forked from aws/amazon-ssm-agent
/
shared_Credentials.go
107 lines (87 loc) · 3.12 KB
/
shared_Credentials.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
// Copyright 2016 Amazon.com, Inc. or its affiliates. All Rights Reserved.
//
// Licensed under the Apache License, Version 2.0 (the "License"). You may not
// use this file except in compliance with the License. A copy of the
// License is located at
//
// http://aws.amazon.com/apache2.0/
//
// or in the "license" file accompanying this file. This file is distributed
// on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND,
// either express or implied. See the License for the specific language governing
// permissions and limitations under the License.
// package sharedCredentials provides access to the aws shared credentials file.
package sharedCredentials
import (
"fmt"
"os"
"path/filepath"
"github.com/aws/amazon-ssm-agent/agent/fileutil"
"github.com/aws/aws-sdk-go/aws/awserr"
"github.com/go-ini/ini"
)
const (
defaultProfile = "default"
awsAccessKeyID = "aws_access_key_id"
awsSecretAccessKey = "aws_secret_access_key"
awsSessionToken = "aws_session_token"
)
// filename returns the filename to use to read AWS shared credentials.
//
// Will return an error if the user's home directory path cannot be found.
func filename() (string, error) {
if credPath := os.Getenv("AWS_SHARED_CREDENTIALS_FILE"); credPath != "" {
return credPath, nil
}
homeDir := getPlatformSpecificHomeLocation()
if homeDir == "" {
return "", awserr.New("UserHomeNotFound", "user home directory not found.", nil)
}
return filepath.Join(homeDir, ".aws", "credentials"), nil
}
func createFile(filePath string) error {
dir, _ := filepath.Split(filePath)
if err := fileutil.MakeDirs(dir); err != nil {
return fmt.Errorf("error creating directories, %s. %v", dir, err)
}
if err := fileutil.HardenedWriteFile(filePath, []byte("")); err != nil {
return fmt.Errorf("error creating file, %s. %v", filePath, err)
}
return nil
}
// Store function updates the shared credentials with the specified values:
// * If the shared credentials file does not exist, it will be created. Any parent directories will also be created.
// * If the section to update does not exist, it will be created.
func Store(accessKeyID, secretAccessKey, sessionToken, profile string) error {
if profile == "" {
profile = defaultProfile
}
credPath, err := filename()
if err != nil {
return err
}
// check if file exists, if not create it
if !fileutil.Exists(credPath) {
err := createFile(credPath)
if err != nil {
return awserr.New("SharedCredentialsStore", "failed to create shared credentials file", err)
}
}
config, err := ini.Load(credPath)
if err != nil {
return awserr.New("SharedCredentialsStore", "failed to load shared credentials file", err)
}
iniProfile := config.Section(profile)
if err != nil {
return awserr.New("SharedCredentialsStore", "failed to get profile", err)
}
// Default to empty string if not found
iniProfile.Key(awsAccessKeyID).SetValue(accessKeyID)
iniProfile.Key(awsSecretAccessKey).SetValue(secretAccessKey)
iniProfile.Key(awsSessionToken).SetValue(sessionToken)
err = config.SaveTo(credPath)
if err != nil {
return awserr.New("SharedCredentialsStore", "failed to save profile", err)
}
return nil
}