feat: implement AWS temporary session based interactions
维护者通常 1 天内回复
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 48/100
调研方向
从 crates/core 中的 Alias 结构体开始,并阅读 AGENTS.md 以了解 breaking change 流程。跟踪 S3Client、AdminClient、CLI 设置 alias 的入口点、migrations/ 和 schemas/output_v2.json,然后检查 golden tests。完成的标准是 session-token 配置、过期处理、redaction、migration、schema 更新以及列出的 cargo 检查全部通过。
由索引模型根据 Issue 内容生成。
描述
Description
Implement support for AWS session tokens to enable temporary, role-based interactions with S3-compatible backends. To maintain a seamless user experience, aliases utilizing expired session tokens will be automatically pruned from the configuration upon detection.
Requirements
- Core Alias Updates: Update the
Aliasconfiguration to support an optional session token using#[serde(default)]for backward compatibility. - Security: Implement a custom
fmt::Debugfor theAliasstruct to ensure session tokens and secret keys are scrubbed from logs. - Credential Injection: Modify
S3ClientandAdminClientto inject the session token into the AWS credentials provider. - Error Handling: Introduce a
TokenExpired(String)error variant and map AWSExpiredToken/InvalidTokenerrors to it. - CLI Auto-Pruning: Intercept
TokenExpirederrors at the CLI boundary to log a clear message, automatically remove the dead alias fromconfig.toml, and exit gracefully.
Acceptance Criteria
-
rc alias setsupports a new--session-tokenflag. - Configuration changes include a
schema_versionbump and a migration path (migrations/). -
schemas/output_v2.jsonis updated to include thesession_tokenfield in thealiasInfodefinition. - Static credentials continue to function normally when the session token is omitted.
- CLI correctly identifies an expired token, logs a helpful warning, deletes the alias, and exits with
AUTH_ERROR(Code 4). - Debug/verbose logs strictly mask the session token as
***REDACTED***. - Golden tests are successfully regenerated (
UPDATE_GOLDEN=1 cargo test --features golden) and pass. - Pre-commit checks (
cargo fmt --all,cargo clippy --workspace -- -D warnings) pass with zero warnings.
Notes
This change impacts the Alias struct in crates/core, triggering the Breaking Change process outlined in AGENTS.md. The aws-sigv4 crate automatically handles the X-Amz-Security-Token header during request signing.
- 主要语言
- Rust
- 星标
- 159
- 派生
- 23
- 平均合并
- 7 小时 4 分钟
- 30 天内合并 PR
- 10
环境准备
- 提供 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 没有贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
rustfs/cli 的其他 Issue
-
难度 1/5 1 小时以内 新手友好度 90/100
维护者通常 1 天内回复
-
Cannot install and update with brew可能已有人在做 @overtrue 于 3 天前认领。 未关闭
难度 2/5 1-3 小时 新手友好度 62/100
维护者通常 1 天内回复
-
难度 1/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 68/100
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 55/100
维护者通常 1 天内回复
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 1 天内回复
-
bug good first issue
难度 2/5 1-3 小时 新手友好度 84/100
repowise-dev/repowise#3374 ·
维护者通常 1 天内回复
-
awaiting-response bug needs-triage
难度 2/5 1-3 小时 新手友好度 72/100
维护者通常 3 天内回复
-
难度 2/5 1-3 小时 新手友好度 75/100
objectionary/sodg.rs#301 ·
-
难度 2/5 1-3 小时 新手友好度 62/100
HakanSeven12/OpenCADStudio#1706 · 1 条评论 ·
维护者通常 1 天内回复