Force Refresh of credentials inside of STSCredentialProvider cache
- Vorherrschende Sprache
- Java
- Sterne
- 2.6k
- Forks
- 1k
- Ø Merge
- 2 T. 9 Std.
- Gemergte PRs (30 T.)
- 51
Beschreibung
### Describe the feature
include a public method for STSCredentialProvider that will forcefully refresh the sessionCache when called
### Use Case
Credentials inside of session cache can become invalid due to a role being deleted and recreated causing `InvalidClientTokenId`, this will continue till new creds are fetched which can take up to 12 hours depending on configuration and in the mean time the client using the provider will be in-operational. Calling the new method will allow for an almost immediate recovery time after catching the error
loose example of recovery
```
try{ client call }
catch(InvalidClientTokenId e){
client.serviceClientConfiguration().credentialsProvider().asInstanceOf[StsAssumeRoleCredentialsProvider].refreshCredentials()
}
```
### Proposed Solution
### StsCredentialsProvider
```
public void refreshCredentials(){
sessionCache.forceRefreshCache();
}
```
### CachedSupplier
```
public void forceRefreshCache() {
try {
boolean lockAcquired = refreshLock.tryLock(BLOCKING_REFRESH_MAX_WAIT.getSeconds(), TimeUnit.SECONDS);
try {
log.debug(() -> "(" + cachedValueName + ") Refreshing cached value.");
// It wasn't, call the supplier to update it.
if (prefetchStrategyInitialized.compareAndSet(false, true)) {
prefetchStrategy.initializeCachedSupplier(this);
}
try {
RefreshResult cachedValue = handleFetchedSuccess(prefetchStrategy.fetch(valueSupplier));
this.cachedValue = cachedValue;
log.debug(() -> "(" + cachedValueName + ") Successfully refreshed cached value. "
+ "Next Prefetch Time: " + cachedValue.prefetchTime() + ". "
+ "Next Stale Time: " + cachedValue.staleTime());
} catch (RuntimeException t) {
cachedValue = handleFetchFailure(t);
}
} finally {
if (lockAcquired) {
refreshLock.unlock();
}
}
} catch (InterruptedException e) {
Thread.currentThread().interrupt();
throw new IllegalStateException("Interrupted waiting to refresh a cached value.", e);
}
}
```
### Other Information
_No response_
### Acknowledgements
- [X] I may be able to implement this feature request
- [x] This feature might incur a breaking change
### AWS Java SDK version used
2.0
### JDK version used
openjdk version "1.8.0_422"
### Operating System and version
Amazon Linux 2 x86_64 5.10 Kernel
Beitragsleitfaden
Rechercherichtung
Beginne mit StsCredentialsProvider und CachedSupplier und untersuche anschließend das vorhandene Verhalten zur Aktualisierung und Sperrung des Session-Caches. Füge den angeforderten öffentlichen Einstiegspunkt zur Aktualisierung hinzu und stelle sicher, dass der Cache bei Fehlern und Unterbrechungen einheitlich zwangsweise aktualisiert wird; abgeschlossen ist die Arbeit, wenn Aufrufer sich nach InvalidClientTokenId umgehend erholen können.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- aws, java
- Bereich
- authentication, security
- Issue-Typ
- Feature
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 45/100