🌱 Bump github.com/aws/aws-sdk-go-v2/config in the aws group (#1618)

Bumps the aws group with 1 update: [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2).


Updates `github.com/aws/aws-sdk-go-v2/config` from 1.32.28 to 1.32.29
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases)
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.32.28...config/v1.32.29)

---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
  dependency-version: 1.32.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aws
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
This commit is contained in:
dependabot[bot]
2026-07-13 07:23:37 +00:00
committed by GitHub
co-authored by lnx01
parent 0da4712eac
commit 86f6019ccd
18 changed files with 1514 additions and 62 deletions
+3 -3
View File
@@ -4,7 +4,7 @@ go 1.26.0
require (
github.com/aws/aws-sdk-go-v2 v1.42.1
github.com/aws/aws-sdk-go-v2/config v1.32.28
github.com/aws/aws-sdk-go-v2/config v1.32.29
github.com/aws/aws-sdk-go-v2/service/eks v1.89.0
github.com/aws/aws-sdk-go-v2/service/iam v1.55.0
github.com/aws/smithy-go v1.27.3
@@ -65,14 +65,14 @@ require (
github.com/Masterminds/sprig/v3 v3.3.0 // indirect
github.com/NYTimes/gziphandler v1.1.1 // indirect
github.com/antlr4-go/antlr/v4 v4.13.1 // indirect
github.com/aws/aws-sdk-go-v2/credentials v1.19.27 // indirect
github.com/aws/aws-sdk-go-v2/credentials v1.19.28 // indirect
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.30 // indirect
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.30 // indirect
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.30 // indirect
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.31 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.13 // indirect
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.30 // indirect
github.com/aws/aws-sdk-go-v2/service/signin v1.3.0 // indirect
github.com/aws/aws-sdk-go-v2/service/signin v1.4.0 // indirect
github.com/aws/aws-sdk-go-v2/service/sso v1.32.0 // indirect
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.37.0 // indirect
github.com/aws/aws-sdk-go-v2/service/sts v1.44.0 // indirect
+6 -6
View File
@@ -32,10 +32,10 @@ github.com/antlr4-go/antlr/v4 v4.13.1 h1:SqQKkuVZ+zWkMMNkjy5FZe5mr5WURWnlpmOuzYW
github.com/antlr4-go/antlr/v4 v4.13.1/go.mod h1:GKmUxMtwp6ZgGwZSva4eWPC5mS6vUAmOABFgjdkM7Nw=
github.com/aws/aws-sdk-go-v2 v1.42.1 h1:9eOTgu1z/dVtYpNZ3/8/XbbaX0x/BqE3HUzAzs6K0ek=
github.com/aws/aws-sdk-go-v2 v1.42.1/go.mod h1:5pKeft2eJj+gElQ38Jqg4ibCqh+/AK33/0X3hip7IjM=
github.com/aws/aws-sdk-go-v2/config v1.32.28 h1:qY6afygxK5c2PPU3Sz8W6yB5W44RF1vnmPdBwViDN+Y=
github.com/aws/aws-sdk-go-v2/config v1.32.28/go.mod h1:WeS/wN1IDs8YC+BxTrFz9ZyJ1rufRBQfirOcDusEpmQ=
github.com/aws/aws-sdk-go-v2/credentials v1.19.27 h1:cFksKkdaBGGmpe6XJpvrxFNWkbXY5/gwFqZNB2O9WCM=
github.com/aws/aws-sdk-go-v2/credentials v1.19.27/go.mod h1:20CoObBgNhFfl8/ggDQu2IZmItxDhkLcWSy4C3alDPI=
github.com/aws/aws-sdk-go-v2/config v1.32.29 h1:BcMHHnpiWKogf+gGfpj3K1w+Sktz29XDo/cPSAPO3FU=
github.com/aws/aws-sdk-go-v2/config v1.32.29/go.mod h1:+Kbhn8Es4kPUph3F/0W7avykytc+Jh2Ld9/msv9ljV4=
github.com/aws/aws-sdk-go-v2/credentials v1.19.28 h1:zTXJSsNcoO91/mTXsZoYf0AK8dvNPiA58/VtyGXR+wM=
github.com/aws/aws-sdk-go-v2/credentials v1.19.28/go.mod h1:Kd9E0JzDBW/q1xbsHFrev/GnbAf5J0Ng8xoyc7HZ91Q=
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.30 h1:/hi1JADLEW9YYryEz1w4GQu0EtP23pP553Cf9KgsDV4=
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.30/go.mod h1:/3AOgy4K17Dm4ucMZVC/MJkzy5kmfKUcINRHZyo0koQ=
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.30 h1:xM/Is9cKMHa8Jj8zkvWhvrFkZsXJV9E+BB4g0HW0duQ=
@@ -52,8 +52,8 @@ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.13 h1:mbRIur
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.13/go.mod h1:ITg9em2KbJx1s0y4aqRX5OYWG6HBZ5TVR//OdpEZ2CQ=
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.30 h1:/Z5jmNrKsSD7EmDjzAPsm/3L9IuOkzaynklJZ1qX7S4=
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.30/go.mod h1:lEzEZnOosE7zi8Z6royW1cFJTD9fpab4Ul1SBrllewk=
github.com/aws/aws-sdk-go-v2/service/signin v1.3.0 h1:i0+tbB9QBnzL5NrF2WR/zk8q2s+1N+RaDYr2627E8UI=
github.com/aws/aws-sdk-go-v2/service/signin v1.3.0/go.mod h1:mxC0nT/C8wMMS97DemZPzvUZxvIt+2Iq+eS3JdFZGgg=
github.com/aws/aws-sdk-go-v2/service/signin v1.4.0 h1:sLzmJGCMv+C8KqiJgEqDLB6vxaJGmobRh4rr//ZpA3w=
github.com/aws/aws-sdk-go-v2/service/signin v1.4.0/go.mod h1:mxC0nT/C8wMMS97DemZPzvUZxvIt+2Iq+eS3JdFZGgg=
github.com/aws/aws-sdk-go-v2/service/sso v1.32.0 h1:qjMmry/cBDee1E/2gyvel0uRYCi3mwRZ2hf6N+GAodo=
github.com/aws/aws-sdk-go-v2/service/sso v1.32.0/go.mod h1:u8af9Nqkmqnr96f7v9nHqzZT9XBwbXEkTiqT4ROuJSE=
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.37.0 h1:fpOlDPI55HdszaxapEGk6HsGosOUaM2YPWJpjMgp8UI=
+4
View File
@@ -1,3 +1,7 @@
# v1.32.29 (2026-07-08.2)
* **Dependency Update**: Updated to the latest SDK module versions
# v1.32.28 (2026-07-06)
* **Dependency Update**: Updated to the latest SDK module versions
+1 -1
View File
@@ -3,4 +3,4 @@
package config
// goModuleVersion is the tagged release for this module
const goModuleVersion = "1.32.28"
const goModuleVersion = "1.32.29"
+4
View File
@@ -1,3 +1,7 @@
# v1.19.28 (2026-07-08.2)
* **Dependency Update**: Updated to the latest SDK module versions
# v1.19.27 (2026-07-06)
* **Dependency Update**: Updated to the latest SDK module versions
+1 -1
View File
@@ -3,4 +3,4 @@
package credentials
// goModuleVersion is the tagged release for this module
const goModuleVersion = "1.19.27"
const goModuleVersion = "1.19.28"
+4
View File
@@ -1,3 +1,7 @@
# v1.4.0 (2026-07-08.2)
* **Feature**: Adds support for OAuth 2.0 token operations in AWS Sign-In, CreateOAuth2TokenWithIAM (client credentials flow), IntrospectOAuth2TokenWithIAM (token inspection), and RevokeOAuth2TokenWithIAM (token revocation).
# v1.3.0 (2026-07-06)
* **Feature**: Add request serialization snapshot tests.
@@ -0,0 +1,134 @@
// Code generated by smithy-go-codegen DO NOT EDIT.
package signin
import (
"context"
"github.com/aws/smithy-go/middleware"
"github.com/aws/smithy-go/ptr"
smithyhttp "github.com/aws/smithy-go/transport/http"
)
// Grants permission to exchange client credentials for an OAuth 2.0 access token
// scoped to a resource that can be used to access AWS services from applications
func (c *Client) CreateOAuth2TokenWithIAM(ctx context.Context, params *CreateOAuth2TokenWithIAMInput, optFns ...func(*Options)) (*CreateOAuth2TokenWithIAMOutput, error) {
if params == nil {
params = &CreateOAuth2TokenWithIAMInput{}
}
result, metadata, err := c.invokeOperation(ctx, "CreateOAuth2TokenWithIAM", params, optFns, c.addOperationCreateOAuth2TokenWithIAMMiddlewares)
if err != nil {
return nil, err
}
out := result.(*CreateOAuth2TokenWithIAMOutput)
out.ResultMetadata = metadata
return out, nil
}
// Input structure for CreateOAuth2TokenWithIAM operation
type CreateOAuth2TokenWithIAMInput struct {
// OAuth 2.0 grant type. Must be "client_credentials".
//
// This member is required.
GrantType *string
// The OAuth resource for which the access token is requested. Example:
// "aws-mcp.amazonaws.com".
//
// This member is required.
Resource *string
noSmithyDocumentSerde
}
func (in *CreateOAuth2TokenWithIAMInput) bindEndpointParams(p *EndpointParameters) {
p.IsOAuthEndpoint = ptr.Bool(true)
}
// Output structure for CreateOAuth2TokenWithIAM operation
//
// Contains the JWT access token, token type, and expiration per RFC 6749 §5.1.
type CreateOAuth2TokenWithIAMOutput struct {
// JWT access token containing principal identity, resource scope, and session
// metadata
//
// This member is required.
AccessToken *string
// Token lifetime in seconds. Value is the minimum of session validity and 1 hour.
//
// This member is required.
ExpiresIn *int32
// Always "Bearer" per OAuth 2.1 specification
//
// This member is required.
TokenType *string
// Metadata pertaining to the operation's result.
ResultMetadata middleware.Metadata
noSmithyDocumentSerde
}
func (c *Client) addOperationCreateOAuth2TokenWithIAMMiddlewares(stack *middleware.Stack, options Options) (err error) {
err = stack.Serialize.Add(&awsRestjson1_serializeOpCreateOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
err = stack.Deserialize.Add(&awsRestjson1_deserializeOpCreateOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
if err = addlegacyEndpointContextSetter(stack, options); err != nil {
return err
}
if err = addComputeContentLength(stack); err != nil {
return err
}
if err = addResolveEndpointMiddleware(stack, options); err != nil {
return err
}
if err = addComputePayloadSHA256(stack); err != nil {
return err
}
if err = addRecordResponseTiming(stack); err != nil {
return err
}
if err = smithyhttp.AddErrorCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = smithyhttp.AddCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = addCredentialSource(stack, options); err != nil {
return err
}
if err = addOpCreateOAuth2TokenWithIAMValidationMiddleware(stack); err != nil {
return err
}
if err = stack.Initialize.Add(newServiceMetadataMiddleware(options.Region, "CreateOAuth2TokenWithIAM"), middleware.Before); err != nil {
return err
}
if err = addRequestIDRetrieverMiddleware(stack); err != nil {
return err
}
if err = addResponseErrorMiddleware(stack); err != nil {
return err
}
if err = addRequestResponseLogging(stack, options); err != nil {
return err
}
if err = addDisableHTTPSMiddleware(stack, options); err != nil {
return err
}
if err = addInterceptors(stack, options); err != nil {
return err
}
return nil
}
@@ -0,0 +1,184 @@
// Code generated by smithy-go-codegen DO NOT EDIT.
package signin
import (
"context"
"github.com/aws/smithy-go/middleware"
"github.com/aws/smithy-go/ptr"
smithyhttp "github.com/aws/smithy-go/transport/http"
)
// Grants permission to inspect the metadata and state of an OAuth 2.0 access
// token or refresh token
//
// Implements RFC 7662 OAuth 2.0 Token Introspection over a SigV4-authenticated
// endpoint. Inspects the metadata of an access_token or refresh_token issued by
// AWS Sign-In and returns the claims associated with it.
//
// Inactive token semantics (RFC 7662 §2.2): when the supplied token is unknown,
// expired, revoked, malformed, or owned by a different account, the response body
// is exactly { "active": false } with all other claims omitted.
func (c *Client) IntrospectOAuth2TokenWithIAM(ctx context.Context, params *IntrospectOAuth2TokenWithIAMInput, optFns ...func(*Options)) (*IntrospectOAuth2TokenWithIAMOutput, error) {
if params == nil {
params = &IntrospectOAuth2TokenWithIAMInput{}
}
result, metadata, err := c.invokeOperation(ctx, "IntrospectOAuth2TokenWithIAM", params, optFns, c.addOperationIntrospectOAuth2TokenWithIAMMiddlewares)
if err != nil {
return nil, err
}
out := result.(*IntrospectOAuth2TokenWithIAMOutput)
out.ResultMetadata = metadata
return out, nil
}
// Input structure for IntrospectOAuth2TokenWithIAM operation
//
// RFC 7662 §2.1 introspection request. Contains the token to inspect and an
// optional hint about the token's type.
type IntrospectOAuth2TokenWithIAMInput struct {
// The string value of the token to introspect. May be either an access_token or a
// refresh_token issued by AWS Sign-In.
//
// This member is required.
Token *string
// Optional hint about the type of the token submitted for introspection. The
// server uses this hint to optimize lookup, but still falls back to the other
// token type on miss. Allowed values: access_token, refresh_token.
TokenTypeHint *string
noSmithyDocumentSerde
}
func (in *IntrospectOAuth2TokenWithIAMInput) bindEndpointParams(p *EndpointParameters) {
p.IsOAuthEndpoint = ptr.Bool(true)
}
// Output structure for IntrospectOAuth2TokenWithIAM operation
//
// RFC 7662 §2.2 introspection response. Only active is required; all other claims
// are omitted when the token is inactive.
type IntrospectOAuth2TokenWithIAMOutput struct {
// Indicates whether the token is currently active. true only when the token is
// valid, has not expired, has not been revoked, and belongs to the caller's
// account.
//
// This member is required.
Active *bool
// 12-digit AWS account ID of the token's subject principal.
AccountId *string
// Audience of the token: the OAuth resource the token is scoped to (for example,
// "aws-mcp.amazonaws.com"). Omitted for refresh tokens.
Aud *string
// Client identifier for the OAuth 2.0 client that requested the token.
ClientId *string
// Token expiration time as a NumericDate (Unix epoch seconds).
Exp *int64
// Token issuance time as a NumericDate (Unix epoch seconds).
Iat *int64
// Issuer of the token. Always "signin.amazonaws.com" for AWS Sign-In.
Iss *string
// Unique identifier for the token.
Jti *string
// Token "not before" time as a NumericDate (Unix epoch seconds).
Nbf *int64
// The OAuth resource the token is scoped to during Human OAuth flow. Only present
// for refresh token introspection.
Resource *string
// AWS Sign-In session ARN bound to the token, of the form
// arn:aws:signin:{region}:{account}:session/{uuid}.
SigninSession *string
// Subject of the token: the IAM principal ARN. For assumed-role sessions, this is
// the session ARN (matches sts:GetCallerIdentity's Arn field), e.g.
// arn:aws:sts::123456789012:assumed-role/MyRole/session-name.
Sub *string
// Indicates which kind of token was introspected. One of "access_token" or
// "refresh_token".
TokenType *string
// User identifier matching sts:GetCallerIdentity's UserId field for the token's
// subject principal (e.g. "AIDAEXAMPLE" for an IAM user, or
// "AROAEXAMPLE:session-name" for an assumed role).
UserId *string
// Metadata pertaining to the operation's result.
ResultMetadata middleware.Metadata
noSmithyDocumentSerde
}
func (c *Client) addOperationIntrospectOAuth2TokenWithIAMMiddlewares(stack *middleware.Stack, options Options) (err error) {
err = stack.Serialize.Add(&awsRestjson1_serializeOpIntrospectOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
err = stack.Deserialize.Add(&awsRestjson1_deserializeOpIntrospectOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
if err = addlegacyEndpointContextSetter(stack, options); err != nil {
return err
}
if err = addComputeContentLength(stack); err != nil {
return err
}
if err = addResolveEndpointMiddleware(stack, options); err != nil {
return err
}
if err = addComputePayloadSHA256(stack); err != nil {
return err
}
if err = addRecordResponseTiming(stack); err != nil {
return err
}
if err = smithyhttp.AddErrorCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = smithyhttp.AddCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = addCredentialSource(stack, options); err != nil {
return err
}
if err = addOpIntrospectOAuth2TokenWithIAMValidationMiddleware(stack); err != nil {
return err
}
if err = stack.Initialize.Add(newServiceMetadataMiddleware(options.Region, "IntrospectOAuth2TokenWithIAM"), middleware.Before); err != nil {
return err
}
if err = addRequestIDRetrieverMiddleware(stack); err != nil {
return err
}
if err = addResponseErrorMiddleware(stack); err != nil {
return err
}
if err = addRequestResponseLogging(stack, options); err != nil {
return err
}
if err = addDisableHTTPSMiddleware(stack, options); err != nil {
return err
}
if err = addInterceptors(stack, options); err != nil {
return err
}
return nil
}
@@ -0,0 +1,122 @@
// Code generated by smithy-go-codegen DO NOT EDIT.
package signin
import (
"context"
"github.com/aws/smithy-go/middleware"
"github.com/aws/smithy-go/ptr"
smithyhttp "github.com/aws/smithy-go/transport/http"
)
// Grants permission to revoke an OAuth 2.0 refresh token and its associated
// refresh tokens
//
// Revokes a refresh_token issued by AWS Sign-In, invalidating the entire token
// chain so that the refresh_token can no longer be used to mint new access_tokens.
//
// Idempotency: revoking an already-revoked, expired, or otherwise invalid token
// still returns 200 OK with an empty body. Only the refresh_token type is
// accepted.
func (c *Client) RevokeOAuth2TokenWithIAM(ctx context.Context, params *RevokeOAuth2TokenWithIAMInput, optFns ...func(*Options)) (*RevokeOAuth2TokenWithIAMOutput, error) {
if params == nil {
params = &RevokeOAuth2TokenWithIAMInput{}
}
result, metadata, err := c.invokeOperation(ctx, "RevokeOAuth2TokenWithIAM", params, optFns, c.addOperationRevokeOAuth2TokenWithIAMMiddlewares)
if err != nil {
return nil, err
}
out := result.(*RevokeOAuth2TokenWithIAMOutput)
out.ResultMetadata = metadata
return out, nil
}
// Input structure for RevokeOAuth2TokenWithIAM operation
//
// RFC 7009 §2.1 revocation request. Contains the refresh_token to revoke.
type RevokeOAuth2TokenWithIAMInput struct {
// The refresh_token to revoke. Must be a refresh_token issued by AWS Sign-In
// (prefix "ASOR"); access_tokens are not accepted for revocation.
//
// This member is required.
Token *string
noSmithyDocumentSerde
}
func (in *RevokeOAuth2TokenWithIAMInput) bindEndpointParams(p *EndpointParameters) {
p.IsOAuthEndpoint = ptr.Bool(true)
}
// Output structure for RevokeOAuth2TokenWithIAM operation
//
// RFC 7009 §2.2 revocation response. The endpoint returns 200 OK with an empty
// body on success; there are no response fields.
type RevokeOAuth2TokenWithIAMOutput struct {
// Metadata pertaining to the operation's result.
ResultMetadata middleware.Metadata
noSmithyDocumentSerde
}
func (c *Client) addOperationRevokeOAuth2TokenWithIAMMiddlewares(stack *middleware.Stack, options Options) (err error) {
err = stack.Serialize.Add(&awsRestjson1_serializeOpRevokeOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
err = stack.Deserialize.Add(&awsRestjson1_deserializeOpRevokeOAuth2TokenWithIAM{}, middleware.After)
if err != nil {
return err
}
if err = addlegacyEndpointContextSetter(stack, options); err != nil {
return err
}
if err = addComputeContentLength(stack); err != nil {
return err
}
if err = addResolveEndpointMiddleware(stack, options); err != nil {
return err
}
if err = addComputePayloadSHA256(stack); err != nil {
return err
}
if err = addRecordResponseTiming(stack); err != nil {
return err
}
if err = smithyhttp.AddErrorCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = smithyhttp.AddCloseResponseBodyMiddleware(stack); err != nil {
return err
}
if err = addCredentialSource(stack, options); err != nil {
return err
}
if err = addOpRevokeOAuth2TokenWithIAMValidationMiddleware(stack); err != nil {
return err
}
if err = stack.Initialize.Add(newServiceMetadataMiddleware(options.Region, "RevokeOAuth2TokenWithIAM"), middleware.Before); err != nil {
return err
}
if err = addRequestIDRetrieverMiddleware(stack); err != nil {
return err
}
if err = addResponseErrorMiddleware(stack); err != nil {
return err
}
if err = addRequestResponseLogging(stack, options); err != nil {
return err
}
if err = addDisableHTTPSMiddleware(stack, options); err != nil {
return err
}
if err = addInterceptors(stack, options); err != nil {
return err
}
return nil
}
+578
View File
@@ -180,6 +180,193 @@ func awsRestjson1_deserializeOpDocumentCreateOAuth2TokenOutput(v **CreateOAuth2T
return nil
}
type awsRestjson1_deserializeOpCreateOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_deserializeOpCreateOAuth2TokenWithIAM) ID() string {
return "OperationDeserializer"
}
func (m *awsRestjson1_deserializeOpCreateOAuth2TokenWithIAM) HandleDeserialize(ctx context.Context, in middleware.DeserializeInput, next middleware.DeserializeHandler) (
out middleware.DeserializeOutput, metadata middleware.Metadata, err error,
) {
out, metadata, err = next.HandleDeserialize(ctx, in)
if err != nil {
return out, metadata, err
}
_, span := tracing.StartSpan(ctx, "OperationDeserializer")
endTimer := startMetricTimer(ctx, "client.call.deserialization_duration")
defer endTimer()
defer span.End()
response, ok := out.RawResponse.(*smithyhttp.Response)
if !ok {
return out, metadata, &smithy.DeserializationError{Err: fmt.Errorf("unknown transport type %T", out.RawResponse)}
}
if response.StatusCode < 200 || response.StatusCode >= 300 {
return out, metadata, awsRestjson1_deserializeOpErrorCreateOAuth2TokenWithIAM(response, &metadata)
}
output := &CreateOAuth2TokenWithIAMOutput{}
out.Result = output
var buff [1024]byte
ringBuffer := smithyio.NewRingBuffer(buff[:])
body := io.TeeReader(response.Body, ringBuffer)
decoder := json.NewDecoder(body)
decoder.UseNumber()
var shape interface{}
if err := decoder.Decode(&shape); err != nil && err != io.EOF {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
err = &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body, %w", err),
Snapshot: snapshot.Bytes(),
}
return out, metadata, err
}
err = awsRestjson1_deserializeOpDocumentCreateOAuth2TokenWithIAMOutput(&output, shape)
if err != nil {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
return out, metadata, &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body with invalid JSON, %w", err),
Snapshot: snapshot.Bytes(),
}
}
span.End()
return out, metadata, err
}
func awsRestjson1_deserializeOpErrorCreateOAuth2TokenWithIAM(response *smithyhttp.Response, metadata *middleware.Metadata) error {
var errorBuffer bytes.Buffer
if _, err := io.Copy(&errorBuffer, response.Body); err != nil {
return &smithy.DeserializationError{Err: fmt.Errorf("failed to copy error response body, %w", err)}
}
errorBody := bytes.NewReader(errorBuffer.Bytes())
errorCode := "UnknownError"
errorMessage := errorCode
headerCode := response.Header.Get("X-Amzn-ErrorType")
if len(headerCode) != 0 {
errorCode = restjson.SanitizeErrorCode(headerCode)
}
var buff [1024]byte
ringBuffer := smithyio.NewRingBuffer(buff[:])
body := io.TeeReader(errorBody, ringBuffer)
decoder := json.NewDecoder(body)
decoder.UseNumber()
jsonCode, message, err := restjson.GetErrorInfo(decoder)
if err != nil {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
err = &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body, %w", err),
Snapshot: snapshot.Bytes(),
}
return err
}
errorBody.Seek(0, io.SeekStart)
if len(headerCode) == 0 && len(jsonCode) != 0 {
errorCode = restjson.SanitizeErrorCode(jsonCode)
}
if len(message) != 0 {
errorMessage = message
}
switch {
case strings.EqualFold("AccessDeniedException", errorCode):
return awsRestjson1_deserializeErrorAccessDeniedException(response, errorBody)
case strings.EqualFold("InternalServerException", errorCode):
return awsRestjson1_deserializeErrorInternalServerException(response, errorBody)
case strings.EqualFold("TooManyRequestsError", errorCode):
return awsRestjson1_deserializeErrorTooManyRequestsError(response, errorBody)
case strings.EqualFold("ValidationException", errorCode):
return awsRestjson1_deserializeErrorValidationException(response, errorBody)
default:
genericError := &smithy.GenericAPIError{
Code: errorCode,
Message: errorMessage,
}
return genericError
}
}
func awsRestjson1_deserializeOpDocumentCreateOAuth2TokenWithIAMOutput(v **CreateOAuth2TokenWithIAMOutput, value interface{}) error {
if v == nil {
return fmt.Errorf("unexpected nil of type %T", v)
}
if value == nil {
return nil
}
shape, ok := value.(map[string]interface{})
if !ok {
return fmt.Errorf("unexpected JSON type %v", value)
}
var sv *CreateOAuth2TokenWithIAMOutput
if *v == nil {
sv = &CreateOAuth2TokenWithIAMOutput{}
} else {
sv = *v
}
for key, value := range shape {
switch key {
case "access_token":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected OAuthAccessToken to be of type string, got %T instead", value)
}
sv.AccessToken = ptr.String(jtv)
}
case "expires_in":
if value != nil {
jtv, ok := value.(json.Number)
if !ok {
return fmt.Errorf("expected TokenExpiresIn to be json.Number, got %T instead", value)
}
i64, err := jtv.Int64()
if err != nil {
return err
}
sv.ExpiresIn = ptr.Int32(int32(i64))
}
case "token_type":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected BearerTokenType to be of type string, got %T instead", value)
}
sv.TokenType = ptr.String(jtv)
}
default:
_, _ = key, value
}
}
*v = sv
return nil
}
type awsRestjson1_deserializeOpDeleteConsoleAuthorizationConfiguration struct {
}
@@ -813,6 +1000,300 @@ func awsRestjson1_deserializeOpDocumentGetResourcePolicyOutput(v **GetResourcePo
return nil
}
type awsRestjson1_deserializeOpIntrospectOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_deserializeOpIntrospectOAuth2TokenWithIAM) ID() string {
return "OperationDeserializer"
}
func (m *awsRestjson1_deserializeOpIntrospectOAuth2TokenWithIAM) HandleDeserialize(ctx context.Context, in middleware.DeserializeInput, next middleware.DeserializeHandler) (
out middleware.DeserializeOutput, metadata middleware.Metadata, err error,
) {
out, metadata, err = next.HandleDeserialize(ctx, in)
if err != nil {
return out, metadata, err
}
_, span := tracing.StartSpan(ctx, "OperationDeserializer")
endTimer := startMetricTimer(ctx, "client.call.deserialization_duration")
defer endTimer()
defer span.End()
response, ok := out.RawResponse.(*smithyhttp.Response)
if !ok {
return out, metadata, &smithy.DeserializationError{Err: fmt.Errorf("unknown transport type %T", out.RawResponse)}
}
if response.StatusCode < 200 || response.StatusCode >= 300 {
return out, metadata, awsRestjson1_deserializeOpErrorIntrospectOAuth2TokenWithIAM(response, &metadata)
}
output := &IntrospectOAuth2TokenWithIAMOutput{}
out.Result = output
var buff [1024]byte
ringBuffer := smithyio.NewRingBuffer(buff[:])
body := io.TeeReader(response.Body, ringBuffer)
decoder := json.NewDecoder(body)
decoder.UseNumber()
var shape interface{}
if err := decoder.Decode(&shape); err != nil && err != io.EOF {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
err = &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body, %w", err),
Snapshot: snapshot.Bytes(),
}
return out, metadata, err
}
err = awsRestjson1_deserializeOpDocumentIntrospectOAuth2TokenWithIAMOutput(&output, shape)
if err != nil {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
return out, metadata, &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body with invalid JSON, %w", err),
Snapshot: snapshot.Bytes(),
}
}
span.End()
return out, metadata, err
}
func awsRestjson1_deserializeOpErrorIntrospectOAuth2TokenWithIAM(response *smithyhttp.Response, metadata *middleware.Metadata) error {
var errorBuffer bytes.Buffer
if _, err := io.Copy(&errorBuffer, response.Body); err != nil {
return &smithy.DeserializationError{Err: fmt.Errorf("failed to copy error response body, %w", err)}
}
errorBody := bytes.NewReader(errorBuffer.Bytes())
errorCode := "UnknownError"
errorMessage := errorCode
headerCode := response.Header.Get("X-Amzn-ErrorType")
if len(headerCode) != 0 {
errorCode = restjson.SanitizeErrorCode(headerCode)
}
var buff [1024]byte
ringBuffer := smithyio.NewRingBuffer(buff[:])
body := io.TeeReader(errorBody, ringBuffer)
decoder := json.NewDecoder(body)
decoder.UseNumber()
jsonCode, message, err := restjson.GetErrorInfo(decoder)
if err != nil {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
err = &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body, %w", err),
Snapshot: snapshot.Bytes(),
}
return err
}
errorBody.Seek(0, io.SeekStart)
if len(headerCode) == 0 && len(jsonCode) != 0 {
errorCode = restjson.SanitizeErrorCode(jsonCode)
}
if len(message) != 0 {
errorMessage = message
}
switch {
case strings.EqualFold("AccessDeniedException", errorCode):
return awsRestjson1_deserializeErrorAccessDeniedException(response, errorBody)
case strings.EqualFold("InternalServerException", errorCode):
return awsRestjson1_deserializeErrorInternalServerException(response, errorBody)
case strings.EqualFold("TooManyRequestsError", errorCode):
return awsRestjson1_deserializeErrorTooManyRequestsError(response, errorBody)
case strings.EqualFold("ValidationException", errorCode):
return awsRestjson1_deserializeErrorValidationException(response, errorBody)
default:
genericError := &smithy.GenericAPIError{
Code: errorCode,
Message: errorMessage,
}
return genericError
}
}
func awsRestjson1_deserializeOpDocumentIntrospectOAuth2TokenWithIAMOutput(v **IntrospectOAuth2TokenWithIAMOutput, value interface{}) error {
if v == nil {
return fmt.Errorf("unexpected nil of type %T", v)
}
if value == nil {
return nil
}
shape, ok := value.(map[string]interface{})
if !ok {
return fmt.Errorf("unexpected JSON type %v", value)
}
var sv *IntrospectOAuth2TokenWithIAMOutput
if *v == nil {
sv = &IntrospectOAuth2TokenWithIAMOutput{}
} else {
sv = *v
}
for key, value := range shape {
switch key {
case "account_id":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected AccountId to be of type string, got %T instead", value)
}
sv.AccountId = ptr.String(jtv)
}
case "active":
if value != nil {
jtv, ok := value.(bool)
if !ok {
return fmt.Errorf("expected Boolean to be of type *bool, got %T instead", value)
}
sv.Active = ptr.Bool(jtv)
}
case "aud":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.Aud = ptr.String(jtv)
}
case "client_id":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.ClientId = ptr.String(jtv)
}
case "exp":
if value != nil {
jtv, ok := value.(json.Number)
if !ok {
return fmt.Errorf("expected Long to be json.Number, got %T instead", value)
}
i64, err := jtv.Int64()
if err != nil {
return err
}
sv.Exp = ptr.Int64(i64)
}
case "iat":
if value != nil {
jtv, ok := value.(json.Number)
if !ok {
return fmt.Errorf("expected Long to be json.Number, got %T instead", value)
}
i64, err := jtv.Int64()
if err != nil {
return err
}
sv.Iat = ptr.Int64(i64)
}
case "iss":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.Iss = ptr.String(jtv)
}
case "jti":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.Jti = ptr.String(jtv)
}
case "nbf":
if value != nil {
jtv, ok := value.(json.Number)
if !ok {
return fmt.Errorf("expected Long to be json.Number, got %T instead", value)
}
i64, err := jtv.Int64()
if err != nil {
return err
}
sv.Nbf = ptr.Int64(i64)
}
case "resource":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.Resource = ptr.String(jtv)
}
case "signin_session":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.SigninSession = ptr.String(jtv)
}
case "sub":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.Sub = ptr.String(jtv)
}
case "token_type":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected IntrospectedTokenType to be of type string, got %T instead", value)
}
sv.TokenType = ptr.String(jtv)
}
case "user_id":
if value != nil {
jtv, ok := value.(string)
if !ok {
return fmt.Errorf("expected String to be of type string, got %T instead", value)
}
sv.UserId = ptr.String(jtv)
}
default:
_, _ = key, value
}
}
*v = sv
return nil
}
type awsRestjson1_deserializeOpListResourcePermissionStatements struct {
}
@@ -1346,6 +1827,103 @@ func awsRestjson1_deserializeOpDocumentPutResourcePermissionStatementOutput(v **
return nil
}
type awsRestjson1_deserializeOpRevokeOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_deserializeOpRevokeOAuth2TokenWithIAM) ID() string {
return "OperationDeserializer"
}
func (m *awsRestjson1_deserializeOpRevokeOAuth2TokenWithIAM) HandleDeserialize(ctx context.Context, in middleware.DeserializeInput, next middleware.DeserializeHandler) (
out middleware.DeserializeOutput, metadata middleware.Metadata, err error,
) {
out, metadata, err = next.HandleDeserialize(ctx, in)
if err != nil {
return out, metadata, err
}
_, span := tracing.StartSpan(ctx, "OperationDeserializer")
endTimer := startMetricTimer(ctx, "client.call.deserialization_duration")
defer endTimer()
defer span.End()
response, ok := out.RawResponse.(*smithyhttp.Response)
if !ok {
return out, metadata, &smithy.DeserializationError{Err: fmt.Errorf("unknown transport type %T", out.RawResponse)}
}
if response.StatusCode < 200 || response.StatusCode >= 300 {
return out, metadata, awsRestjson1_deserializeOpErrorRevokeOAuth2TokenWithIAM(response, &metadata)
}
output := &RevokeOAuth2TokenWithIAMOutput{}
out.Result = output
span.End()
return out, metadata, err
}
func awsRestjson1_deserializeOpErrorRevokeOAuth2TokenWithIAM(response *smithyhttp.Response, metadata *middleware.Metadata) error {
var errorBuffer bytes.Buffer
if _, err := io.Copy(&errorBuffer, response.Body); err != nil {
return &smithy.DeserializationError{Err: fmt.Errorf("failed to copy error response body, %w", err)}
}
errorBody := bytes.NewReader(errorBuffer.Bytes())
errorCode := "UnknownError"
errorMessage := errorCode
headerCode := response.Header.Get("X-Amzn-ErrorType")
if len(headerCode) != 0 {
errorCode = restjson.SanitizeErrorCode(headerCode)
}
var buff [1024]byte
ringBuffer := smithyio.NewRingBuffer(buff[:])
body := io.TeeReader(errorBody, ringBuffer)
decoder := json.NewDecoder(body)
decoder.UseNumber()
jsonCode, message, err := restjson.GetErrorInfo(decoder)
if err != nil {
var snapshot bytes.Buffer
io.Copy(&snapshot, ringBuffer)
err = &smithy.DeserializationError{
Err: fmt.Errorf("failed to decode response body, %w", err),
Snapshot: snapshot.Bytes(),
}
return err
}
errorBody.Seek(0, io.SeekStart)
if len(headerCode) == 0 && len(jsonCode) != 0 {
errorCode = restjson.SanitizeErrorCode(jsonCode)
}
if len(message) != 0 {
errorMessage = message
}
switch {
case strings.EqualFold("AccessDeniedException", errorCode):
return awsRestjson1_deserializeErrorAccessDeniedException(response, errorBody)
case strings.EqualFold("InternalServerException", errorCode):
return awsRestjson1_deserializeErrorInternalServerException(response, errorBody)
case strings.EqualFold("TooManyRequestsError", errorCode):
return awsRestjson1_deserializeErrorTooManyRequestsError(response, errorBody)
case strings.EqualFold("ValidationException", errorCode):
return awsRestjson1_deserializeErrorValidationException(response, errorBody)
default:
genericError := &smithy.GenericAPIError{
Code: errorCode,
Message: errorMessage,
}
return genericError
}
}
func awsRestjson1_deserializeErrorAccessDeniedException(response *smithyhttp.Response, errorBody *bytes.Reader) error {
output := &types.AccessDeniedException{}
var buff [1024]byte
+92 -44
View File
@@ -276,6 +276,12 @@ type EndpointParameters struct {
// Parameter is
// required.
IsControlPlane *bool
// Indicates if the operation targets the OAuth token endpoint
//
// Parameter is
// required.
IsOAuthEndpoint *bool
}
// ValidateRequired validates required parameters are set.
@@ -306,8 +312,8 @@ func (p EndpointParameters) WithDefaults() EndpointParameters {
const bddRoot int32 = 2
var bddNodes = [99]int32{
-1, 1, -1, 0, 4, 3, 2, 30, 100000025, 1, 24, 5, 2, 30, 6, 3, 7, 26, 4, 18, 8, 5, 17, 9, 6, 100000004, 10, 7, 100000005, 11, 10, 100000006, 12, 12, 100000007, 13, 13, 100000008, 14, 14, 100000009, 15, 15, 100000010, 16, 16, 100000011, 100000014, 8, 100000022, 100000023, 5, 22, 19, 9, 100000012, 20, 10, 100000013, 21, 11, 100000020, 100000021, 8, 23, 100000019, 11, 100000018, 100000019, 2, 29, 25, 3, 32, 26, 4, 27, 100000025, 5, 100000025, 28, 9, 100000012, 100000025, 3, 32, 30, 4, 100000015, 31, 5, 100000016, 100000017, 6, 100000001, 33, 7, 100000002, 100000003}
var bddNodes = [120]int32{
-1, 1, -1, 0, 6, 3, 2, 36, 4, 4, 5, 100000027, 6, 100000004, 100000027, 1, 29, 7, 2, 36, 8, 3, 9, 31, 4, 22, 10, 5, 19, 11, 7, 21, 12, 8, 100000007, 13, 10, 100000008, 14, 12, 100000009, 15, 13, 100000010, 16, 14, 100000011, 17, 15, 100000012, 18, 16, 100000013, 100000016, 6, 100000005, 20, 7, 21, 100000006, 17, 100000024, 100000025, 6, 100000004, 23, 7, 27, 24, 9, 100000014, 25, 10, 100000015, 26, 11, 100000022, 100000023, 11, 28, 100000021, 17, 100000020, 100000021, 2, 35, 30, 3, 39, 31, 4, 32, 100000027, 6, 100000004, 33, 7, 100000027, 34, 9, 100000014, 100000027, 3, 39, 36, 4, 38, 37, 7, 100000018, 100000019, 6, 100000004, 100000017, 5, 100000001, 40, 8, 100000002, 100000003}
type conditionContext struct {
PartitionResult *awsrulesfn.PartitionConfig
@@ -335,13 +341,18 @@ func evalCondition(idx int, params *EndpointParameters, c *conditionContext) boo
case 4:
return *params.UseFIPS == true
case 5:
return *params.UseDualStack == true
case 6:
return c.PartitionResult.Name == "aws"
case 6:
return func() bool {
if v := params.IsOAuthEndpoint; v != nil {
return *v
}
return false
}() == true
case 7:
return c.PartitionResult.Name == "aws-cn"
return *params.UseDualStack == true
case 8:
return c.PartitionResult.SupportsDualStack == true
return c.PartitionResult.Name == "aws-cn"
case 9:
return *params.Region == "us-gov-west-1"
case 10:
@@ -358,6 +369,8 @@ func evalCondition(idx int, params *EndpointParameters, c *conditionContext) boo
return c.PartitionResult.Name == "aws-iso-e"
case 16:
return c.PartitionResult.Name == "aws-eusc"
case 17:
return c.PartitionResult.SupportsDualStack == true
}
return false
}
@@ -467,6 +480,41 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
}(),
}, nil
case 4:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "FIPS endpoints are not supported for OAuth operations. Disable FIPS or use a non-OAuth operation.")
case 5:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
out.WriteString(*params.Region)
out.WriteString(".oauth.signin.aws")
return out.String()
}()
uri, err := url.Parse(uriString)
if err != nil {
return smithyendpoints.Endpoint{}, fmt.Errorf("Failed to parse uri: %s", uriString)
}
return smithyendpoints.Endpoint{
URI: *uri,
Headers: http.Header{},
Properties: func() smithy.Properties {
var out smithy.Properties
smithyauth.SetAuthOptions(&out, []*smithyauth.Option{
{
SchemeID: "sigv4",
SignerProperties: func() smithy.Properties {
var sp smithy.Properties
smithyhttp.SetSigV4SigningName(&sp, "signin")
smithyhttp.SetSigV4ASigningName(&sp, "signin")
smithyhttp.SetSigV4SigningRegion(&sp, *params.Region)
return sp
}(),
},
})
return out
}(),
}, nil
case 6:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -482,7 +530,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 5:
case 7:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -498,7 +546,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 6:
case 8:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -514,7 +562,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 7:
case 9:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -530,7 +578,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 8:
case 10:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -546,7 +594,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 9:
case 11:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -562,7 +610,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 10:
case 12:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -578,7 +626,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 11:
case 13:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -594,7 +642,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 12:
case 14:
uriString := "https://signin-fips.amazonaws-us-gov.com"
uri, err := url.Parse(uriString)
if err != nil {
@@ -604,7 +652,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 13:
case 15:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -620,7 +668,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 14:
case 16:
uriString := func() string {
var out strings.Builder
out.WriteString("https://")
@@ -637,11 +685,11 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 15:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "Invalid Configuration: FIPS and custom endpoint are not supported")
case 16:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "Invalid Configuration: Dualstack and custom endpoint are not supported")
case 17:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "Invalid Configuration: FIPS and custom endpoint are not supported")
case 18:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "Invalid Configuration: Dualstack and custom endpoint are not supported")
case 19:
uriString := *params.Endpoint
uri, err := url.Parse(uriString)
if err != nil {
@@ -651,32 +699,13 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 18:
uriString := func() string {
var out strings.Builder
out.WriteString("https://signin-fips.")
out.WriteString(*params.Region)
out.WriteString(".")
out.WriteString(c.PartitionResult.DualStackDnsSuffix)
return out.String()
}()
uri, err := url.Parse(uriString)
if err != nil {
return smithyendpoints.Endpoint{}, fmt.Errorf("Failed to parse uri: %s", uriString)
}
return smithyendpoints.Endpoint{
URI: *uri,
Headers: http.Header{},
}, nil
case 19:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "FIPS and DualStack are enabled, but this partition does not support one or both")
case 20:
uriString := func() string {
var out strings.Builder
out.WriteString("https://signin-fips.")
out.WriteString(*params.Region)
out.WriteString(".")
out.WriteString(c.PartitionResult.DnsSuffix)
out.WriteString(c.PartitionResult.DualStackDnsSuffix)
return out.String()
}()
uri, err := url.Parse(uriString)
@@ -688,8 +717,27 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
Headers: http.Header{},
}, nil
case 21:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "FIPS is enabled but this partition does not support FIPS")
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "FIPS and DualStack are enabled, but this partition does not support one or both")
case 22:
uriString := func() string {
var out strings.Builder
out.WriteString("https://signin-fips.")
out.WriteString(*params.Region)
out.WriteString(".")
out.WriteString(c.PartitionResult.DnsSuffix)
return out.String()
}()
uri, err := url.Parse(uriString)
if err != nil {
return smithyendpoints.Endpoint{}, fmt.Errorf("Failed to parse uri: %s", uriString)
}
return smithyendpoints.Endpoint{
URI: *uri,
Headers: http.Header{},
}, nil
case 23:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "FIPS is enabled but this partition does not support FIPS")
case 24:
uriString := func() string {
var out strings.Builder
out.WriteString("https://signin.")
@@ -706,9 +754,9 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 23:
case 25:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "DualStack is enabled but this partition does not support DualStack")
case 24:
case 26:
uriString := func() string {
var out strings.Builder
out.WriteString("https://signin.")
@@ -725,7 +773,7 @@ func resolveResult(idx int32, params *EndpointParameters, c *conditionContext) (
URI: *uri,
Headers: http.Header{},
}, nil
case 25:
case 27:
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, %s", "Invalid Configuration: Missing Region")
}
return smithyendpoints.Endpoint{}, fmt.Errorf("endpoint rule error, invalid result index: %d", idx)
+3
View File
@@ -9,13 +9,16 @@
"api_client.go",
"api_client_test.go",
"api_op_CreateOAuth2Token.go",
"api_op_CreateOAuth2TokenWithIAM.go",
"api_op_DeleteConsoleAuthorizationConfiguration.go",
"api_op_DeleteResourcePermissionStatement.go",
"api_op_GetConsoleAuthorizationConfiguration.go",
"api_op_GetResourcePolicy.go",
"api_op_IntrospectOAuth2TokenWithIAM.go",
"api_op_ListResourcePermissionStatements.go",
"api_op_PutConsoleAuthorizationConfiguration.go",
"api_op_PutResourcePermissionStatement.go",
"api_op_RevokeOAuth2TokenWithIAM.go",
"auth.go",
"deserializers.go",
"doc.go",
+1 -1
View File
@@ -3,4 +3,4 @@
package signin
// goModuleVersion is the tagged release for this module
const goModuleVersion = "1.3.0"
const goModuleVersion = "1.4.0"
+253
View File
@@ -97,6 +97,92 @@ func awsRestjson1_serializeOpHttpBindingsCreateOAuth2TokenInput(v *CreateOAuth2T
return nil
}
type awsRestjson1_serializeOpCreateOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_serializeOpCreateOAuth2TokenWithIAM) ID() string {
return "OperationSerializer"
}
func (m *awsRestjson1_serializeOpCreateOAuth2TokenWithIAM) HandleSerialize(ctx context.Context, in middleware.SerializeInput, next middleware.SerializeHandler) (
out middleware.SerializeOutput, metadata middleware.Metadata, err error,
) {
_, span := tracing.StartSpan(ctx, "OperationSerializer")
endTimer := startMetricTimer(ctx, "client.call.serialization_duration")
defer endTimer()
defer span.End()
request, ok := in.Request.(*smithyhttp.Request)
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown transport type %T", in.Request)}
}
input, ok := in.Parameters.(*CreateOAuth2TokenWithIAMInput)
_ = input
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown input parameters type %T", in.Parameters)}
}
opPath, opQuery := httpbinding.SplitURI("/v1/token?x-amz-client-auth-method=iam")
request.URL.Path = smithyhttp.JoinPath(request.URL.Path, opPath)
request.URL.RawQuery = smithyhttp.JoinRawQuery(request.URL.RawQuery, opQuery)
request.Method = "POST"
var restEncoder *httpbinding.Encoder
if request.URL.RawPath == "" {
restEncoder, err = httpbinding.NewEncoder(request.URL.Path, request.URL.RawQuery, request.Header)
} else {
request.URL.RawPath = smithyhttp.JoinPath(request.URL.RawPath, opPath)
restEncoder, err = httpbinding.NewEncoderWithRawPath(request.URL.Path, request.URL.RawPath, request.URL.RawQuery, request.Header)
}
if err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
restEncoder.SetHeader("Content-Type").String("application/json")
jsonEncoder := smithyjson.NewEncoder()
if err := awsRestjson1_serializeOpDocumentCreateOAuth2TokenWithIAMInput(input, jsonEncoder.Value); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request, err = request.SetStream(bytes.NewReader(jsonEncoder.Bytes())); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request.Request, err = restEncoder.Encode(request.Request); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
in.Request = request
endTimer()
span.End()
return next.HandleSerialize(ctx, in)
}
func awsRestjson1_serializeOpHttpBindingsCreateOAuth2TokenWithIAMInput(v *CreateOAuth2TokenWithIAMInput, encoder *httpbinding.Encoder) error {
if v == nil {
return fmt.Errorf("unsupported serialization of nil %T", v)
}
return nil
}
func awsRestjson1_serializeOpDocumentCreateOAuth2TokenWithIAMInput(v *CreateOAuth2TokenWithIAMInput, value smithyjson.Value) error {
object := value.Object()
defer object.Close()
if v.GrantType != nil {
ok := object.Key("grant_type")
ok.String(*v.GrantType)
}
if v.Resource != nil {
ok := object.Key("resource")
ok.String(*v.Resource)
}
return nil
}
type awsRestjson1_serializeOpDeleteConsoleAuthorizationConfiguration struct {
}
@@ -403,6 +489,92 @@ func awsRestjson1_serializeOpHttpBindingsGetResourcePolicyInput(v *GetResourcePo
return nil
}
type awsRestjson1_serializeOpIntrospectOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_serializeOpIntrospectOAuth2TokenWithIAM) ID() string {
return "OperationSerializer"
}
func (m *awsRestjson1_serializeOpIntrospectOAuth2TokenWithIAM) HandleSerialize(ctx context.Context, in middleware.SerializeInput, next middleware.SerializeHandler) (
out middleware.SerializeOutput, metadata middleware.Metadata, err error,
) {
_, span := tracing.StartSpan(ctx, "OperationSerializer")
endTimer := startMetricTimer(ctx, "client.call.serialization_duration")
defer endTimer()
defer span.End()
request, ok := in.Request.(*smithyhttp.Request)
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown transport type %T", in.Request)}
}
input, ok := in.Parameters.(*IntrospectOAuth2TokenWithIAMInput)
_ = input
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown input parameters type %T", in.Parameters)}
}
opPath, opQuery := httpbinding.SplitURI("/v1/introspect?x-amz-client-auth-method=iam")
request.URL.Path = smithyhttp.JoinPath(request.URL.Path, opPath)
request.URL.RawQuery = smithyhttp.JoinRawQuery(request.URL.RawQuery, opQuery)
request.Method = "POST"
var restEncoder *httpbinding.Encoder
if request.URL.RawPath == "" {
restEncoder, err = httpbinding.NewEncoder(request.URL.Path, request.URL.RawQuery, request.Header)
} else {
request.URL.RawPath = smithyhttp.JoinPath(request.URL.RawPath, opPath)
restEncoder, err = httpbinding.NewEncoderWithRawPath(request.URL.Path, request.URL.RawPath, request.URL.RawQuery, request.Header)
}
if err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
restEncoder.SetHeader("Content-Type").String("application/json")
jsonEncoder := smithyjson.NewEncoder()
if err := awsRestjson1_serializeOpDocumentIntrospectOAuth2TokenWithIAMInput(input, jsonEncoder.Value); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request, err = request.SetStream(bytes.NewReader(jsonEncoder.Bytes())); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request.Request, err = restEncoder.Encode(request.Request); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
in.Request = request
endTimer()
span.End()
return next.HandleSerialize(ctx, in)
}
func awsRestjson1_serializeOpHttpBindingsIntrospectOAuth2TokenWithIAMInput(v *IntrospectOAuth2TokenWithIAMInput, encoder *httpbinding.Encoder) error {
if v == nil {
return fmt.Errorf("unsupported serialization of nil %T", v)
}
return nil
}
func awsRestjson1_serializeOpDocumentIntrospectOAuth2TokenWithIAMInput(v *IntrospectOAuth2TokenWithIAMInput, value smithyjson.Value) error {
object := value.Object()
defer object.Close()
if v.Token != nil {
ok := object.Key("token")
ok.String(*v.Token)
}
if v.TokenTypeHint != nil {
ok := object.Key("token_type_hint")
ok.String(*v.TokenTypeHint)
}
return nil
}
type awsRestjson1_serializeOpListResourcePermissionStatements struct {
}
@@ -686,6 +858,87 @@ func awsRestjson1_serializeOpDocumentPutResourcePermissionStatementInput(v *PutR
return nil
}
type awsRestjson1_serializeOpRevokeOAuth2TokenWithIAM struct {
}
func (*awsRestjson1_serializeOpRevokeOAuth2TokenWithIAM) ID() string {
return "OperationSerializer"
}
func (m *awsRestjson1_serializeOpRevokeOAuth2TokenWithIAM) HandleSerialize(ctx context.Context, in middleware.SerializeInput, next middleware.SerializeHandler) (
out middleware.SerializeOutput, metadata middleware.Metadata, err error,
) {
_, span := tracing.StartSpan(ctx, "OperationSerializer")
endTimer := startMetricTimer(ctx, "client.call.serialization_duration")
defer endTimer()
defer span.End()
request, ok := in.Request.(*smithyhttp.Request)
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown transport type %T", in.Request)}
}
input, ok := in.Parameters.(*RevokeOAuth2TokenWithIAMInput)
_ = input
if !ok {
return out, metadata, &smithy.SerializationError{Err: fmt.Errorf("unknown input parameters type %T", in.Parameters)}
}
opPath, opQuery := httpbinding.SplitURI("/v1/revoke?x-amz-client-auth-method=iam")
request.URL.Path = smithyhttp.JoinPath(request.URL.Path, opPath)
request.URL.RawQuery = smithyhttp.JoinRawQuery(request.URL.RawQuery, opQuery)
request.Method = "POST"
var restEncoder *httpbinding.Encoder
if request.URL.RawPath == "" {
restEncoder, err = httpbinding.NewEncoder(request.URL.Path, request.URL.RawQuery, request.Header)
} else {
request.URL.RawPath = smithyhttp.JoinPath(request.URL.RawPath, opPath)
restEncoder, err = httpbinding.NewEncoderWithRawPath(request.URL.Path, request.URL.RawPath, request.URL.RawQuery, request.Header)
}
if err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
restEncoder.SetHeader("Content-Type").String("application/json")
jsonEncoder := smithyjson.NewEncoder()
if err := awsRestjson1_serializeOpDocumentRevokeOAuth2TokenWithIAMInput(input, jsonEncoder.Value); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request, err = request.SetStream(bytes.NewReader(jsonEncoder.Bytes())); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
if request.Request, err = restEncoder.Encode(request.Request); err != nil {
return out, metadata, &smithy.SerializationError{Err: err}
}
in.Request = request
endTimer()
span.End()
return next.HandleSerialize(ctx, in)
}
func awsRestjson1_serializeOpHttpBindingsRevokeOAuth2TokenWithIAMInput(v *RevokeOAuth2TokenWithIAMInput, encoder *httpbinding.Encoder) error {
if v == nil {
return fmt.Errorf("unsupported serialization of nil %T", v)
}
return nil
}
func awsRestjson1_serializeOpDocumentRevokeOAuth2TokenWithIAMInput(v *RevokeOAuth2TokenWithIAMInput, value smithyjson.Value) error {
object := value.Object()
defer object.Close()
if v.Token != nil {
ok := object.Key("token")
ok.String(*v.Token)
}
return nil
}
func awsRestjson1_serializeDocumentCreateOAuth2TokenRequestBody(v *types.CreateOAuth2TokenRequestBody, value smithyjson.Value) error {
object := value.Object()
defer object.Close()
+1 -3
View File
@@ -8,9 +8,7 @@ import (
// AWS credentials structure containing temporary access credentials
//
// The scoped-down, 15 minute duration AWS credentials. Scoping down will be based
// on CLI policy (CLI team needs to create it). Similar to cloud shell
// implementation.
// Scoped, temporary AWS credentials with a 15-minute duration.
type AccessToken struct {
// AWS access key ID for temporary credentials
+120
View File
@@ -30,6 +30,26 @@ func (m *validateOpCreateOAuth2Token) HandleInitialize(ctx context.Context, in m
return next.HandleInitialize(ctx, in)
}
type validateOpCreateOAuth2TokenWithIAM struct {
}
func (*validateOpCreateOAuth2TokenWithIAM) ID() string {
return "OperationInputValidation"
}
func (m *validateOpCreateOAuth2TokenWithIAM) HandleInitialize(ctx context.Context, in middleware.InitializeInput, next middleware.InitializeHandler) (
out middleware.InitializeOutput, metadata middleware.Metadata, err error,
) {
input, ok := in.Parameters.(*CreateOAuth2TokenWithIAMInput)
if !ok {
return out, metadata, fmt.Errorf("unknown input parameters type %T", in.Parameters)
}
if err := validateOpCreateOAuth2TokenWithIAMInput(input); err != nil {
return out, metadata, err
}
return next.HandleInitialize(ctx, in)
}
type validateOpDeleteResourcePermissionStatement struct {
}
@@ -50,14 +70,66 @@ func (m *validateOpDeleteResourcePermissionStatement) HandleInitialize(ctx conte
return next.HandleInitialize(ctx, in)
}
type validateOpIntrospectOAuth2TokenWithIAM struct {
}
func (*validateOpIntrospectOAuth2TokenWithIAM) ID() string {
return "OperationInputValidation"
}
func (m *validateOpIntrospectOAuth2TokenWithIAM) HandleInitialize(ctx context.Context, in middleware.InitializeInput, next middleware.InitializeHandler) (
out middleware.InitializeOutput, metadata middleware.Metadata, err error,
) {
input, ok := in.Parameters.(*IntrospectOAuth2TokenWithIAMInput)
if !ok {
return out, metadata, fmt.Errorf("unknown input parameters type %T", in.Parameters)
}
if err := validateOpIntrospectOAuth2TokenWithIAMInput(input); err != nil {
return out, metadata, err
}
return next.HandleInitialize(ctx, in)
}
type validateOpRevokeOAuth2TokenWithIAM struct {
}
func (*validateOpRevokeOAuth2TokenWithIAM) ID() string {
return "OperationInputValidation"
}
func (m *validateOpRevokeOAuth2TokenWithIAM) HandleInitialize(ctx context.Context, in middleware.InitializeInput, next middleware.InitializeHandler) (
out middleware.InitializeOutput, metadata middleware.Metadata, err error,
) {
input, ok := in.Parameters.(*RevokeOAuth2TokenWithIAMInput)
if !ok {
return out, metadata, fmt.Errorf("unknown input parameters type %T", in.Parameters)
}
if err := validateOpRevokeOAuth2TokenWithIAMInput(input); err != nil {
return out, metadata, err
}
return next.HandleInitialize(ctx, in)
}
func addOpCreateOAuth2TokenValidationMiddleware(stack *middleware.Stack) error {
return stack.Initialize.Add(&validateOpCreateOAuth2Token{}, middleware.After)
}
func addOpCreateOAuth2TokenWithIAMValidationMiddleware(stack *middleware.Stack) error {
return stack.Initialize.Add(&validateOpCreateOAuth2TokenWithIAM{}, middleware.After)
}
func addOpDeleteResourcePermissionStatementValidationMiddleware(stack *middleware.Stack) error {
return stack.Initialize.Add(&validateOpDeleteResourcePermissionStatement{}, middleware.After)
}
func addOpIntrospectOAuth2TokenWithIAMValidationMiddleware(stack *middleware.Stack) error {
return stack.Initialize.Add(&validateOpIntrospectOAuth2TokenWithIAM{}, middleware.After)
}
func addOpRevokeOAuth2TokenWithIAMValidationMiddleware(stack *middleware.Stack) error {
return stack.Initialize.Add(&validateOpRevokeOAuth2TokenWithIAM{}, middleware.After)
}
func validateCreateOAuth2TokenRequestBody(v *types.CreateOAuth2TokenRequestBody) error {
if v == nil {
return nil
@@ -95,6 +167,24 @@ func validateOpCreateOAuth2TokenInput(v *CreateOAuth2TokenInput) error {
}
}
func validateOpCreateOAuth2TokenWithIAMInput(v *CreateOAuth2TokenWithIAMInput) error {
if v == nil {
return nil
}
invalidParams := smithy.InvalidParamsError{Context: "CreateOAuth2TokenWithIAMInput"}
if v.GrantType == nil {
invalidParams.Add(smithy.NewErrParamRequired("GrantType"))
}
if v.Resource == nil {
invalidParams.Add(smithy.NewErrParamRequired("Resource"))
}
if invalidParams.Len() > 0 {
return invalidParams
} else {
return nil
}
}
func validateOpDeleteResourcePermissionStatementInput(v *DeleteResourcePermissionStatementInput) error {
if v == nil {
return nil
@@ -109,3 +199,33 @@ func validateOpDeleteResourcePermissionStatementInput(v *DeleteResourcePermissio
return nil
}
}
func validateOpIntrospectOAuth2TokenWithIAMInput(v *IntrospectOAuth2TokenWithIAMInput) error {
if v == nil {
return nil
}
invalidParams := smithy.InvalidParamsError{Context: "IntrospectOAuth2TokenWithIAMInput"}
if v.Token == nil {
invalidParams.Add(smithy.NewErrParamRequired("Token"))
}
if invalidParams.Len() > 0 {
return invalidParams
} else {
return nil
}
}
func validateOpRevokeOAuth2TokenWithIAMInput(v *RevokeOAuth2TokenWithIAMInput) error {
if v == nil {
return nil
}
invalidParams := smithy.InvalidParamsError{Context: "RevokeOAuth2TokenWithIAMInput"}
if v.Token == nil {
invalidParams.Add(smithy.NewErrParamRequired("Token"))
}
if invalidParams.Len() > 0 {
return invalidParams
} else {
return nil
}
}
+3 -3
View File
@@ -92,11 +92,11 @@ github.com/aws/aws-sdk-go-v2/internal/shareddefaults
github.com/aws/aws-sdk-go-v2/internal/strings
github.com/aws/aws-sdk-go-v2/internal/sync/singleflight
github.com/aws/aws-sdk-go-v2/internal/timeconv
# github.com/aws/aws-sdk-go-v2/config v1.32.28
# github.com/aws/aws-sdk-go-v2/config v1.32.29
## explicit; go 1.24
github.com/aws/aws-sdk-go-v2/config
github.com/aws/aws-sdk-go-v2/config/internal/ini
# github.com/aws/aws-sdk-go-v2/credentials v1.19.27
# github.com/aws/aws-sdk-go-v2/credentials v1.19.28
## explicit; go 1.24
github.com/aws/aws-sdk-go-v2/credentials
github.com/aws/aws-sdk-go-v2/credentials/ec2rolecreds
@@ -137,7 +137,7 @@ github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
# github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.30
## explicit; go 1.24
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
# github.com/aws/aws-sdk-go-v2/service/signin v1.3.0
# github.com/aws/aws-sdk-go-v2/service/signin v1.4.0
## explicit; go 1.24
github.com/aws/aws-sdk-go-v2/service/signin
github.com/aws/aws-sdk-go-v2/service/signin/internal/endpoints