aws / aws/aws-dynamodb-encryption-python

Support transactional methods in EncryptionClient

Open
#406 2 comments 0 reactions 0 assignees View on GitHub
enhancement
Dominant language
Python
Stars
95
Forks
57
PR merge metrics
No merged PRs in 30d

Description

### Problem:

- [transact_get_items()](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/dynamodb.html#DynamoDB.Client.transact_get_items)
- [transact_write_items()](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/dynamodb.html#DynamoDB.Client.transact_write_items)

Are not currently supported by the `EncryptionClient` and passed through to the underlying client.

### Solution:

Fully implement `transact_get_items()` and `transact_write_items()` in the `EncryptionClient`

### Out of scope:

Is there anything the solution will intentionally NOT address? No

### Workaround

I was able to implement the following workaround to encrypt one of the `Put` requests within my transaction:

```
aws_kms_cmp = AwsKmsCryptographicMaterialsProvider(key_id=KEY_ARN)
actions = AttributeActions(
default_action=CryptoAction.DO_NOTHING,
attribute_actions={"access_token": CryptoAction.ENCRYPT_AND_SIGN},
)
encrypted_client = EncryptedClient(
client=dynamodb.meta.client,
materials_provider=aws_kms_cmp,
attribute_actions=actions,
expect_standard_dictionaries=True,
auto_refresh_table_indexes=False
)

item = {
"pk": f"USER#{user_id}#ITEM#{item_id}",
"sk": "v0",
"access_token": access_token,
"institution_id": institution_id,
"institution_name": institution.get("name"),
"link_session_id": metadata.get("link_session_id"),
"created_at": now,
}

def mock_write_method(**kwargs):
return kwargs.get("Item")

encrypt_item = partial(
encrypt_put_item,
encrypted_client._encrypt_item,
encrypted_client._item_crypto_config,
mock_write_method,
)
encrypted_item = encrypt_item(TableName=TABLE_NAME, Item=item)

items = [
{
"Put": {
"TableName": TABLE_NAME,
"Item": encrypted_item
}
}
]
dynamodb_client.transact_write_items(TransactItems=items)
```

Contributor guide

Open the contributing guide

Research direction

Start at the EncryptionClient entry point and inspect how its existing DynamoDB operations interact with the underlying client. Compare the transact_get_items() and transact_write_items() AWS APIs with the workaround shown; done means both methods are fully supported instead of being passed through.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
databases, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.