Documentation
¶
Overview ¶
Package aws provides a verifier for AWS Access Key credentials. It uses AWS STS GetCallerIdentity to check whether a key pair is active.
Index ¶
- type Verifier
- func (v *Verifier) Type() string
- func (v *Verifier) VerificationRequestBudget() int
- func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
- func (v *Verifier) VerifyWithRequestGate(ctx context.Context, raw detector.RawFinding, gate verifier.RequestGate) finding.VerificationResult
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
This section is empty.
Types ¶
type Verifier ¶
type Verifier struct {
// contains filtered or unexported fields
}
Verifier checks whether an AWS access key pair is active by calling STS GetCallerIdentity. It NEVER logs or persists raw key values.
func (*Verifier) VerificationRequestBudget ¶ added in v1.8.0
VerificationRequestBudget declares the single STS probe this verifier can issue for a complete key pair.
func (*Verifier) Verify ¶
func (v *Verifier) Verify(ctx context.Context, raw detector.RawFinding) finding.VerificationResult
Verify checks if the detected AWS access key is valid/active. Raw contains the Access Key ID and RawV2 contains the Secret Access Key. Both are required for verification.
func (*Verifier) VerifyWithRequestGate ¶ added in v1.8.0
func (v *Verifier) VerifyWithRequestGate( ctx context.Context, raw detector.RawFinding, gate verifier.RequestGate, ) finding.VerificationResult
VerifyWithRequestGate admits the STS request at its actual SDK send point.
Click to show internal directories.
Click to hide internal directories.