aws / aws/aws-sdk-cpp

Aws::Auth::STSProfileCredentialsProvider does not read from ~/.aws/credentials

Aperta
#1,963 1 commento 0 reazioni 0 assegnatari Vedi su GitHub
bug p2
Lingua principale
C++
Stelle
2.2k
Fork
1.2k
Merge medio
4g 11h
PR unite (30g)
13

Descrizione

### Describe the bug

`Aws::Auth::STSProfileCredentialsProvider` only looks at `~/.aws/config` when trying to look up a profile, but the `aws_access_key_id ` and `aws_secret_access_key` are conventionally stored in `~/.aws/credentials`. This causes applications using this provider to fail to acquire credentials, while applications built using other SDKs and the AWS CLI correctly find credentials.

### Expected Behavior

`Aws::Auth::STSProfileCredentialsProvider` should read keys from `~/.aws/credentials` when looking for a named profile.

### Current Behavior

`Aws::Auth::STSProfileCredentialsProvider` will only read keys from `~/.aws/config` when evaluating a profile.

### Reproduction Steps

The below code tells `STSProfileCredentialsProvider` to load credentials from the profile in `argv[1]`, and then print the count of buckets in an `s3:ListBuckets` call:

```c++
#include "config.h"

#include
#include
#include
#include
#include
#include
#include

int main(int argc, const char *argv[]) {
if (argc < 2) {
std::cerr << "Usage: " << argv[0] << " PROFILENAME" << std::endl;
return 1;
}

Aws::SDKOptions options;
options.loggingOptions.logLevel = Aws::Utils::Logging::LogLevel::Debug;
Aws::InitAPI(options);

Aws::S3::S3Client client(
std::make_shared(argv[1])
);
auto outcome = client.ListBuckets();
if (outcome.IsSuccess()) {
std::cout << outcome.GetResult().GetBuckets().size() << " buckets" << std::endl;
} else {
std::cout << "Error: " << outcome.GetError() << std::endl;
}

Aws::ShutdownAPI(options);
return 0;
}
```

With `aws_access_key_id` and `aws_secret_access_key` in `~/.aws/credentials`, this code will print `0 buckets`. It will list the correct number of buckets if the key fields are instead set in `~/.aws/config`.

### Possible Solution

`STSProfileCredentialsProvider` should read the `~/.aws/credentials` file when trying to load a profile.

### Additional Information/Context

_No response_

### AWS CPP SDK version used

1.9.238

### Compiler and Version used

gcc 11.3.0

### Operating System and version

Linux 5.15.43 on x86_64

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia da Aws::Auth::STSProfileCredentialsProvider e traccia il modo in cui carica un profilo denominato. Riproduci il problema con il programma C++ fornito e le credenziali memorizzate in ~/.aws/credentials. Il lavoro è completato quando il provider acquisisce le credenziali da quel file e la richiesta S3 ha esito positivo, mentre il comportamento esistente basato sulla configurazione rimane intatto.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
aws, cpp
Ambito
authentication
Tipo di issue
Bug
Difficoltà
3/5
Tempo stimato
1-2 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
48/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.