3
0

AWSDefaultCredentialHandler.cpp 6.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157
  1. /*
  2. * Copyright (c) Contributors to the Open 3D Engine Project.
  3. * For complete copyright and license terms please see the LICENSE at the root of this distribution.
  4. *
  5. * SPDX-License-Identifier: Apache-2.0 OR MIT
  6. *
  7. */
  8. #include <Configuration/AWSCoreConfiguration.h>
  9. #include <Credential/AWSDefaultCredentialHandler.h>
  10. #include <aws/core/platform/Environment.h>
  11. #include <aws/core/utils/StringUtils.h>
  12. namespace AWSCore
  13. {
  14. static constexpr char AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG[] = "AWSDefaultCredentialHandler";
  15. static constexpr char AWS_EC2_METADATA_DISABLED[] = "AWS_EC2_METADATA_DISABLED";
  16. AWSDefaultCredentialHandler::AWSDefaultCredentialHandler()
  17. : m_profileName("")
  18. {
  19. }
  20. void AWSDefaultCredentialHandler::ActivateHandler()
  21. {
  22. InitCredentialsProviders();
  23. AWSCredentialRequestBus::Handler::BusConnect();
  24. }
  25. void AWSDefaultCredentialHandler::DeactivateHandler()
  26. {
  27. AWSCredentialRequestBus::Handler::BusDisconnect();
  28. ResetCredentialsProviders();
  29. }
  30. int AWSDefaultCredentialHandler::GetCredentialHandlerOrder() const
  31. {
  32. return CredentialHandlerOrder::DEFAULT_CREDENTIAL_HANDLER;
  33. }
  34. std::shared_ptr<Aws::Auth::AWSCredentialsProvider> AWSDefaultCredentialHandler::GetCredentialsProvider()
  35. {
  36. {
  37. AZStd::lock_guard<AZStd::mutex> credentialsLock{m_credentialMutex};
  38. auto credentials = m_environmentCredentialsProvider->GetAWSCredentials();
  39. if (!credentials.IsEmpty())
  40. {
  41. return m_environmentCredentialsProvider;
  42. }
  43. }
  44. {
  45. AZStd::lock_guard<AZStd::mutex> credentialsLock{m_credentialMutex};
  46. AZStd::string newProfileName = "";
  47. AWSCoreInternalRequestBus::BroadcastResult(newProfileName, &AWSCoreInternalRequests::GetProfileName);
  48. if (newProfileName != m_profileName)
  49. {
  50. m_profileName = newProfileName;
  51. SetProfileCredentialsProvider(Aws::MakeShared<Aws::Auth::ProfileConfigFileAWSCredentialsProvider>(
  52. AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG, m_profileName.c_str()));
  53. }
  54. auto credentials = m_profileCredentialsProvider->GetAWSCredentials();
  55. if (!credentials.IsEmpty())
  56. {
  57. return m_profileCredentialsProvider;
  58. }
  59. }
  60. {
  61. AZStd::lock_guard<AZStd::mutex> credentialsLock{ m_credentialMutex };
  62. bool allowAWSMetadata = false;
  63. AWSCoreInternalRequestBus::BroadcastResult(allowAWSMetadata, &AWSCoreInternalRequests::IsAllowedAWSMetadataCredentials);
  64. if (allowAWSMetadata)
  65. {
  66. const auto ec2MetadataDisabled = Aws::Environment::GetEnv(AWS_EC2_METADATA_DISABLED);
  67. if (Aws::Utils::StringUtils::ToLower(ec2MetadataDisabled.c_str()) != "true")
  68. {
  69. if (!m_instanceProfileCredentialsProvider)
  70. {
  71. SetInstanceProfileCredentialProvider(
  72. Aws::MakeShared<Aws::Auth::InstanceProfileCredentialsProvider>(AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG));
  73. }
  74. auto credentials = m_instanceProfileCredentialsProvider->GetAWSCredentials();
  75. if (!credentials.IsEmpty())
  76. {
  77. return m_instanceProfileCredentialsProvider;
  78. }
  79. }
  80. }
  81. }
  82. return nullptr;
  83. }
  84. void AWSDefaultCredentialHandler::InitCredentialsProviders()
  85. {
  86. // Must init credential provider after AWSNativeSDKs init
  87. AZStd::lock_guard<AZStd::mutex> credentialsLock{m_credentialMutex};
  88. SetEnvironmentCredentialsProvider(Aws::MakeShared<Aws::Auth::EnvironmentAWSCredentialsProvider>(
  89. AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG));
  90. AZStd::string profileName = "";
  91. AWSCoreInternalRequestBus::BroadcastResult(profileName, &AWSCoreInternalRequests::GetProfileName);
  92. if (profileName.empty())
  93. {
  94. AZ_Warning("AWSDefaultCredentialHandler", false, "Failed to get profile name, use default profile name instead");
  95. SetProfileCredentialsProvider(Aws::MakeShared<Aws::Auth::ProfileConfigFileAWSCredentialsProvider>(
  96. AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG, AWSCoreConfiguration::AWSCoreDefaultProfileName));
  97. }
  98. else
  99. {
  100. m_profileName = profileName;
  101. SetProfileCredentialsProvider(Aws::MakeShared<Aws::Auth::ProfileConfigFileAWSCredentialsProvider>(
  102. AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG, m_profileName.c_str()));
  103. }
  104. bool allowAWSMetadata = false;
  105. AWSCoreInternalRequestBus::BroadcastResult(allowAWSMetadata, &AWSCoreInternalRequests::IsAllowedAWSMetadataCredentials);
  106. if (allowAWSMetadata)
  107. {
  108. SetInstanceProfileCredentialProvider(
  109. Aws::MakeShared<Aws::Auth::InstanceProfileCredentialsProvider>(AWSDEFAULTCREDENTIALHANDLER_ALLOC_TAG));
  110. }
  111. }
  112. void AWSDefaultCredentialHandler::SetEnvironmentCredentialsProvider(
  113. std::shared_ptr<Aws::Auth::EnvironmentAWSCredentialsProvider> credentialsProvider)
  114. {
  115. m_environmentCredentialsProvider = credentialsProvider;
  116. }
  117. void AWSDefaultCredentialHandler::SetProfileCredentialsProvider(
  118. std::shared_ptr<Aws::Auth::ProfileConfigFileAWSCredentialsProvider> credentialsProvider)
  119. {
  120. m_profileCredentialsProvider = credentialsProvider;
  121. }
  122. void AWSDefaultCredentialHandler::SetInstanceProfileCredentialProvider(
  123. std::shared_ptr<Aws::Auth::InstanceProfileCredentialsProvider> credentialsProvider)
  124. {
  125. m_instanceProfileCredentialsProvider = credentialsProvider;
  126. }
  127. void AWSDefaultCredentialHandler::ResetCredentialsProviders()
  128. {
  129. // Must reset credential provider before AWSNativeSDKs shutdown
  130. AZStd::lock_guard<AZStd::mutex> credentialsLock{m_credentialMutex};
  131. m_environmentCredentialsProvider.reset();
  132. m_profileCredentialsProvider.reset();
  133. if (m_instanceProfileCredentialsProvider)
  134. {
  135. m_instanceProfileCredentialsProvider.reset();
  136. }
  137. }
  138. } // namespace AWSCore