aws_sdk_sts/operation/
assume_role.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2/// Orchestration and serialization glue logic for `AssumeRole`.
3#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct AssumeRole;
6impl AssumeRole {
7    /// Creates a new `AssumeRole`
8    pub fn new() -> Self {
9        Self
10    }
11    pub(crate) async fn orchestrate(
12                        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13                        input: crate::operation::assume_role::AssumeRoleInput,
14                    ) -> ::std::result::Result<crate::operation::assume_role::AssumeRoleOutput, ::aws_smithy_runtime_api::client::result::SdkError<crate::operation::assume_role::AssumeRoleError, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>> {
15                        let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<::aws_smithy_runtime_api::client::interceptors::context::Error, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>| {
16                            err.map_service_error(|err| {
17                                err.downcast::<crate::operation::assume_role::AssumeRoleError>().expect("correct error type")
18                            })
19                        };
20                        let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
21                            .await
22                            .map_err(map_err)?;
23                        let output = context.finalize().map_err(map_err)?;
24                        ::std::result::Result::Ok(output.downcast::<crate::operation::assume_role::AssumeRoleOutput>().expect("correct output type"))
25                    }
26    
27                    pub(crate) async fn orchestrate_with_stop_point(
28                        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
29                        input: crate::operation::assume_role::AssumeRoleInput,
30                        stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
31                    ) -> ::std::result::Result<::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext, ::aws_smithy_runtime_api::client::result::SdkError<::aws_smithy_runtime_api::client::interceptors::context::Error, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>> {
32                        let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
33                        use ::tracing::Instrument;
34                        ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point(
35                            "STS",
36                            "AssumeRole",
37                            input,
38                            runtime_plugins,
39                            stop_point
40                        )
41                        // Create a parent span for the entire operation. Includes a random, internal-only,
42                        // seven-digit ID for the operation orchestration so that it can be correlated in the logs.
43                        .instrument(::tracing::debug_span!(
44                                "STS.AssumeRole",
45                                "rpc.service" = "STS",
46                                "rpc.method" = "AssumeRole",
47                                "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
48                                "rpc.system" = "aws-api",
49                            ))
50                        .await
51                    }
52    
53                    pub(crate) fn operation_runtime_plugins(
54                        client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
55                        client_config: &crate::config::Config,
56                        config_override: ::std::option::Option<crate::config::Builder>,
57                    ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
58                        let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
59                        
60                        if let ::std::option::Option::Some(config_override) = config_override {
61                            for plugin in config_override.runtime_plugins.iter().cloned() {
62                                runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
63                            }
64                            runtime_plugins = runtime_plugins.with_operation_plugin(
65                                crate::config::ConfigOverrideRuntimePlugin::new(config_override, client_config.config.clone(), &client_config.runtime_components)
66                            );
67                        }
68                        runtime_plugins
69                    }
70}
71impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for AssumeRole {
72                fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
73                    let mut cfg = ::aws_smithy_types::config_bag::Layer::new("AssumeRole");
74
75                    cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(AssumeRoleRequestSerializer));
76                    cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(AssumeRoleResponseDeserializer));
77
78                    cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
79                        crate::config::auth::Params::builder()
80                            .operation_name("AssumeRole")
81                            .build()
82                            .expect("required fields set")
83                    ));
84
85                    cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::SensitiveOutput);
86cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new(
87                            "AssumeRole",
88                            "STS",
89                        ));
90let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
91                            signing_options.double_uri_encode = true;
92                            signing_options.content_sha256_header = false;
93                            signing_options.normalize_uri_path = true;
94                            signing_options.payload_override = None;
95
96                            cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
97                                signing_options,
98                                ..::std::default::Default::default()
99                            });
100
101                    ::std::option::Option::Some(cfg.freeze())
102                }
103
104                fn runtime_components(&self, _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
105                    #[allow(unused_mut)]
106                    let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("AssumeRole")
107                            .with_interceptor(::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default())
108.with_interceptor(AssumeRoleEndpointParamsInterceptor)
109                            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<crate::operation::assume_role::AssumeRoleError>::new())
110.with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<crate::operation::assume_role::AssumeRoleError>::new())
111.with_retry_classifier(::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<crate::operation::assume_role::AssumeRoleError>::new());
112
113                    ::std::borrow::Cow::Owned(rcb)
114                }
115            }
116
117            
118#[derive(Debug)]
119            struct AssumeRoleResponseDeserializer;
120            impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for AssumeRoleResponseDeserializer {
121                
122
123                fn deserialize_nonstreaming(&self, response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
124                    let (success, status) = (response.status().is_success(), response.status().as_u16());
125            let headers = response.headers();
126            let body = response.body().bytes().expect("body loaded");
127            #[allow(unused_mut)]
128            let mut force_error = false;
129            ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
130            let parse_result = if !success && status != 200 || force_error {
131                crate::protocol_serde::shape_assume_role::de_assume_role_http_error(status, headers, body)
132            } else {
133                crate::protocol_serde::shape_assume_role::de_assume_role_http_response(status, headers, body)
134            };
135            crate::protocol_serde::type_erase_result(parse_result)
136                }
137            }
138#[derive(Debug)]
139            struct AssumeRoleRequestSerializer;
140            impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for AssumeRoleRequestSerializer {
141                #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
142                fn serialize_input(&self, input: ::aws_smithy_runtime_api::client::interceptors::context::Input, _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
143                    let input = input.downcast::<crate::operation::assume_role::AssumeRoleInput>().expect("correct type");
144                    let _header_serialization_settings = _cfg.load::<crate::serialization_settings::HeaderSerializationSettings>().cloned().unwrap_or_default();
145                    let mut request_builder = {
146                        fn uri_base(_input: &crate::operation::assume_role::AssumeRoleInput, output: &mut ::std::string::String) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
147    use ::std::fmt::Write as _;
148    ::std::write!(output, "/").expect("formatting should succeed");
149    ::std::result::Result::Ok(())
150}
151#[allow(clippy::unnecessary_wraps)]
152fn update_http_builder(
153                input: &crate::operation::assume_role::AssumeRoleInput,
154                builder: ::http::request::Builder
155            ) -> ::std::result::Result<::http::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
156    let mut uri = ::std::string::String::new();
157    uri_base(input, &mut uri)?;
158    ::std::result::Result::Ok(builder.method("POST").uri(uri))
159}
160let mut builder = update_http_builder(&input, ::http::request::Builder::new())?;
161builder = _header_serialization_settings.set_default_header(builder, ::http::header::CONTENT_TYPE, "application/x-www-form-urlencoded");
162builder
163                    };
164                    let body = ::aws_smithy_types::body::SdkBody::from(crate::protocol_serde::shape_assume_role_input::ser_assume_role_input_input_input(&input)?);
165                    if let Some(content_length) = body.content_length() {
166                                let content_length = content_length.to_string();
167                                request_builder = _header_serialization_settings.set_default_header(request_builder, ::http::header::CONTENT_LENGTH, &content_length);
168                            }
169                    ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
170                }
171            }
172#[derive(Debug)]
173            struct AssumeRoleEndpointParamsInterceptor;
174
175            impl ::aws_smithy_runtime_api::client::interceptors::Intercept for AssumeRoleEndpointParamsInterceptor {
176                fn name(&self) -> &'static str {
177                    "AssumeRoleEndpointParamsInterceptor"
178                }
179
180                fn read_before_execution(
181                    &self,
182                    context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<'_, ::aws_smithy_runtime_api::client::interceptors::context::Input, ::aws_smithy_runtime_api::client::interceptors::context::Output, ::aws_smithy_runtime_api::client::interceptors::context::Error>,
183                    cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
184                ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
185                    let _input = context.input()
186                        .downcast_ref::<AssumeRoleInput>()
187                        .ok_or("failed to downcast to AssumeRoleInput")?;
188
189                    
190
191                    let params = crate::config::endpoint::Params::builder()
192                        .set_region(cfg.load::<::aws_types::region::Region>().map(|r|r.as_ref().to_owned()))
193.set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
194.set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
195.set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
196                        .build()
197                        .map_err(|err| ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err))?;
198
199                    
200
201                    cfg.interceptor_state().store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
202
203                    ::std::result::Result::Ok(())
204                }
205            }
206
207            // The get_* functions below are generated from JMESPath expressions in the
208            // operationContextParams trait. They target the operation's input shape.
209
210            
211
212/// Error type for the `AssumeRoleError` operation.
213#[non_exhaustive]
214#[derive(::std::fmt::Debug)]
215pub enum AssumeRoleError {
216    /// <p>The web identity token that was passed is expired or is not valid. Get a new identity token from the identity provider and then retry the request.</p>
217    ExpiredTokenException(crate::types::error::ExpiredTokenException),
218    /// <p>The request was rejected because the policy document was malformed. The error message describes the specific error.</p>
219    MalformedPolicyDocumentException(crate::types::error::MalformedPolicyDocumentException),
220    /// <p>The request was rejected because the total packed size of the session policies and session tags combined was too large. An Amazon Web Services conversion compresses the session policy document, session policy ARNs, and session tags into a packed binary format that has a separate limit. The error message indicates by percentage how close the policies and tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the <i>IAM User Guide</i>.</p>
221    /// <p>You could receive this error even though you meet other defined session policy and session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity Character Limits</a> in the <i>IAM User Guide</i>.</p>
222    PackedPolicyTooLargeException(crate::types::error::PackedPolicyTooLargeException),
223    /// <p>STS is not activated in the requested region for the account that is being asked to generate credentials. The account administrator must use the IAM console to activate STS in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and Deactivating Amazon Web Services STS in an Amazon Web Services Region</a> in the <i>IAM User Guide</i>.</p>
224    RegionDisabledException(crate::types::error::RegionDisabledException),
225    /// An unexpected error occurred (e.g., invalid JSON returned by the service or an unknown error code).
226                    #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
227    variable wildcard pattern and check `.code()`:
228     \
229    &nbsp;&nbsp;&nbsp;`err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
230     \
231    See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-AssumeRoleError) for what information is available for the error.")]
232                    Unhandled(crate::error::sealed_unhandled::Unhandled),
233}
234impl AssumeRoleError {
235    /// Creates the `AssumeRoleError::Unhandled` variant from any error type.
236                    pub fn unhandled(err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>) -> Self {
237                        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source: err.into(), meta: ::std::default::Default::default() })
238                    }
239    
240                    /// Creates the `AssumeRoleError::Unhandled` variant from an [`ErrorMetadata`](::aws_smithy_types::error::ErrorMetadata).
241                    pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
242                        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source: err.clone().into(), meta: err })
243                    }
244    /// 
245    /// Returns error metadata, which includes the error code, message,
246    /// request ID, and potentially additional information.
247    /// 
248    pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
249        match self {
250            Self::ExpiredTokenException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
251            Self::MalformedPolicyDocumentException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
252            Self::PackedPolicyTooLargeException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
253            Self::RegionDisabledException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
254            Self::Unhandled(e) => &e.meta,
255        }
256    }
257    /// Returns `true` if the error kind is `AssumeRoleError::ExpiredTokenException`.
258    pub fn is_expired_token_exception(&self) -> bool {
259        matches!(self, Self::ExpiredTokenException(_))
260    }
261    /// Returns `true` if the error kind is `AssumeRoleError::MalformedPolicyDocumentException`.
262    pub fn is_malformed_policy_document_exception(&self) -> bool {
263        matches!(self, Self::MalformedPolicyDocumentException(_))
264    }
265    /// Returns `true` if the error kind is `AssumeRoleError::PackedPolicyTooLargeException`.
266    pub fn is_packed_policy_too_large_exception(&self) -> bool {
267        matches!(self, Self::PackedPolicyTooLargeException(_))
268    }
269    /// Returns `true` if the error kind is `AssumeRoleError::RegionDisabledException`.
270    pub fn is_region_disabled_exception(&self) -> bool {
271        matches!(self, Self::RegionDisabledException(_))
272    }
273}
274impl ::std::error::Error for AssumeRoleError {
275    fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
276        match self {
277            Self::ExpiredTokenException(_inner) =>
278            ::std::option::Option::Some(_inner)
279            ,
280            Self::MalformedPolicyDocumentException(_inner) =>
281            ::std::option::Option::Some(_inner)
282            ,
283            Self::PackedPolicyTooLargeException(_inner) =>
284            ::std::option::Option::Some(_inner)
285            ,
286            Self::RegionDisabledException(_inner) =>
287            ::std::option::Option::Some(_inner)
288            ,
289            Self::Unhandled(_inner) => {
290                ::std::option::Option::Some(&*_inner.source)
291            }
292        }
293    }
294}
295impl ::std::fmt::Display for AssumeRoleError {
296    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
297        match self {
298            Self::ExpiredTokenException(_inner) =>
299            _inner.fmt(f)
300            ,
301            Self::MalformedPolicyDocumentException(_inner) =>
302            _inner.fmt(f)
303            ,
304            Self::PackedPolicyTooLargeException(_inner) =>
305            _inner.fmt(f)
306            ,
307            Self::RegionDisabledException(_inner) =>
308            _inner.fmt(f)
309            ,
310            Self::Unhandled(_inner) => {
311                if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
312                                                        write!(f, "unhandled error ({code})")
313                                                    } else {
314                                                        f.write_str("unhandled error")
315                                                    }
316            }
317        }
318    }
319}
320impl ::aws_smithy_types::retry::ProvideErrorKind for AssumeRoleError {
321    fn code(&self) -> ::std::option::Option<&str> {
322        ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
323    }
324    fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
325        ::std::option::Option::None
326    }
327}
328impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for AssumeRoleError {
329    fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
330        match self {
331            Self::ExpiredTokenException(_inner) =>
332            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
333            ,
334            Self::MalformedPolicyDocumentException(_inner) =>
335            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
336            ,
337            Self::PackedPolicyTooLargeException(_inner) =>
338            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
339            ,
340            Self::RegionDisabledException(_inner) =>
341            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
342            ,
343            Self::Unhandled(_inner) => {
344                &_inner.meta
345            }
346        }
347    }
348}
349impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for AssumeRoleError {
350    fn create_unhandled_error(
351                        source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
352                        meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>
353                    ) -> Self {
354        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source, meta: meta.unwrap_or_default() })
355    }
356}
357impl ::aws_types::request_id::RequestId for crate::operation::assume_role::AssumeRoleError {
358                                fn request_id(&self) -> Option<&str> {
359                                    self.meta().request_id()
360                                }
361                            }
362
363pub use crate::operation::assume_role::_assume_role_output::AssumeRoleOutput;
364
365pub use crate::operation::assume_role::_assume_role_input::AssumeRoleInput;
366
367mod _assume_role_input;
368
369mod _assume_role_output;
370
371/// Builders
372pub mod builders;
373