aws-cloudformation / aws-cloudformation/cloudformation-cli
Limitations when using get_session_token
- Vorherrschende Sprache
- Python
- Sterne
- 336
- Forks
- 172
- Ø Merge
- 3 T. 5 Min.
- Gemergte PRs (30 T.)
- 3
Beschreibung
Currently when doing a test the code will use `get_session_token` when an execution role isn't provided or the credential chain being used doesn't have a session token.
https://github.com/aws-cloudformation/cloudformation-cli/blob/1d32b070d26cf6c8d17b03dc06190c08d5c9444b/src/rpdk/core/boto_helpers.py#L67
The [get_session_token](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/sts.html#STS.Client.get_session_token) will return back credentials that have a few exceptions.
```
You cannot call any IAM API operations unless MFA authentication information is included in the request.
You cannot call any STS API except AssumeRole or GetCallerIdentity .
```
The result is if you are testing an IAM resource or using STS in your resource the tests will fail.
The workaround is to use an execution role.
Beitragsleitfaden
Rechercherichtung
Lies src/rpdk/core/boto_helpers.py am Aufruf von get_session_token und reproduziere dann den Fehler beim Testen von IAM oder bei der Verwendung von STS ohne eine Ausführungsrolle. Erledigt ist die Aufgabe, wenn der Anmeldeinformationspfad nicht mehr dazu führt, dass diese Tests fehlschlagen, und die betroffenen Fälle durch Tests abgedeckt sind; das Issue gibt das vorgesehene Ersatzverhalten nicht an.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- aws, python
- Bereich
- authentication, cloud
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 38/100