aws-cloudformation / aws-cloudformation/cloudformation-cli-java-plugin

AmazonWebServicesClientProxy.logRequestMetadataV2 causes a premature evaluation of the response object

Đang mở
#414 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
Ngôn ngữ chính
Java
Star
30
Fork
48
Chỉ số merge pull request
Không có pull request nào được merge trong 30 ngày

Mô tả

**Summary**: `AmazonWebServicesClientProxy.logRequestMetadataV2` causes lazily-evaluated SDK response objects (streams, iterables) to be evaluated immediately. A response resolve would immediately engage the SDK client and execute the service API calls. Whenever a consumer of this response object would access the data again, it would have to be re-resolved and the same API calls would be executed once again. The issue issue exists in the latest lib version.

**Example**: using `injectCredentialsAndInvokeIterableV2` paginated operation causes the SDK to perform 2x more API requests.

**Details**:
`AmazonWebServicesClientProxy` exposes multiple handles to interact with the SDK client. A response object could be either immediately (plain `AwsResponse` object) or lazily (`CompletableFuture`, `SdkIterable`, `ResponseInputStream`) evaluated. A private logging routine called `logRequestMetadataV2` causes lazily evaluated response objects to be evaluated immediately for the sake of logging. The resolve would cause a full range of the service API calls to be executed. By default, the SDK would not perform a deep response cache, hence a secondary access to the response data would once again hook up the SDK client, which would perform the same set of API calls.

```java
public >
IterableT
injectCredentialsAndInvokeIterableV2(final RequestT request, final Function requestFunction) {

AwsRequestOverrideConfiguration overrideConfiguration = AwsRequestOverrideConfiguration.builder()
.credentialsProvider(v2CredentialsProvider).build();

@SuppressWarnings("unchecked")
RequestT wrappedRequest = (RequestT) request.toBuilder().overrideConfiguration(overrideConfiguration).build();

try {
IterableT response = requestFunction.apply(wrappedRequest);
response.forEach(r -> logRequestMetadataV2(request, r)); // <- this invocation would resolve the response object immediately
return response; // <- the response object is returned to the invoker. It would be re-resolved upon a data access.
} catch (final Throwable e) {
loggerProxy.log(String.format("Failed to execute remote function: {%s}", e.getMessage()));
throw e;
}
}
```

**Possible Mitigation**: `logRequestMetadataV2` (and any other kind of non-lazy logging) should be avoided on all non-immediately resolved result types in the following routines:
* `injectCredentialsAndInvokeV2Async`
* `injectCredentialsAndInvokeIterableV2`
* `injectCredentialsAndInvokeV2InputStream`
* `injectCredentialsAndInvokeV2Bytes`

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.