Documentation
¶
Overview ¶
Package aws holds what every AWS service client in this repository needs: SigV4 signing, credentials, environment resolution, and the HTTP client the build selects.
It exists because the maintained Go SDK does not build with TinyGo — aws-sdk-go-v2 reaches for the full net/http.Transport API through smithy-go, which TinyGo declares as an empty struct — so the services here speak their REST APIs directly. Signing is the part they share, and a second copy of it would be a second chance to break the rule that the signature must cover exactly what goes on the wire.
req, _ := http.NewRequest("POST", endpoint, body)
req.Header.Set("Content-Type", "application/x-amz-json-1.0")
aws.Sign(req, creds, aws.SignRequest{
Service: "dynamodb",
Region: "ap-northeast-1",
PayloadHash: aws.SHA256Hex(payload),
})
Credentials are static values or environment variables. There is no shared credentials file, no SSO, and no IMDS lookup.
The signer is usable for AWS services this repository has no client for: the request is an ordinary *http.Request, and Sign only reads and sets headers. Two rules matter when doing that. The service name in SignRequest enters both the credential scope and the signing key, so it must be the real one. And for any service with a path other than "/", set DoubleEncodePath: S3 is the exception the other services are not.
Index ¶
- Constants
- Variables
- func CanonicalQuery(params [][2]string) string
- func CloseIdleConnections(client *http.Client)
- func DisableRedirectFollowing(client *http.Client)
- func EndpointFromEnv(service string) string
- func NewHTTPClient(opts ClientOptions) *http.Client
- func RegionFromEnv() string
- func SHA256Hex(b []byte) string
- func Sign(req *http.Request, creds Credentials, sr SignRequest)
- func URIEncode(s string, encodeSlash bool) string
- type ClientOptions
- type Credentials
- type SignRequest
Constants ¶
const ( // EmptyPayloadHash is SHA-256 of no bytes, sent for bodyless requests. EmptyPayloadHash = "e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855" // UnsignedPayload signs a request without hashing the body, which is what // makes a non-rewindable stream uploadable. S3 accepts it; other services // do not, so it is not a general escape hatch. UnsignedPayload = "UNSIGNED-PAYLOAD" )
const Backend = cloudhttp.Backend
Backend identifies the HTTP stack selected by build constraints.
Variables ¶
var ( ErrNoCredentials = errors.New("aws: no credentials configured") ErrNoRegion = errors.New("aws: no region configured") )
Configuration failures shared by every service client. A rejected signature is a wire response and belongs to the service package that decoded it.
Functions ¶
func CanonicalQuery ¶
CanonicalQuery renders params sorted and escaped. A parameter with an empty value keeps its "=", which is what S3 subresources such as ?uploads expect.
func CloseIdleConnections ¶
CloseIdleConnections releases the pooled connections of client, if its transport keeps any. Both https.Transport and net/http.Transport do.
It exists because a service client should be closable without knowing which transport it was given, including one the caller supplied.
func DisableRedirectFollowing ¶
DisableRedirectFollowing stops http.Client from following redirects, so the caller sees them and can sign each hop for its new host.
This file covers every host-Go build, including -tags force_tinygo_logic: the TinyGo code path is exercised there through a standard http.Client, which would otherwise follow redirects that TinyGo's own client never follows.
func EndpointFromEnv ¶
EndpointFromEnv reads AWS_ENDPOINT_URL_<SERVICE>, then AWS_ENDPOINT_URL, which are the names the AWS CLI uses for pointing a client at a non-AWS endpoint. The service is spelled as in a SigV4 credential scope, so "s3" reads AWS_ENDPOINT_URL_S3 and "dynamodb" reads AWS_ENDPOINT_URL_DYNAMODB.
func NewHTTPClient ¶
func NewHTTPClient(opts ClientOptions) *http.Client
NewHTTPClient builds the default HTTP client for a service package. The idle-connection setting is forwarded to https.Transport on TinyGo builds and to net/http.Transport otherwise, so it means the same thing on both paths.
func RegionFromEnv ¶
func RegionFromEnv() string
RegionFromEnv reads AWS_REGION, then AWS_DEFAULT_REGION.
func SHA256Hex ¶
SHA256Hex returns the hex SHA-256 of b, which is the form a payload hash takes on the wire.
func Sign ¶
func Sign(req *http.Request, creds Credentials, sr SignRequest)
Sign adds x-amz-date, x-amz-content-sha256, the optional session token, and the Authorization header to req.
req.URL.RawPath and req.URL.RawQuery must already hold the encoded forms produced by URIEncode and CanonicalQuery: the canonical request is built from them, so signature and request line cannot drift apart.
Types ¶
type ClientOptions ¶
type ClientOptions = cloudhttp.ClientOptions
ClientOptions configures the HTTP client a service package uses when the caller supplies none.
type Credentials ¶
Credentials are the values SigV4 signs with. SessionToken is empty for long-lived keys.
func CredentialsFromEnv ¶
func CredentialsFromEnv() Credentials
CredentialsFromEnv reads AWS_ACCESS_KEY_ID, AWS_SECRET_ACCESS_KEY and AWS_SESSION_TOKEN. Missing variables yield a zero Credentials, which every client constructor rejects.
There is no shared credentials file, no SSO, and no metadata service: those need an INI parser, a browser flow, and a link-local HTTP call respectively, none of which belong in a client this size.
func (Credentials) Valid ¶
func (c Credentials) Valid() bool
Valid reports whether both required fields are present.
type SignRequest ¶
type SignRequest struct {
// Service is the name in the credential scope, "s3" or "dynamodb". It also
// enters the signing key, and the two must agree: a mismatch is a
// SignatureDoesNotMatch that no local test can catch, because both sides of
// a self-test would use the same wrong value.
Service string
// Region is the signing region, "ap-northeast-1".
Region string
// PayloadHash is the hex SHA-256 of the body, EmptyPayloadHash, or
// UnsignedPayload.
PayloadHash string
// DoubleEncodePath selects the canonicalization the SigV4 specification
// applies to every service except S3, which signs the path exactly as sent.
// A DynamoDB request posts to "/", where both rules agree, so this stays
// false there too; a new service with a real path must set it.
DoubleEncodePath bool
// Time is the signing time. The zero value means now.
Time time.Time
}
SignRequest is everything about a signature that is not the request or the credentials.