Coverage Report

Created: 2026-09-28 17:01

next uncovered line (L), next uncovered region (R), next uncovered branch (B)
common/cpp/obj-client/auth/aws_credential_factory.cpp
Line
Count
Source
1
// Licensed to the Apache Software Foundation (ASF) under one
2
// or more contributor license agreements.  See the NOTICE file
3
// distributed with this work for additional information
4
// regarding copyright ownership.  The ASF licenses this file
5
// to you under the Apache License, Version 2.0 (the
6
// "License"); you may not use this file except in compliance
7
// with the License.  You may obtain a copy of the License at
8
//
9
//   http://www.apache.org/licenses/LICENSE-2.0
10
//
11
// Unless required by applicable law or agreed to in writing,
12
// software distributed under the License is distributed on an
13
// "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
14
// KIND, either express or implied.  See the License for the
15
// specific language governing permissions and limitations
16
// under the License.
17
18
#include "aws_credential_factory.h"
19
20
#include <aws/core/auth/AWSCredentials.h>
21
#include <aws/core/auth/AWSCredentialsProvider.h>
22
#include <aws/core/auth/AWSCredentialsProviderChain.h>
23
#include <aws/core/auth/STSCredentialsProvider.h>
24
#include <aws/identity-management/auth/STSAssumeRoleCredentialsProvider.h>
25
#include <aws/sts/STSClient.h>
26
27
#include "cpp/custom_aws_credentials_provider_chain.h"
28
29
namespace doris {
30
namespace {
31
32
using Provider = Aws::Auth::AWSCredentialsProvider;
33
34
58
std::shared_ptr<Provider> create_v2_base_provider(CredProviderType type) {
35
58
    switch (type) {
36
4
    case CredProviderType::Env:
37
4
        return std::make_shared<Aws::Auth::EnvironmentAWSCredentialsProvider>();
38
4
    case CredProviderType::SystemProperties:
39
4
        return std::make_shared<Aws::Auth::ProfileConfigFileAWSCredentialsProvider>();
40
6
    case CredProviderType::WebIdentity:
41
6
        return std::make_shared<Aws::Auth::STSAssumeRoleWebIdentityCredentialsProvider>();
42
14
    case CredProviderType::Container:
43
14
        return create_container_credentials_provider();
44
8
    case CredProviderType::Anonymous:
45
8
        return std::make_shared<Aws::Auth::AnonymousAWSCredentialsProvider>();
46
6
    case CredProviderType::Default:
47
10
    case CredProviderType::Simple:
48
10
        return std::make_shared<CustomAwsCredentialsProviderChain>();
49
12
    case CredProviderType::InstanceProfile:
50
12
        return std::make_shared<Aws::Auth::InstanceProfileCredentialsProvider>();
51
58
    }
52
0
    __builtin_unreachable();
53
58
}
54
55
AwsCredentialResult assume_role(const AwsCredentialOptions& options,
56
24
                                std::shared_ptr<Provider> base_provider) {
57
24
    auto sts_client =
58
24
            std::make_shared<Aws::STS::STSClient>(base_provider, options.sts_client_config);
59
24
    return {
60
24
            .provider = std::make_shared<Aws::Auth::STSAssumeRoleCredentialsProvider>(
61
24
                    options.role_arn, Aws::String(), options.external_id,
62
24
                    Aws::Auth::DEFAULT_CREDS_LOAD_FREQ_SECONDS, std::move(sts_client)),
63
24
    };
64
24
}
65
66
} // namespace
67
68
82
AwsCredentialResult AwsCredentialFactory::create(const AwsCredentialOptions& options) {
69
82
    const bool has_access_key = !options.access_key.empty();
70
82
    const bool has_secret_key = !options.secret_key.empty();
71
72
82
    if (has_access_key && has_secret_key) {
73
12
        Aws::Auth::AWSCredentials credentials(options.access_key, options.secret_key);
74
12
        if (!options.session_token.empty()) {
75
0
            credentials.SetSessionToken(options.session_token);
76
0
        }
77
12
        return {
78
12
                .provider = std::make_shared<Aws::Auth::SimpleAWSCredentialsProvider>(
79
12
                        std::move(credentials)),
80
12
        };
81
12
    }
82
83
70
    if (options.version == AwsCredentialProviderVersion::V1) {
84
12
        if (options.provider_type == CredProviderType::InstanceProfile) {
85
4
            auto base = std::make_shared<Aws::Auth::InstanceProfileCredentialsProvider>();
86
4
            return options.role_arn.empty() ? AwsCredentialResult {.provider = std::move(base)}
87
4
                                            : assume_role(options, std::move(base));
88
4
        }
89
8
        if (!has_access_key && !has_secret_key &&
90
8
            options.empty_credentials == EmptyCredentialsBehavior::ANONYMOUS) {
91
4
            return {
92
4
                    .provider = std::make_shared<Aws::Auth::AnonymousAWSCredentialsProvider>(),
93
4
            };
94
4
        }
95
4
        return {
96
4
                .provider = std::make_shared<Aws::Auth::DefaultAWSCredentialsProviderChain>(),
97
4
        };
98
8
    }
99
100
58
    auto base = create_v2_base_provider(options.provider_type);
101
58
    return options.role_arn.empty() ? AwsCredentialResult {.provider = std::move(base)}
102
58
                                    : assume_role(options, std::move(base));
103
70
}
104
105
} // namespace doris