aws / aws/aws-sdk-java-v2

Force Refresh of credentials inside of STSCredentialProvider cache

Open
#5,545 0 comments 2 reactions 0 assignees View on GitHub
feature-request needs-triage
Dominant language
Java
Stars
2.6k
Forks
1k
Avg merge
2d 9h
Merged PRs (30d)
51

Description

### Describe the feature

include a public method for STSCredentialProvider that will forcefully refresh the sessionCache when called

### Use Case

Credentials inside of session cache can become invalid due to a role being deleted and recreated causing `InvalidClientTokenId`, this will continue till new creds are fetched which can take up to 12 hours depending on configuration and in the mean time the client using the provider will be in-operational. Calling the new method will allow for an almost immediate recovery time after catching the error

loose example of recovery

```
try{ client call }
catch(InvalidClientTokenId e){
client.serviceClientConfiguration().credentialsProvider().asInstanceOf[StsAssumeRoleCredentialsProvider].refreshCredentials()
}
```

### Proposed Solution

### StsCredentialsProvider
```
public void refreshCredentials(){
sessionCache.forceRefreshCache();
}
```
### CachedSupplier

```
public void forceRefreshCache() {
try {
boolean lockAcquired = refreshLock.tryLock(BLOCKING_REFRESH_MAX_WAIT.getSeconds(), TimeUnit.SECONDS);

try {
log.debug(() -> "(" + cachedValueName + ") Refreshing cached value.");

// It wasn't, call the supplier to update it.

if (prefetchStrategyInitialized.compareAndSet(false, true)) {
prefetchStrategy.initializeCachedSupplier(this);
}

try {
RefreshResult cachedValue = handleFetchedSuccess(prefetchStrategy.fetch(valueSupplier));
this.cachedValue = cachedValue;
log.debug(() -> "(" + cachedValueName + ") Successfully refreshed cached value. "
+ "Next Prefetch Time: " + cachedValue.prefetchTime() + ". "
+ "Next Stale Time: " + cachedValue.staleTime());
} catch (RuntimeException t) {
cachedValue = handleFetchFailure(t);
}
} finally {
if (lockAcquired) {
refreshLock.unlock();
}
}
} catch (InterruptedException e) {
Thread.currentThread().interrupt();
throw new IllegalStateException("Interrupted waiting to refresh a cached value.", e);
}
}
```

### Other Information

_No response_

### Acknowledgements

- [X] I may be able to implement this feature request
- [x] This feature might incur a breaking change

### AWS Java SDK version used

2.0

### JDK version used

openjdk version "1.8.0_422"

### Operating System and version

Amazon Linux 2 x86_64 5.10 Kernel

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.