aws-cloudformation / aws-cloudformation/cloudformation-cli

Limitations when using get_session_token

Offen
#577 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
cli experience enhancement
Vorherrschende Sprache
Python
Sterne
336
Forks
172
Ø Merge
3 T. 5 Min.
Gemergte PRs (30 T.)
3

Beschreibung

Currently when doing a test the code will use `get_session_token` when an execution role isn't provided or the credential chain being used doesn't have a session token.
https://github.com/aws-cloudformation/cloudformation-cli/blob/1d32b070d26cf6c8d17b03dc06190c08d5c9444b/src/rpdk/core/boto_helpers.py#L67

The [get_session_token](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/sts.html#STS.Client.get_session_token) will return back credentials that have a few exceptions.
```
You cannot call any IAM API operations unless MFA authentication information is included in the request.
You cannot call any STS API except AssumeRole or GetCallerIdentity .
```

The result is if you are testing an IAM resource or using STS in your resource the tests will fail.

The workaround is to use an execution role.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Lies src/rpdk/core/boto_helpers.py am Aufruf von get_session_token und reproduziere dann den Fehler beim Testen von IAM oder bei der Verwendung von STS ohne eine Ausführungsrolle. Erledigt ist die Aufgabe, wenn der Anmeldeinformationspfad nicht mehr dazu führt, dass diese Tests fehlschlagen, und die betroffenen Fälle durch Tests abgedeckt sind; das Issue gibt das vorgesehene Ersatzverhalten nicht an.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, python
Bereich
authentication, cloud
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Muss geklärt werden
Anfängerfreundlichkeit
38/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.