy.ErrorFault
func (*TooManyRequestsError) ErrorMessage ¶
func (e *TooManyRequestsError) ErrorMessage() string
type ValidationException ¶
type ValidationException struct {
Message *string
ErrorCodeOverride *string
Error_ OAuth2ErrorCode
// contains filtered or unexported fields
}
Error thrown when request validation fails
HTTP Status Code: 400 Bad Request
Used for request validation errors such as malformed parameters, missing required fields, or invalid parameter values.
func (*ValidationException) Error ¶
func (e *ValidationException) Error() string
func (*ValidationException) ErrorCode ¶
func (e *ValidationException) ErrorCode() string
func (*ValidationException) ErrorFault ¶
func (e *ValidationException) ErrorFault() smithy.ErrorFault
func (*ValidationException) ErrorMessage ¶
func (e *ValidationException) ErrorMessage() string