feat: implement AWS temporary session based interactions
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 48/100
Research direction
Start with the Alias struct in crates/core and read AGENTS.md for the breaking-change process. Trace S3Client, AdminClient, the CLI alias set entry point, migrations/, and schemas/output_v2.json, then inspect the golden tests. Done means session-token configuration, expiry handling, redaction, migration, schema updates, and the listed cargo checks all pass.
Written by the indexing model from the issue text.
Description
Description
Implement support for AWS session tokens to enable temporary, role-based interactions with S3-compatible backends. To maintain a seamless user experience, aliases utilizing expired session tokens will be automatically pruned from the configuration upon detection.
Requirements
- Core Alias Updates: Update the
Aliasconfiguration to support an optional session token using#[serde(default)]for backward compatibility. - Security: Implement a custom
fmt::Debugfor theAliasstruct to ensure session tokens and secret keys are scrubbed from logs. - Credential Injection: Modify
S3ClientandAdminClientto inject the session token into the AWS credentials provider. - Error Handling: Introduce a
TokenExpired(String)error variant and map AWSExpiredToken/InvalidTokenerrors to it. - CLI Auto-Pruning: Intercept
TokenExpirederrors at the CLI boundary to log a clear message, automatically remove the dead alias fromconfig.toml, and exit gracefully.
Acceptance Criteria
-
rc alias setsupports a new--session-tokenflag. - Configuration changes include a
schema_versionbump and a migration path (migrations/). -
schemas/output_v2.jsonis updated to include thesession_tokenfield in thealiasInfodefinition. - Static credentials continue to function normally when the session token is omitted.
- CLI correctly identifies an expired token, logs a helpful warning, deletes the alias, and exits with
AUTH_ERROR(Code 4). - Debug/verbose logs strictly mask the session token as
***REDACTED***. - Golden tests are successfully regenerated (
UPDATE_GOLDEN=1 cargo test --features golden) and pass. - Pre-commit checks (
cargo fmt --all,cargo clippy --workspace -- -D warnings) pass with zero warnings.
Notes
This change impacts the Alias struct in crates/core, triggering the Breaking Change process outlined in AGENTS.md. The aws-sigv4 crate automatically handles the X-Amz-Security-Token header during request signing.
- Dominant language
- Rust
- Stars
- 152
- Forks
- 21
- Avg merge
- 1d 4h
- Merged PRs (30d)
- 23
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from rustfs/cli
-
Difficulty 1/5 1-3 hours Newbie friendliness 82/100
-
Difficulty 4/5 3-5 days Newbie friendliness 52/100
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
issue
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
-
agentic-workflows
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
web-infra-dev/rspack#15847 ·