Documentation
¶
Overview ¶
Copyright © 2022 NAME HERE <EMAIL ADDRESS>
force.go 实现 --force 强制泛化调用。
正常模式下 CLI 仅允许 metadata 中已收录的 service/action;--force 跳过该校验, 直接通过 SDK 发起 RPC 请求,适用于未收录产品、新发布接口或需覆盖 API 版本的场景。
调用入口(维护时按此排查):
- cmd_root.Execute -> tryExecuteGenericInvoke:metadata 中不存在的 service
- cmd_service.runServiceCmd:已知 service、action 未匹配子命令时
- cmd_action action RunE:已知 action 子命令且带 --force(可覆盖 --version/--method)
共享调用前处理见 invocation.go;profile/endpoint 解析真相见 sdk_client.go (selectInvocationProfile / resolveClientEndpoint / hasEffectiveFixedEndpoint)。
系统参数:parser.go publicSystemFlags / localizedSystemFlagsHelp(对外双横线;三横线为冲突逃逸)。 双横线保留控制参数:reserved_dynamic.go(--header / --body)。 force 路径额外约定:
--force 纯开关,出现即启用(只放宽 service/action 元数据校验,不改变 endpoint 解析)
--version 未收录 service 时必填;已收录可回落元数据
--endpoint 与正常调用同一套解析(flag > resolver=standard > profile/env > 已收录 SDK 解析);
未收录需要最终生效的固定 host(standard / auto-addressing 不够)
--method 可选;未指定时优先元数据,否则 GET
--header 可重复 HTTP 头 Name=Value(Content-Type 可覆盖元数据;不进请求体)
--body JSON 请求体;与 flattened 业务参数互斥
invocation.go 存放正常路径与 force 路径共用的“调用前”处理: context 重置、参数解析、API 版本 / method 固定参数、call-style 解析、 service 级 action 分发。真正发 SDK 请求的 executeInvocation 仍在 cmd_action.go。
Index ¶
- Constants
- func Execute()
- func GetServiceMapping(s string) (string, bool)
- func SetServiceMapping(s1, s2 string)
- func WriteConfigToFile(config *Configure) error
- type AccountInfo
- type ApiDescription
- type ApiInfo
- type ApiMeta
- type Configure
- type ConsoleDeviceAuthorizationRequest
- type ConsoleDeviceAuthorizationResponse
- type ConsoleLogin
- type ConsoleLogout
- type ConsoleOAuthAPIError
- type ConsoleOAuthClient
- type ConsoleOAuthClientConfig
- type ConsoleOAuthErrorResponse
- type ConsoleTokenRequest
- type ConsoleTokenResponse
- type Context
- type CreateTokenRequest
- type CreateTokenResponse
- type DebugLogger
- type DeviceCodeFetcher
- type Flag
- type FlagSet
- type GetRoleCredentialsRequest
- type GetRoleCredentialsResponse
- type Language
- type ListAccountRolesRequest
- type ListAccountRolesResponse
- type ListAccountsRequest
- type ListAccountsResponse
- type LoginTokenCache
- type Meta
- type MetaInfo
- type MetaType
- type OAuthAPIError
- type OAuthClient
- func (c *OAuthClient) CreateToken(ctx context.Context, req *CreateTokenRequest) (*CreateTokenResponse, error)
- func (c *OAuthClient) RegisterClient(ctx context.Context, req *RegisterClientRequest) (*RegisterClientResponse, error)
- func (c *OAuthClient) RevokeToken(ctx context.Context, req *RevokeTokenRequest) error
- func (c *OAuthClient) StartDeviceAuthorization(ctx context.Context, req *StartDeviceAuthorizationRequest) (*StartDeviceAuthorizationResponse, error)
- type OAuthClientAPI
- type OAuthClientConfig
- type Parser
- type PortalAPIError
- type PortalClient
- func (c *PortalClient) GetRoleCredentials(ctx context.Context, req *GetRoleCredentialsRequest) (*GetRoleCredentialsResponse, error)
- func (c *PortalClient) ListAccountRoles(ctx context.Context, req *ListAccountRolesRequest) (*ListAccountRolesResponse, error)
- func (c *PortalClient) ListAccounts(ctx context.Context, req *ListAccountsRequest) (*ListAccountsResponse, error)
- type PortalClientAPI
- type PortalClientConfig
- type Profile
- type RegisterClientRequest
- type RegisterClientResponse
- type ResponseMetadata
- type RevokeTokenRequest
- type RoleCredentials
- type RoleInfo
- type RootSupport
- func (r *RootSupport) GetAllAction(svc string) []string
- func (r *RootSupport) GetAllSvc() []string
- func (r *RootSupport) GetAllSvcCompatible() []string
- func (r *RootSupport) GetApiInfo(svc string, action string) *ApiInfo
- func (r *RootSupport) GetApiMeta(svc string, action string) *ApiMeta
- func (r *RootSupport) GetVersion(svc string) string
- func (r *RootSupport) IsValidAction(svc, action string) bool
- func (r *RootSupport) IsValidSvc(svc string) bool
- type SSOService
- type STSCredentials
- type SdkClient
- type SdkClientInfo
- type ServiceDescription
- type Sso
- func (s *Sso) EnsureValidStsToken(ctx *Context) error
- func (s *Sso) GetAccessToken() (string, error)
- func (s *Sso) GetRoleCredentials() (*RoleCredentials, error)
- func (s *Sso) GetValidAccessToken() (string, error)
- func (s *Sso) Login() error
- func (s *Sso) Logout() error
- func (s *Sso) SetProfile() error
- type SsoSession
- type SsoTokenCache
- type StartDeviceAuthorizationRequest
- type StartDeviceAuthorizationResponse
- type StructInfo
- type VolcengineMeta
Constants ¶
const ( ModeSSO = "sso" ModeConsoleLogin = "console-login" ModeAK = "ak" ModeRamRoleArn = "ramrolearn" ModeOIDC = "oidc" ModeEcsRole = "ecsrole" ConfigFile = "config.json" )
定义模式枚举常量
const ( // ConsoleClientIDSameDevice is the legacy public client ID issued by the // removed authorization code flow. Login never mints it again; refresh // replays whatever client ID the cache holds, so caches written by older // CLI versions keep working. Kept to document that value and to pin it in // the compatibility tests. ConsoleClientIDSameDevice = "trn:signin:::devtools/same-device" // ConsoleClientIDCrossDevice is the public client ID used by device code login. ConsoleClientIDCrossDevice = "trn:signin:::devtools/cross-device" )
Variables ¶
This section is empty.
Functions ¶
func GetServiceMapping ¶
func SetServiceMapping ¶ added in v1.0.12
func SetServiceMapping(s1, s2 string)
func WriteConfigToFile ¶
WriteConfigToFile store config
Types ¶
type AccountInfo ¶ added in v1.0.39
type AccountInfo struct {
AccountID string `json:"AccountId"`
AccountName string `json:"AccountName"`
}
AccountInfo 表示 ListAccounts 返回的账号信息。
type ApiDescription ¶ added in v1.0.48
type ApiMeta ¶
func (*ApiMeta) GetReqRequired ¶
func (*ApiMeta) GetReqTypeName ¶
func (*ApiMeta) GetRequestParams ¶ added in v1.0.48
func (m *ApiMeta) GetRequestParams() (params []param)
type Configure ¶
type Configure struct {
Current string `json:"current"`
Profiles map[string]*Profile `json:"profiles"`
EnableColor bool `json:"enableColor"`
SsoSession map[string]*SsoSession `json:"sso-session"`
}
func LoadConfig ¶
func LoadConfig() *Configure
LoadConfig from CONFIG_FILE_DIR(default ~/.volcengine)
func (*Configure) SetRandomCurrentProfile ¶
func (config *Configure) SetRandomCurrentProfile()
type ConsoleDeviceAuthorizationRequest ¶ added in v1.1.5
ConsoleDeviceAuthorizationRequest represents a device authorization request.
type ConsoleDeviceAuthorizationResponse ¶ added in v1.1.5
type ConsoleDeviceAuthorizationResponse struct {
DeviceCode string `json:"device_code"`
UserCode string `json:"user_code"`
VerificationURI string `json:"verification_uri"`
VerificationURIComplete string `json:"verification_uri_complete,omitempty"`
ExpiresIn int `json:"expires_in"`
Interval int `json:"interval,omitempty"`
}
ConsoleDeviceAuthorizationResponse represents a device authorization response.
type ConsoleLogin ¶ added in v1.0.41
type ConsoleLogin struct {
Profile string // profile name, default "default"
Region string
NoBrowser bool // true = do not automatically open a browser during authorization
EndpointURL string // default "https://signin.volcengine.com"
}
ConsoleLogin holds runtime state for the volcengine login flow.
func (*ConsoleLogin) Login ¶ added in v1.0.41
func (cl *ConsoleLogin) Login() error
type ConsoleLogout ¶ added in v1.0.41
type ConsoleLogout struct {
Profile string // profile name, default "default"
All bool // true = clear all login caches
}
ConsoleLogout holds runtime state for the volcengine logout flow.
func (*ConsoleLogout) Logout ¶ added in v1.0.41
func (cl *ConsoleLogout) Logout() error
type ConsoleOAuthAPIError ¶ added in v1.0.41
type ConsoleOAuthAPIError struct {
StatusCode int
Response ConsoleOAuthErrorResponse
RawBody string
RequestID string // X-Tt-Logid header
}
ConsoleOAuthAPIError wraps a non-2xx response from the console OAuth endpoints.
func (*ConsoleOAuthAPIError) Error ¶ added in v1.0.41
func (e *ConsoleOAuthAPIError) Error() string
func (*ConsoleOAuthAPIError) IsRetryable ¶ added in v1.0.41
func (e *ConsoleOAuthAPIError) IsRetryable() bool
IsRetryable reports whether the error is transient and the request should be retried. Reuses the same HTTP status heuristic as the SSO client.
type ConsoleOAuthClient ¶ added in v1.0.41
type ConsoleOAuthClient struct {
// contains filtered or unexported fields
}
ConsoleOAuthClient wraps HTTP calls to the Volcengine console sign-in OAuth endpoints. Unlike the existing OAuthClient (which talks to CloudIdentity), this client targets signin.volcengine.com and implements the public-client device code flow.
func NewConsoleOAuthClient ¶ added in v1.0.41
func NewConsoleOAuthClient(cfg *ConsoleOAuthClientConfig) *ConsoleOAuthClient
NewConsoleOAuthClient creates a new ConsoleOAuthClient with the given configuration. If cfg is nil or EndpointURL is empty, the default endpoint is used.
func (*ConsoleOAuthClient) ExchangeToken ¶ added in v1.0.41
func (c *ConsoleOAuthClient) ExchangeToken(ctx context.Context, req *ConsoleTokenRequest) (*ConsoleTokenResponse, error)
ExchangeToken performs the token exchange by sending a POST request to the token endpoint with application/x-www-form-urlencoded body parameters.
For the device code grant: device_code and client_id are required.
For grant_type=refresh_token: refresh_token and client_id are required.
The method uses retry logic (doWithRetry) with up to 3 attempts for transient failures. Only errors where ConsoleOAuthAPIError.IsRetryable() returns true are retried.
func (*ConsoleOAuthClient) StartDeviceAuthorization ¶ added in v1.1.5
func (c *ConsoleOAuthClient) StartDeviceAuthorization( ctx context.Context, req *ConsoleDeviceAuthorizationRequest, ) (*ConsoleDeviceAuthorizationResponse, error)
StartDeviceAuthorization starts the OAuth 2.0 Device Authorization Grant flow.
type ConsoleOAuthClientConfig ¶ added in v1.0.41
type ConsoleOAuthClientConfig struct {
// EndpointURL is the base URL of the console sign-in service,
// e.g. "https://signin.volcengine.com". If empty, defaultConsoleEndpoint is used.
EndpointURL string
// HTTPClient allows injecting a custom HTTP client (e.g. for proxy or testing).
HTTPClient *http.Client
}
ConsoleOAuthClientConfig holds configuration for console OAuth client.
type ConsoleOAuthErrorResponse ¶ added in v1.0.41
type ConsoleOAuthErrorResponse struct {
State string `json:"state,omitempty"`
Error string `json:"error"`
ErrorDescription string `json:"error_description,omitempty"`
ErrorURI string `json:"error_uri,omitempty"`
}
ConsoleOAuthErrorResponse represents the error response body from the console signin OAuth endpoints. Structure per the signin API spec:
{
"state": "...", // echoed back if present in request
"error": "invalid_grant", // OAuth error code (required)
"error_description": "...", // human-readable detail (optional)
"error_uri": "..." // URI for more info (optional)
}
type ConsoleTokenRequest ¶ added in v1.0.41
type ConsoleTokenRequest struct {
GrantType string // deviceCodeGrantType or "refresh_token"
ClientID string
Scope string
RefreshToken string // for refresh_token grant
DeviceCode string // for device code grant
}
ConsoleTokenRequest represents the token exchange request for console OAuth.
type ConsoleTokenResponse ¶ added in v1.0.41
type ConsoleTokenResponse struct {
AccessToken string `json:"access_token"` // JSON string containing STS credentials
TokenType string `json:"token_type"` // e.g. "urn:ietf:params:oauth:token-type:access_token_sts"
ExpiresIn int `json:"expires_in"` // seconds, e.g. 900
RefreshToken string `json:"refresh_token"`
Scope string `json:"scope"`
IDToken string `json:"id_token"` // JWT
}
ConsoleTokenResponse represents the raw token response from the console OAuth endpoint.
type Context ¶
type Context struct {
// contains filtered or unexported fields
}
func NewContext ¶
func NewContext() *Context
type CreateTokenRequest ¶ added in v1.0.39
type CreateTokenRequest struct {
GrantType string `json:"grant_type"`
ClientID string `json:"client_id"`
ClientSecret string `json:"client_secret"`
RefreshToken string `json:"refresh_token,omitempty"`
DeviceCode string `json:"device_code,omitempty"`
}
CreateTokenRequest 对应 CreateToken API 的请求参数。
type CreateTokenResponse ¶ added in v1.0.39
type CreateTokenResponse struct {
AccessToken string `json:"access_token"`
TokenType string `json:"token_type"`
RefreshToken string `json:"refresh_token,omitempty"`
ExpiresIn int `json:"expires_in"`
}
CreateTokenResponse 表示获取 Token 成功后的返回结构。
type DebugLogger ¶ added in v1.0.48
type DebugLogger struct {
// contains filtered or unexported fields
}
func (*DebugLogger) Close ¶ added in v1.0.48
func (l *DebugLogger) Close() error
Close 刷新缓冲区并关闭底层输出资源。 返回写入、刷新或关闭阶段遇到的首个错误;nil logger 直接返回 nil,便于调用方安全 defer。
func (*DebugLogger) Enabled ¶ added in v1.0.48
func (l *DebugLogger) Enabled() bool
Enabled 返回 debug logger 当前是否可写。 nil logger 或显式关闭 debug 时都视为未启用,方便调用方直接在链路中做空值保护。
func (*DebugLogger) Printf ¶ added in v1.0.48
func (l *DebugLogger) Printf(format string, args ...interface{})
Printf 在 debug logger 启用时写入一行格式化日志。 写入失败只记录首个错误并留到 Close 返回,避免 debug 日志问题打断主业务流程。
type DeviceCodeFetcher ¶ added in v1.0.39
type DeviceCodeFetcher struct {
// contains filtered or unexported fields
}
DeviceCodeFetcher 负责基于设备码的 OAuth 授权流程。
func (*DeviceCodeFetcher) GetFreshTokenForLogin ¶ added in v1.0.41
func (f *DeviceCodeFetcher) GetFreshTokenForLogin() (*SsoTokenCache, error)
GetFreshTokenForLogin 执行显式登录授权。 无论缓存 access token 是否有效,也不会用 refresh_token 静默完成登录。
func (*DeviceCodeFetcher) GetToken ¶ added in v1.0.39
func (f *DeviceCodeFetcher) GetToken() (*SsoTokenCache, error)
GetToken 协调设备码流程、refresh token 刷新及缓存复用。 该方法保留给 configure sso 等交互式流程使用:它可以复用缓存、尝试 refresh,并在必要时回退到设备码授权。
func (*DeviceCodeFetcher) GetValidTokenForBusiness ¶ added in v1.0.41
func (f *DeviceCodeFetcher) GetValidTokenForBusiness() (*SsoTokenCache, error)
GetValidTokenForBusiness 返回业务命令可用的 access token 缓存。 业务命令只允许静默 refresh,不允许回退到设备码授权,避免普通 API 调用突然打开浏览器或阻塞等待用户授权。
type Flag ¶
type Flag struct {
Name string
// contains filtered or unexported fields
}
type FlagSet ¶
type FlagSet struct {
// contains filtered or unexported fields
}
func NewFlagSet ¶
func NewFlagSet() *FlagSet
type GetRoleCredentialsRequest ¶ added in v1.0.39
type GetRoleCredentialsRequest struct {
AccessToken string
AccountID string
RoleName string
PageSize int
PageNumber int
}
GetRoleCredentialsRequest 为 GetRoleCredentials 的请求参数封装。
type GetRoleCredentialsResponse ¶ added in v1.0.39
type GetRoleCredentialsResponse struct {
RoleCredentials RoleCredentials
RequestID string
}
GetRoleCredentialsResponse 返回临时凭证及请求 ID。
type ListAccountRolesRequest ¶ added in v1.0.39
type ListAccountRolesRequest struct {
AccessToken string
AccountID string
PageSize int
PageNumber int
NextToken string
}
ListAccountRolesRequest 为 ListAccountRoles 的请求参数封装。
type ListAccountRolesResponse ¶ added in v1.0.39
type ListAccountRolesResponse struct {
Total int
PageNumber int
PageSize int
RoleList []RoleInfo
NextToken string
RequestID string
}
ListAccountRolesResponse 返回角色列表及分页信息。
type ListAccountsRequest ¶ added in v1.0.39
ListAccountsRequest 为 ListAccounts 的请求参数封装。
type ListAccountsResponse ¶ added in v1.0.39
type ListAccountsResponse struct {
Total int
PageNumber int
PageSize int
AccountList []AccountInfo
NextToken string
RequestID string
}
ListAccountsResponse 返回账号列表及分页信息。
type LoginTokenCache ¶ added in v1.0.41
type LoginTokenCache struct {
LoginSession string `json:"login_session"`
AccessToken json.RawMessage `json:"access_token"`
RefreshToken string `json:"refresh_token,omitempty"`
IDToken string `json:"id_token,omitempty"`
Scope string `json:"scope"`
ClientID string `json:"client_id"`
EndpointURL string `json:"endpoint_url,omitempty"`
IssuedAt string `json:"issued_at"`
ExpiresIn int `json:"expires_in"`
TokenType string `json:"token_type"`
}
LoginTokenCache represents the cached login token data persisted to disk.
type Meta ¶
type Meta struct {
MetaTypes map[string]*MetaType `json:"MetaTypes,omitempty"`
ChildMetas map[string]*Meta `json:"ChildMetas,omitempty"`
}
func (*Meta) GetReqBody ¶
type OAuthAPIError ¶ added in v1.0.39
OAuthAPIError 用于承载 OAuth API 非 2xx 响应时的结构化错误信息。
func (*OAuthAPIError) Error ¶ added in v1.0.39
func (e *OAuthAPIError) Error() string
type OAuthClient ¶ added in v1.0.39
type OAuthClient struct {
// contains filtered or unexported fields
}
OAuthClient 缓存拼好的 URL 和 HTTP 客户端,避免每次调用重新计算。
func NewOAuthClient ¶ added in v1.0.39
func NewOAuthClient(cfg *OAuthClientConfig) *OAuthClient
NewOAuthClient 根据配置创建 OAuthClient,包含默认值和可选覆盖项。
func (*OAuthClient) CreateToken ¶ added in v1.0.39
func (c *OAuthClient) CreateToken(ctx context.Context, req *CreateTokenRequest) (*CreateTokenResponse, error)
CreateToken 调用 CreateToken API,获取 access/refresh token。
func (*OAuthClient) RegisterClient ¶ added in v1.0.39
func (c *OAuthClient) RegisterClient(ctx context.Context, req *RegisterClientRequest) (*RegisterClientResponse, error)
RegisterClient 调用 RegisterClient API,返回注册后的 client_id/client_secret。
func (*OAuthClient) RevokeToken ¶ added in v1.0.39
func (c *OAuthClient) RevokeToken(ctx context.Context, req *RevokeTokenRequest) error
RevokeToken 调用 RevokeToken API 撤销 access/refresh token。
func (*OAuthClient) StartDeviceAuthorization ¶ added in v1.0.39
func (c *OAuthClient) StartDeviceAuthorization(ctx context.Context, req *StartDeviceAuthorizationRequest) (*StartDeviceAuthorizationResponse, error)
StartDeviceAuthorization 发起设备码授权流程。
type OAuthClientAPI ¶ added in v1.0.39
type OAuthClientAPI interface {
RegisterClient(ctx context.Context, req *RegisterClientRequest) (*RegisterClientResponse, error)
CreateToken(ctx context.Context, req *CreateTokenRequest) (*CreateTokenResponse, error)
RevokeToken(ctx context.Context, req *RevokeTokenRequest) error
StartDeviceAuthorization(ctx context.Context, req *StartDeviceAuthorizationRequest) (*StartDeviceAuthorizationResponse, error)
}
OAuthClientAPI 定义 OAuth 客户端对外暴露的方法集合,便于测试或替换实现。
type OAuthClientConfig ¶ added in v1.0.39
type OAuthClientConfig struct {
// Region 控制使用的区域(默认:cn-beijing)。
Region string
// HTTPClient 允许注入自定义 HTTP 客户端(例如代理、超时)。
HTTPClient *http.Client
}
OAuthClientConfig 用于配置 OAuth 客户端的可选项。
type PortalAPIError ¶ added in v1.0.39
PortalAPIError 用于承载 Portal API 非 2xx 响应时的结构化错误信息。
func (*PortalAPIError) Error ¶ added in v1.0.39
func (e *PortalAPIError) Error() string
type PortalClient ¶ added in v1.0.39
type PortalClient struct {
// contains filtered or unexported fields
}
PortalClient 封装 CloudIdentity Portal API 调用,集中管理 URL、HTTP 客户端和默认分页参数。
func NewPortalClient ¶ added in v1.0.39
func NewPortalClient(cfg *PortalClientConfig) *PortalClient
NewPortalClient 根据配置创建 PortalClient,包含默认值和可选覆盖项。
func (*PortalClient) GetRoleCredentials ¶ added in v1.0.39
func (c *PortalClient) GetRoleCredentials(ctx context.Context, req *GetRoleCredentialsRequest) (*GetRoleCredentialsResponse, error)
GetRoleCredentials 使用 Portal 访问令牌换取指定账号和角色的临时凭证。
func (*PortalClient) ListAccountRoles ¶ added in v1.0.39
func (c *PortalClient) ListAccountRoles(ctx context.Context, req *ListAccountRolesRequest) (*ListAccountRolesResponse, error)
ListAccountRoles 调用 ListAccountRoles API,返回指定账号下当前令牌可用的角色列表。
func (*PortalClient) ListAccounts ¶ added in v1.0.39
func (c *PortalClient) ListAccounts(ctx context.Context, req *ListAccountsRequest) (*ListAccountsResponse, error)
ListAccounts 调用 ListAccounts API,返回当前访问令牌可见的账号列表。
type PortalClientAPI ¶ added in v1.0.39
type PortalClientAPI interface {
ListAccounts(ctx context.Context, req *ListAccountsRequest) (*ListAccountsResponse, error)
ListAccountRoles(ctx context.Context, req *ListAccountRolesRequest) (*ListAccountRolesResponse, error)
GetRoleCredentials(ctx context.Context, req *GetRoleCredentialsRequest) (*GetRoleCredentialsResponse, error)
}
PortalClientAPI 定义 Portal 客户端对外暴露的方法集合,便于测试或替换实现。
type PortalClientConfig ¶ added in v1.0.39
type PortalClientConfig struct {
Region string // 区域标识(当前逻辑未使用)
BaseURL string // 自定义 Portal 基础地址
HTTPClient *http.Client // 自定义 HTTP 客户端(可注入超时、代理等)
DefaultPageSize int // 默认分页大小
}
PortalClientConfig 用于配置 Portal 客户端的可选项,比如自定义 BaseURL、HTTPClient 或分页大小。
type Profile ¶
type Profile struct {
Name string `json:"name"`
Mode string `json:"mode"`
AccessKey string `json:"access-key"`
SecretKey string `json:"secret-key"`
Region string `json:"region"`
Endpoint string `json:"endpoint"`
EndpointResolver string `json:"endpoint-resolver,omitempty"`
HTTPProxy string `json:"http-proxy,omitempty"`
HTTPSProxy string `json:"https-proxy,omitempty"`
UseDualStack *bool `json:"use-dual-stack,omitempty"`
SessionToken string `json:"session-token"`
DisableSSL *bool `json:"disable-ssl"`
SsoSessionName string `json:"sso-session-name"`
AccountId string `json:"account-id"`
RoleName string `json:"role-name"`
StsExpiration int64 `json:"sts-expiration"`
OidcTokenFile string `json:"oidc-token-file,omitempty"`
RoleTrn string `json:"role-trn,omitempty"`
LoginSession string `json:"login-session,omitempty"`
}
type RegisterClientRequest ¶ added in v1.0.39
type RegisterClientRequest struct {
ClientName string `json:"client_name"`
ClientType string `json:"client_type"`
GrantTypes []string `json:"grant_types,omitempty"`
Scopes []string `json:"scopes,omitempty"`
}
RegisterClientRequest 对应 RegisterClient API 的请求参数。
type RegisterClientResponse ¶ added in v1.0.39
type RegisterClientResponse struct {
ClientID string `json:"client_id"`
ClientSecret string `json:"client_secret"`
ClientIDIssuedAt int64 `json:"client_id_issued_at,omitempty"`
ClientSecretExpiresAt int64 `json:"client_secret_expires_at,omitempty"`
}
RegisterClientResponse 表示注册客户端成功后的返回结构。
type ResponseMetadata ¶ added in v1.0.39
type ResponseMetadata struct {
RequestID string `json:"RequestId"`
}
ResponseMetadata 表示 Portal API 返回的基础元信息。
type RevokeTokenRequest ¶ added in v1.0.39
type RevokeTokenRequest struct {
ClientID string `json:"client_id"`
ClientSecret string `json:"client_secret"`
Token string `json:"token"`
}
RevokeTokenRequest 为撤销 token 的请求参数。
type RoleCredentials ¶ added in v1.0.39
type RoleCredentials struct {
AccessKeyID string `json:"AccessKeyId"`
Expiration int64 `json:"Expiration"`
SecretAccessKey string `json:"SecretAccessKey"`
SessionToken string `json:"sessionToken"`
}
RoleCredentials 表示 GetRoleCredentials 返回的临时凭证信息。
type RootSupport ¶
type RootSupport struct {
SupportSvc []string
SupportAction map[string]map[string]*VolcengineMeta
Versions map[string]string
SupportTypes map[string]map[string]*ApiMeta
}
func NewRootSupport ¶
func NewRootSupport() *RootSupport
func (*RootSupport) GetAllAction ¶
func (r *RootSupport) GetAllAction(svc string) []string
func (*RootSupport) GetAllSvc ¶
func (r *RootSupport) GetAllSvc() []string
func (*RootSupport) GetAllSvcCompatible ¶ added in v1.0.15
func (r *RootSupport) GetAllSvcCompatible() []string
func (*RootSupport) GetApiInfo ¶
func (r *RootSupport) GetApiInfo(svc string, action string) *ApiInfo
func (*RootSupport) GetApiMeta ¶ added in v1.0.40
func (r *RootSupport) GetApiMeta(svc string, action string) *ApiMeta
func (*RootSupport) GetVersion ¶
func (r *RootSupport) GetVersion(svc string) string
func (*RootSupport) IsValidAction ¶
func (r *RootSupport) IsValidAction(svc, action string) bool
func (*RootSupport) IsValidSvc ¶
func (r *RootSupport) IsValidSvc(svc string) bool
type SSOService ¶ added in v1.0.39
type SSOService interface {
SetProfile() error
Login() error
Logout() error
GetAccessToken() (string, error)
GetRoleCredentials() (*RoleCredentials, error)
}
SSOService 定义对外暴露的 SSO 操作接口。
type STSCredentials ¶ added in v1.0.41
type STSCredentials struct {
AccessKeyID string `json:"access_key_id"`
SecretAccessKey string `json:"secret_access_key"`
SessionToken string `json:"session_token"`
}
STSCredentials represents the parsed STS credentials extracted from the access_token field of ConsoleTokenResponse. The access_token is a JSON-encoded string that must be parsed separately.
func EnsureValidLoginToken ¶ added in v1.0.41
func EnsureValidLoginToken(cfg *Configure, profileName string) (*STSCredentials, error)
func ParseSTSCredentials ¶ added in v1.0.41
func ParseSTSCredentials(accessToken string) (*STSCredentials, error)
ParseSTSCredentials parses the JSON-encoded access_token string into an STSCredentials struct. The access_token field in ConsoleTokenResponse is not a simple bearer token; it is a JSON string containing STS temporary credentials.
type SdkClient ¶
type SdkClient struct {
Config *volcengine.Config
Session *session.Session
DebugLogger *DebugLogger
}
func NewSimpleClient ¶
NewSimpleClient creates an SDK client with credential resolution:
- If a profile is configured: a. SSO mode: CLI refreshes STS credentials (EnsureValidStsToken), then delegates to SDK CliProvider. b. Console Login mode: CLI refreshes the login cache, then delegates to SDK CliProvider. c. Other modes: directly delegates to SDK CliProvider for credential resolution.
- If no profile is configured, use the SDK default credential chain (Env → OIDC → CliProvider → EcsRole).
type SdkClientInfo ¶
type ServiceDescription ¶ added in v1.0.48
type Sso ¶ added in v1.0.39
type Sso struct {
Profile *Profile
SsoSessionName string
StartURL string
Region string
UseDeviceCode bool
NoBrowser bool
Scopes []string
}
Sso 持有 SSO 运行时所需的配置与状态。
func (*Sso) EnsureValidStsToken ¶ added in v1.0.39
EnsureValidStsToken 确保 SSO 模式下的 STS Token 有效(过期或缺失则刷新)。
func (*Sso) GetAccessToken ¶ added in v1.0.39
GetAccessToken 从缓存获取有效的 access token。
func (*Sso) GetRoleCredentials ¶ added in v1.0.39
func (s *Sso) GetRoleCredentials() (*RoleCredentials, error)
GetRoleCredentials 获取当前 profile 对应角色的临时凭证。
func (*Sso) GetValidAccessToken ¶ added in v1.0.41
GetValidAccessToken 获取业务命令可用的 access token。 access token 未进入刷新窗口时直接复用;过期或即将过期时仅尝试 refresh_token 静默续期。
func (*Sso) SetProfile ¶ added in v1.0.39
SetProfile 通过 SSO 登录并写入配置文件。
type SsoSession ¶ added in v1.0.39
type SsoTokenCache ¶ added in v1.0.39
type SsoTokenCache struct {
StartURL string `json:"start_url"`
SessionName string `json:"session_name"`
AccessToken string `json:"access_token"`
ExpiresAt string `json:"expires_at"`
ClientId string `json:"client_id"`
ClientSecret string `json:"client_secret"`
ClientIdIssuedAt int64 `json:"client_id_issued_at,omitempty"`
ClientSecretExpiresAt int64 `json:"client_secret_expires_at,omitempty"`
RefreshToken string `json:"refresh_token,omitempty"`
Region string `json:"region"`
}
SsoTokenCache 保存 SSO 访问令牌及客户端凭据的缓存结构。
type StartDeviceAuthorizationRequest ¶ added in v1.0.39
type StartDeviceAuthorizationRequest struct {
ClientID string `json:"client_id"`
ClientSecret string `json:"client_secret"`
Scopes []string `json:"scopes,omitempty"`
PortalUrl string `json:"portal_url,omitempty"`
}
StartDeviceAuthorizationRequest 为设备码授权的请求参数。
type StartDeviceAuthorizationResponse ¶ added in v1.0.39
type StartDeviceAuthorizationResponse struct {
DeviceCode string `json:"device_code"`
UserCode string `json:"user_code"`
VerificationURI string `json:"verification_uri"`
VerificationURIComplete string `json:"verification_uri_complete"`
ExpiresIn int `json:"expires_in"`
Interval int `json:"interval,omitempty"`
}
StartDeviceAuthorizationResponse 表示设备码授权成功后的返回结构。
type StructInfo ¶ added in v1.0.15
type VolcengineMeta ¶
func (*VolcengineMeta) GetRequestParams ¶
func (meta *VolcengineMeta) GetRequestParams(apiMeta *ApiMeta) (params []param)
Source Files
¶
- action_help.go
- action_input.go
- cmd_action.go
- cmd_configure.go
- cmd_consolelogin.go
- cmd_root.go
- cmd_service.go
- cmd_skills.go
- cmd_sso.go
- cmd_upgrade.go
- compatible.go
- completion.go
- configure.go
- consolelogin_device_code_poll.go
- consolelogin_login.go
- consolelogin_logout.go
- consolelogin_oauth_client.go
- context.go
- debug_logger.go
- debug_logger_links.go
- explorer_descriptions.go
- flag.go
- flat_expand.go
- force.go
- global_meta.go
- http_retry.go
- i18n.go
- i18n_messages_zh.go
- invocation.go
- meta_type.go
- metadata.go
- oauth_client.go
- output.go
- param_descriptions.go
- parser.go
- portal_client.go
- reserved_dynamic.go
- root_support.go
- sdk_client.go
- sdk_request_debug.go
- service_mapping.go
- sso.go
- system_flag_defs.go
- system_flags.go
- version.go