| 1 | <?php |
||
| 2 | |||
| 3 | namespace AlibabaCloud\Client\Credentials\Providers; |
||
| 4 | |||
| 5 | use Exception; |
||
| 6 | use AlibabaCloud\Client\Support\Stringy; |
||
| 7 | use AlibabaCloud\Client\SDK; |
||
| 8 | use AlibabaCloud\Client\Result\Result; |
||
| 9 | use Psr\Http\Message\ResponseInterface; |
||
| 10 | use GuzzleHttp\Exception\GuzzleException; |
||
| 11 | use AlibabaCloud\Client\Request\RpcRequest; |
||
| 12 | use AlibabaCloud\Client\Credentials\StsCredential; |
||
| 13 | use AlibabaCloud\Client\Exception\ClientException; |
||
| 14 | use AlibabaCloud\Client\Exception\ServerException; |
||
| 15 | use AlibabaCloud\Client\Credentials\EcsRamRoleCredential; |
||
| 16 | |||
| 17 | /** |
||
| 18 | * Class EcsRamRoleProvider |
||
| 19 | * |
||
| 20 | * @package AlibabaCloud\Client\Credentials\Providers |
||
| 21 | */ |
||
| 22 | class EcsRamRoleProvider extends Provider |
||
| 23 | { |
||
| 24 | |||
| 25 | /** |
||
| 26 | * Expiration time slot for temporary security credentials. |
||
| 27 | * |
||
| 28 | * @var int |
||
| 29 | */ |
||
| 30 | |||
| 31 | protected $expirationSlot = 10; |
||
| 32 | |||
| 33 | /** |
||
| 34 | * @var string |
||
| 35 | */ |
||
| 36 | private $uri = 'http://100.100.100.200/latest/meta-data/ram/security-credentials/'; |
||
| 37 | |||
| 38 | /** |
||
| 39 | * Get credential. |
||
| 40 | * |
||
| 41 | * @return StsCredential |
||
| 42 | * @throws ClientException |
||
| 43 | * @throws ServerException |
||
| 44 | */ |
||
| 45 | 11 | public function get() |
|
| 46 | { |
||
| 47 | 11 | $result = $this->getCredentialsInCache(); |
|
| 48 | |||
| 49 | 11 | if ($result === null) { |
|
| 50 | 10 | $result = $this->request(); |
|
| 51 | |||
| 52 | 2 | if (!isset($result['AccessKeyId'], $result['AccessKeySecret'], $result['SecurityToken'])) { |
|
| 53 | 1 | throw new ServerException($result, $this->error, SDK::INVALID_CREDENTIAL); |
|
| 54 | } |
||
| 55 | |||
| 56 | 1 | $this->cache($result->toArray()); |
|
| 57 | 1 | } |
|
| 58 | |||
| 59 | 2 | return new StsCredential( |
|
| 60 | 2 | $result['AccessKeyId'], |
|
| 61 | 2 | $result['AccessKeySecret'], |
|
| 62 | 2 | $result['SecurityToken'] |
|
| 63 | 2 | ); |
|
| 64 | } |
||
| 65 | |||
| 66 | /** |
||
| 67 | * Get credentials by request. |
||
| 68 | * |
||
| 69 | * @return Result |
||
| 70 | * @throws ClientException |
||
| 71 | * @throws ServerException |
||
| 72 | */ |
||
| 73 | 10 | public function request() |
|
| 74 | { |
||
| 75 | 10 | $result = $this->getResponse(); |
|
| 76 | |||
| 77 | 4 | if ($result->getStatusCode() === 404) { |
|
| 78 | 1 | $message = 'The role was not found in the instance'; |
|
| 79 | 1 | throw new ClientException($message, SDK::INVALID_CREDENTIAL); |
|
| 80 | } |
||
| 81 | |||
| 82 | 3 | if (!$result->isSuccess()) { |
|
|
0 ignored issues
–
show
Bug
introduced
by
Loading history...
|
|||
| 83 | 1 | $message = 'Error retrieving credentials from result'; |
|
| 84 | 1 | throw new ServerException($result, $message, SDK::INVALID_CREDENTIAL); |
|
| 85 | } |
||
| 86 | |||
| 87 | 2 | return $result; |
|
| 88 | } |
||
| 89 | |||
| 90 | /** |
||
| 91 | * Get data from meta. |
||
| 92 | * |
||
| 93 | * @return mixed|ResponseInterface |
||
| 94 | * @throws ClientException |
||
| 95 | * @throws Exception |
||
| 96 | */ |
||
| 97 | 10 | public function getResponse() |
|
| 98 | { |
||
| 99 | /** |
||
| 100 | * @var EcsRamRoleCredential $credential |
||
| 101 | */ |
||
| 102 | 10 | $credential = $this->client->getCredential(); |
|
| 103 | 10 | $url = $this->uri . $credential->getRoleName(); |
|
| 104 | |||
| 105 | $options = [ |
||
| 106 | 10 | 'http_errors' => false, |
|
| 107 | 10 | 'timeout' => 1, |
|
| 108 | 10 | 'connect_timeout' => 1, |
|
| 109 | 10 | 'debug' => $this->client->isDebug(), |
|
| 110 | 10 | ]; |
|
| 111 | |||
| 112 | try { |
||
| 113 | 10 | return RpcRequest::createClient()->request('GET', $url, $options); |
|
| 114 | 6 | } catch (GuzzleException $exception) { |
|
| 115 | 6 | if (Stringy::contains($exception->getMessage(), 'timed')) { |
|
| 116 | 5 | $message = 'Timeout or instance does not belong to Alibaba Cloud'; |
|
| 117 | 5 | } else { |
|
| 118 | 1 | $message = $exception->getMessage(); |
|
| 119 | } |
||
| 120 | |||
| 121 | 6 | throw new ClientException( |
|
| 122 | 6 | $message, |
|
| 123 | 6 | SDK::SERVER_UNREACHABLE, |
|
| 124 | $exception |
||
| 125 | 6 | ); |
|
| 126 | } |
||
| 127 | } |
||
| 128 | } |
||
| 129 |