aws_sdk_sts/operation/
assume_role.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2/// Orchestration and serialization glue logic for `AssumeRole`.
3#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct AssumeRole;
6impl AssumeRole {
7    /// Creates a new `AssumeRole`
8    pub fn new() -> Self {
9        Self
10    }
11    pub(crate) async fn orchestrate(
12                        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13                        input: crate::operation::assume_role::AssumeRoleInput,
14                    ) -> ::std::result::Result<crate::operation::assume_role::AssumeRoleOutput, ::aws_smithy_runtime_api::client::result::SdkError<crate::operation::assume_role::AssumeRoleError, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>> {
15                        let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<::aws_smithy_runtime_api::client::interceptors::context::Error, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>| {
16                            err.map_service_error(|err| {
17                                err.downcast::<crate::operation::assume_role::AssumeRoleError>().expect("correct error type")
18                            })
19                        };
20                        let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
21                            .await
22                            .map_err(map_err)?;
23                        let output = context.finalize().map_err(map_err)?;
24                        ::std::result::Result::Ok(output.downcast::<crate::operation::assume_role::AssumeRoleOutput>().expect("correct output type"))
25                    }
26    
27                    pub(crate) async fn orchestrate_with_stop_point(
28                        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
29                        input: crate::operation::assume_role::AssumeRoleInput,
30                        stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
31                    ) -> ::std::result::Result<::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext, ::aws_smithy_runtime_api::client::result::SdkError<::aws_smithy_runtime_api::client::interceptors::context::Error, ::aws_smithy_runtime_api::client::orchestrator::HttpResponse>> {
32                        let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
33                        use ::tracing::Instrument;
34                        ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point(
35                            "STS",
36                            "AssumeRole",
37                            input,
38                            runtime_plugins,
39                            stop_point
40                        )
41                        // Create a parent span for the entire operation. Includes a random, internal-only,
42                        // seven-digit ID for the operation orchestration so that it can be correlated in the logs.
43                        .instrument(::tracing::debug_span!(
44                                "STS.AssumeRole",
45                                "rpc.service" = "STS",
46                                "rpc.method" = "AssumeRole",
47                                "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
48                                "rpc.system" = "aws-api",
49                            ))
50                        .await
51                    }
52    
53                    pub(crate) fn operation_runtime_plugins(
54                        client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
55                        client_config: &crate::config::Config,
56                        config_override: ::std::option::Option<crate::config::Builder>,
57                    ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
58                        let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
59                        
60                        if let ::std::option::Option::Some(config_override) = config_override {
61                            for plugin in config_override.runtime_plugins.iter().cloned() {
62                                runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
63                            }
64                            runtime_plugins = runtime_plugins.with_operation_plugin(
65                                crate::config::ConfigOverrideRuntimePlugin::new(config_override, client_config.config.clone(), &client_config.runtime_components)
66                            );
67                        }
68                        runtime_plugins
69                    }
70}
71impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for AssumeRole {
72                fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
73                    let mut cfg = ::aws_smithy_types::config_bag::Layer::new("AssumeRole");
74
75                    cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(AssumeRoleRequestSerializer));
76                    cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(AssumeRoleResponseDeserializer));
77
78                    cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
79                        crate::config::auth::Params::builder()
80                            .operation_name("AssumeRole")
81                            .build()
82                            .expect("required fields set")
83                    ));
84
85                    cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::SensitiveOutput);
86cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new(
87                            "AssumeRole",
88                            "STS",
89                        ));
90let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
91                            signing_options.double_uri_encode = true;
92                            signing_options.content_sha256_header = false;
93                            signing_options.normalize_uri_path = true;
94                            signing_options.payload_override = None;
95
96                            cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
97                                signing_options,
98                                ..::std::default::Default::default()
99                            });
100
101                    ::std::option::Option::Some(cfg.freeze())
102                }
103
104                fn runtime_components(&self, _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
105                    #[allow(unused_mut)]
106                    let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("AssumeRole")
107                            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default()))
108.with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(AssumeRoleEndpointParamsInterceptor))
109                            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<crate::operation::assume_role::AssumeRoleError>::new())
110.with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<crate::operation::assume_role::AssumeRoleError>::new())
111.with_retry_classifier(::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<crate::operation::assume_role::AssumeRoleError>::new());
112
113                    ::std::borrow::Cow::Owned(rcb)
114                }
115            }
116
117            
118#[derive(Debug)]
119            struct AssumeRoleResponseDeserializer;
120            impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for AssumeRoleResponseDeserializer {
121                
122
123                fn deserialize_nonstreaming(&self, response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
124                    let (success, status) = (response.status().is_success(), response.status().as_u16());
125            let headers = response.headers();
126            let body = response.body().bytes().expect("body loaded");
127            #[allow(unused_mut)]
128            let mut force_error = false;
129            ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
130            let parse_result = if !success && status != 200 || force_error {
131                crate::protocol_serde::shape_assume_role::de_assume_role_http_error(status, headers, body)
132            } else {
133                crate::protocol_serde::shape_assume_role::de_assume_role_http_response(status, headers, body)
134            };
135            crate::protocol_serde::type_erase_result(parse_result)
136                }
137            }
138#[derive(Debug)]
139            struct AssumeRoleRequestSerializer;
140            impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for AssumeRoleRequestSerializer {
141                #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
142                fn serialize_input(&self, input: ::aws_smithy_runtime_api::client::interceptors::context::Input, _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
143                    let input = input.downcast::<crate::operation::assume_role::AssumeRoleInput>().expect("correct type");
144                    let _header_serialization_settings = _cfg.load::<crate::serialization_settings::HeaderSerializationSettings>().cloned().unwrap_or_default();
145                    let mut request_builder = {
146                        #[allow(clippy::uninlined_format_args)]
147fn uri_base(_input: &crate::operation::assume_role::AssumeRoleInput, output: &mut ::std::string::String) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
148    use ::std::fmt::Write as _;
149    ::std::write!(output, "/").expect("formatting should succeed");
150    ::std::result::Result::Ok(())
151}
152#[allow(clippy::unnecessary_wraps)]
153fn update_http_builder(
154                input: &crate::operation::assume_role::AssumeRoleInput,
155                builder: ::http_1x::request::Builder
156            ) -> ::std::result::Result<::http_1x::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
157    let mut uri = ::std::string::String::new();
158    uri_base(input, &mut uri)?;
159    ::std::result::Result::Ok(builder.method("POST").uri(uri))
160}
161let mut builder = update_http_builder(&input, ::http_1x::request::Builder::new())?;
162builder = _header_serialization_settings.set_default_header(builder, ::http_1x::header::CONTENT_TYPE, "application/x-www-form-urlencoded");
163builder
164                    };
165                    let body = ::aws_smithy_types::body::SdkBody::from(crate::protocol_serde::shape_assume_role_input::ser_assume_role_input_input_input(&input)?);
166                    if let Some(content_length) = body.content_length() {
167                                let content_length = content_length.to_string();
168                                request_builder = _header_serialization_settings.set_default_header(request_builder, ::http_1x::header::CONTENT_LENGTH, &content_length);
169                            }
170                    ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
171                }
172            }
173#[derive(Debug)]
174            struct AssumeRoleEndpointParamsInterceptor;
175
176            #[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
177            impl ::aws_smithy_runtime_api::client::interceptors::Intercept for AssumeRoleEndpointParamsInterceptor {
178                fn name(&self) -> &'static str {
179                    "AssumeRoleEndpointParamsInterceptor"
180                }
181
182                fn read_before_execution(
183                    &self,
184                    context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<'_, ::aws_smithy_runtime_api::client::interceptors::context::Input, ::aws_smithy_runtime_api::client::interceptors::context::Output, ::aws_smithy_runtime_api::client::interceptors::context::Error>,
185                    cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
186                ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
187                    let _input = context.input()
188                        .downcast_ref::<AssumeRoleInput>()
189                        .ok_or("failed to downcast to AssumeRoleInput")?;
190
191                    
192
193                    let params = crate::config::endpoint::Params::builder()
194                        .set_region(cfg.load::<::aws_types::region::Region>().map(|r|r.as_ref().to_owned()))
195.set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
196.set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
197.set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
198                        .build()
199                        .map_err(|err| ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err))?;
200                    cfg.interceptor_state().store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
201                    ::std::result::Result::Ok(())
202                }
203            }
204
205            // The get_* functions below are generated from JMESPath expressions in the
206            // operationContextParams trait. They target the operation's input shape.
207
208            
209
210/// Error type for the `AssumeRoleError` operation.
211#[non_exhaustive]
212#[derive(::std::fmt::Debug)]
213pub enum AssumeRoleError {
214    /// <p>The web identity token that was passed is expired or is not valid. Get a new identity token from the identity provider and then retry the request.</p>
215    ExpiredTokenException(crate::types::error::ExpiredTokenException),
216    /// <p>The request was rejected because the policy document was malformed. The error message describes the specific error.</p>
217    MalformedPolicyDocumentException(crate::types::error::MalformedPolicyDocumentException),
218    /// <p>The request was rejected because the total packed size of the session policies and session tags combined was too large. An Amazon Web Services conversion compresses the session policy document, session policy ARNs, and session tags into a packed binary format that has a separate limit. The error message indicates by percentage how close the policies and tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the <i>IAM User Guide</i>.</p>
219    /// <p>You could receive this error even though you meet other defined session policy and session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity Character Limits</a> in the <i>IAM User Guide</i>.</p>
220    PackedPolicyTooLargeException(crate::types::error::PackedPolicyTooLargeException),
221    /// <p>STS is not activated in the requested region for the account that is being asked to generate credentials. The account administrator must use the IAM console to activate STS in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html">Activating and Deactivating STS in an Amazon Web Services Region</a> in the <i>IAM User Guide</i>.</p>
222    RegionDisabledException(crate::types::error::RegionDisabledException),
223    /// An unexpected error occurred (e.g., invalid JSON returned by the service or an unknown error code).
224                    #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
225    variable wildcard pattern and check `.code()`:
226     \
227    &nbsp;&nbsp;&nbsp;`err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
228     \
229    See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-AssumeRoleError) for what information is available for the error.")]
230                    Unhandled(crate::error::sealed_unhandled::Unhandled),
231}
232impl AssumeRoleError {
233    /// Creates the `AssumeRoleError::Unhandled` variant from any error type.
234                    pub fn unhandled(err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>) -> Self {
235                        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source: err.into(), meta: ::std::default::Default::default() })
236                    }
237    
238                    /// Creates the `AssumeRoleError::Unhandled` variant from an [`ErrorMetadata`](::aws_smithy_types::error::ErrorMetadata).
239                    pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
240                        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source: err.clone().into(), meta: err })
241                    }
242    /// 
243    /// Returns error metadata, which includes the error code, message,
244    /// request ID, and potentially additional information.
245    /// 
246    pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
247        match self {
248            Self::ExpiredTokenException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
249            Self::MalformedPolicyDocumentException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
250            Self::PackedPolicyTooLargeException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
251            Self::RegionDisabledException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
252            Self::Unhandled(e) => &e.meta,
253        }
254    }
255    /// Returns `true` if the error kind is `AssumeRoleError::ExpiredTokenException`.
256    pub fn is_expired_token_exception(&self) -> bool {
257        matches!(self, Self::ExpiredTokenException(_))
258    }
259    /// Returns `true` if the error kind is `AssumeRoleError::MalformedPolicyDocumentException`.
260    pub fn is_malformed_policy_document_exception(&self) -> bool {
261        matches!(self, Self::MalformedPolicyDocumentException(_))
262    }
263    /// Returns `true` if the error kind is `AssumeRoleError::PackedPolicyTooLargeException`.
264    pub fn is_packed_policy_too_large_exception(&self) -> bool {
265        matches!(self, Self::PackedPolicyTooLargeException(_))
266    }
267    /// Returns `true` if the error kind is `AssumeRoleError::RegionDisabledException`.
268    pub fn is_region_disabled_exception(&self) -> bool {
269        matches!(self, Self::RegionDisabledException(_))
270    }
271}
272impl ::std::error::Error for AssumeRoleError {
273    fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
274        match self {
275            Self::ExpiredTokenException(_inner) =>
276            ::std::option::Option::Some(_inner)
277            ,
278            Self::MalformedPolicyDocumentException(_inner) =>
279            ::std::option::Option::Some(_inner)
280            ,
281            Self::PackedPolicyTooLargeException(_inner) =>
282            ::std::option::Option::Some(_inner)
283            ,
284            Self::RegionDisabledException(_inner) =>
285            ::std::option::Option::Some(_inner)
286            ,
287            Self::Unhandled(_inner) => {
288                ::std::option::Option::Some(&*_inner.source)
289            }
290        }
291    }
292}
293impl ::std::fmt::Display for AssumeRoleError {
294    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
295        match self {
296            Self::ExpiredTokenException(_inner) =>
297            _inner.fmt(f)
298            ,
299            Self::MalformedPolicyDocumentException(_inner) =>
300            _inner.fmt(f)
301            ,
302            Self::PackedPolicyTooLargeException(_inner) =>
303            _inner.fmt(f)
304            ,
305            Self::RegionDisabledException(_inner) =>
306            _inner.fmt(f)
307            ,
308            Self::Unhandled(_inner) => {
309                if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
310                                                        write!(f, "unhandled error ({code})")
311                                                    } else {
312                                                        f.write_str("unhandled error")
313                                                    }
314            }
315        }
316    }
317}
318impl ::aws_smithy_types::retry::ProvideErrorKind for AssumeRoleError {
319    fn code(&self) -> ::std::option::Option<&str> {
320        ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
321    }
322    fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
323        ::std::option::Option::None
324    }
325}
326impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for AssumeRoleError {
327    fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
328        match self {
329            Self::ExpiredTokenException(_inner) =>
330            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
331            ,
332            Self::MalformedPolicyDocumentException(_inner) =>
333            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
334            ,
335            Self::PackedPolicyTooLargeException(_inner) =>
336            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
337            ,
338            Self::RegionDisabledException(_inner) =>
339            ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner)
340            ,
341            Self::Unhandled(_inner) => {
342                &_inner.meta
343            }
344        }
345    }
346}
347impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for AssumeRoleError {
348    fn create_unhandled_error(
349                        source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
350                        meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>
351                    ) -> Self {
352        Self::Unhandled(crate::error::sealed_unhandled::Unhandled { source, meta: meta.unwrap_or_default() })
353    }
354}
355impl ::aws_types::request_id::RequestId for crate::operation::assume_role::AssumeRoleError {
356                                fn request_id(&self) -> Option<&str> {
357                                    self.meta().request_id()
358                                }
359                            }
360
361pub use crate::operation::assume_role::_assume_role_input::AssumeRoleInput;
362
363pub use crate::operation::assume_role::_assume_role_output::AssumeRoleOutput;
364
365mod _assume_role_input;
366
367mod _assume_role_output;
368
369/// Builders
370pub mod builders;
371