1#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct AssumeRole;
6impl AssumeRole {
7 pub fn new() -> Self {
9 Self
10 }
11 pub(crate) async fn orchestrate(
12 runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13 input: crate::operation::assume_role::AssumeRoleInput,
14 ) -> ::std::result::Result<
15 crate::operation::assume_role::AssumeRoleOutput,
16 ::aws_smithy_runtime_api::client::result::SdkError<
17 crate::operation::assume_role::AssumeRoleError,
18 ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
19 >,
20 > {
21 let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<
22 ::aws_smithy_runtime_api::client::interceptors::context::Error,
23 ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
24 >| {
25 err.map_service_error(|err| {
26 err.downcast::<crate::operation::assume_role::AssumeRoleError>()
27 .expect("correct error type")
28 })
29 };
30 let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
31 .await
32 .map_err(map_err)?;
33 let output = context.finalize().map_err(map_err)?;
34 ::std::result::Result::Ok(
35 output
36 .downcast::<crate::operation::assume_role::AssumeRoleOutput>()
37 .expect("correct output type"),
38 )
39 }
40
41 pub(crate) async fn orchestrate_with_stop_point(
42 runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
43 input: crate::operation::assume_role::AssumeRoleInput,
44 stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
45 ) -> ::std::result::Result<
46 ::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext,
47 ::aws_smithy_runtime_api::client::result::SdkError<
48 ::aws_smithy_runtime_api::client::interceptors::context::Error,
49 ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
50 >,
51 > {
52 let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
53 use ::tracing::Instrument;
54 ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point("STS", "AssumeRole", input, runtime_plugins, stop_point)
55 .instrument(::tracing::debug_span!(
58 "STS.AssumeRole",
59 "rpc.service" = "STS",
60 "rpc.method" = "AssumeRole",
61 "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
62 "rpc.system" = "aws-api",
63 ))
64 .await
65 }
66
67 pub(crate) fn operation_runtime_plugins(
68 client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
69 client_config: &crate::config::Config,
70 config_override: ::std::option::Option<crate::config::Builder>,
71 ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
72 let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
73
74 if let ::std::option::Option::Some(config_override) = config_override {
75 for plugin in config_override.runtime_plugins.iter().cloned() {
76 runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
77 }
78 runtime_plugins = runtime_plugins.with_operation_plugin(crate::config::ConfigOverrideRuntimePlugin::new(
79 config_override,
80 client_config.config.clone(),
81 &client_config.runtime_components,
82 ));
83 }
84 runtime_plugins
85 }
86}
87impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for AssumeRole {
88 fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
89 let mut cfg = ::aws_smithy_types::config_bag::Layer::new("AssumeRole");
90
91 cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(
92 AssumeRoleRequestSerializer,
93 ));
94 cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(
95 AssumeRoleResponseDeserializer,
96 ));
97
98 cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
99 crate::config::auth::Params::builder()
100 .operation_name("AssumeRole")
101 .build()
102 .expect("required fields set"),
103 ));
104
105 cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::SensitiveOutput);
106 cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new("AssumeRole", "STS"));
107 let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
108 signing_options.double_uri_encode = true;
109 signing_options.content_sha256_header = false;
110 signing_options.normalize_uri_path = true;
111 signing_options.payload_override = None;
112
113 cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
114 signing_options,
115 ..::std::default::Default::default()
116 });
117
118 ::std::option::Option::Some(cfg.freeze())
119 }
120
121 fn runtime_components(
122 &self,
123 _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder,
124 ) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
125 #[allow(unused_mut)]
126 let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("AssumeRole")
127 .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
128 AssumeRoleTelemetryInputCaptureInterceptor,
129 ))
130 .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
131 ::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default(),
132 ))
133 .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
134 AssumeRoleEndpointParamsInterceptor,
135 ))
136 .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<
137 crate::operation::assume_role::AssumeRoleError,
138 >::new())
139 .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<
140 crate::operation::assume_role::AssumeRoleError,
141 >::new())
142 .with_retry_classifier(
143 ::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<crate::operation::assume_role::AssumeRoleError>::builder()
144 .transient_errors({
145 let mut transient_errors: Vec<&'static str> = ::aws_runtime::retries::classifiers::TRANSIENT_ERRORS.into();
146 transient_errors.push("IDPCommunicationError");
147 ::std::borrow::Cow::Owned(transient_errors)
148 })
149 .build(),
150 )
151 .with_retry_classifier(::aws_runtime::service_clock_skew::ServiceClockSkewClassifier::<
152 crate::operation::assume_role::AssumeRoleError,
153 >::new());
154
155 ::std::borrow::Cow::Owned(rcb)
156 }
157}
158
159#[derive(Debug)]
160struct AssumeRoleTelemetryInputCaptureInterceptor;
161
162#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
163impl ::aws_smithy_runtime_api::client::interceptors::Intercept for AssumeRoleTelemetryInputCaptureInterceptor {
164 fn name(&self) -> &'static str {
165 "AssumeRoleTelemetryInputCaptureInterceptor"
166 }
167
168 fn read_before_execution(
169 &self,
170 context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
171 '_,
172 ::aws_smithy_runtime_api::client::interceptors::context::Input,
173 ::aws_smithy_runtime_api::client::interceptors::context::Output,
174 ::aws_smithy_runtime_api::client::interceptors::context::Error,
175 >,
176 cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
177 ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
178 let ::std::option::Option::Some(requested) = cfg
180 .load::<::aws_smithy_types::telemetry::RequestedTelemetryAttributes>()
181 .filter(|r| !r.is_empty())
182 else {
183 return ::std::result::Result::Ok(());
184 };
185
186 let ::std::option::Option::Some(input) = context.input().downcast_ref::<AssumeRoleInput>() else {
187 return ::std::result::Result::Ok(());
189 };
190
191 let mut captured = ::aws_smithy_types::telemetry::CapturedTelemetryAttributes::default();
192 if requested.should_capture("RoleArn") {
193 if let ::std::option::Option::Some(value) = input.role_arn.as_deref() {
194 captured.insert("RoleArn", value);
195 }
196 }
197 if requested.should_capture("RoleSessionName") {
198 if let ::std::option::Option::Some(value) = input.role_session_name.as_deref() {
199 captured.insert("RoleSessionName", value);
200 }
201 }
202 if requested.should_capture("Policy") {
203 if let ::std::option::Option::Some(value) = input.policy.as_deref() {
204 captured.insert("Policy", value);
205 }
206 }
207 if requested.should_capture("ExternalId") {
208 if let ::std::option::Option::Some(value) = input.external_id.as_deref() {
209 captured.insert("ExternalId", value);
210 }
211 }
212 if requested.should_capture("SerialNumber") {
213 if let ::std::option::Option::Some(value) = input.serial_number.as_deref() {
214 captured.insert("SerialNumber", value);
215 }
216 }
217 if requested.should_capture("TokenCode") {
218 if let ::std::option::Option::Some(value) = input.token_code.as_deref() {
219 captured.insert("TokenCode", value);
220 }
221 }
222 if requested.should_capture("SourceIdentity") {
223 if let ::std::option::Option::Some(value) = input.source_identity.as_deref() {
224 captured.insert("SourceIdentity", value);
225 }
226 }
227
228 cfg.interceptor_state().store_put(captured);
229 ::std::result::Result::Ok(())
230 }
231}
232#[derive(Debug)]
233struct AssumeRoleResponseDeserializer;
234impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for AssumeRoleResponseDeserializer {
235 fn deserialize_nonstreaming_with_config(
236 &self,
237 response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
238 _cfg: &::aws_smithy_types::config_bag::ConfigBag,
239 ) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
240 let (success, status) = (response.status().is_success(), response.status().as_u16());
241 let headers = response.headers();
242 let body = response.body().bytes().expect("body loaded");
243 #[allow(unused_mut)]
244 let mut force_error = false;
245 ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
246 let parse_result = if !success && status != 200 || force_error {
247 crate::protocol_serde::shape_assume_role::de_assume_role_http_error(status, headers, body, _cfg)
248 } else {
249 crate::protocol_serde::shape_assume_role::de_assume_role_http_response(status, headers, body, _cfg)
250 };
251 crate::protocol_serde::type_erase_result(parse_result)
252 }
253}
254#[derive(Debug)]
255struct AssumeRoleRequestSerializer;
256impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for AssumeRoleRequestSerializer {
257 #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
258 fn serialize_input(
259 &self,
260 input: ::aws_smithy_runtime_api::client::interceptors::context::Input,
261 _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
262 ) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
263 let input = input.downcast::<crate::operation::assume_role::AssumeRoleInput>().expect("correct type");
264 let _header_serialization_settings = _cfg
265 .load::<crate::serialization_settings::HeaderSerializationSettings>()
266 .cloned()
267 .unwrap_or_default();
268 let mut request_builder = {
269 #[allow(clippy::uninlined_format_args)]
270 fn uri_base(
271 _input: &crate::operation::assume_role::AssumeRoleInput,
272 output: &mut ::std::string::String,
273 ) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
274 use ::std::fmt::Write as _;
275 ::std::write!(output, "/").expect("formatting should succeed");
276 ::std::result::Result::Ok(())
277 }
278 #[allow(clippy::unnecessary_wraps)]
279 fn update_http_builder(
280 input: &crate::operation::assume_role::AssumeRoleInput,
281 builder: ::http_1x::request::Builder,
282 ) -> ::std::result::Result<::http_1x::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
283 let mut uri = ::std::string::String::new();
284 uri_base(input, &mut uri)?;
285 ::std::result::Result::Ok(builder.method("POST").uri(uri))
286 }
287 let mut builder = update_http_builder(&input, ::http_1x::request::Builder::new())?;
288 builder =
289 _header_serialization_settings.set_default_header(builder, ::http_1x::header::CONTENT_TYPE, "application/x-www-form-urlencoded");
290 builder
291 };
292 let body =
293 ::aws_smithy_types::body::SdkBody::from(crate::protocol_serde::shape_assume_role_input::ser_assume_role_input_input_input(&input)?);
294 if let Some(content_length) = body.content_length() {
295 let content_length = content_length.to_string();
296 request_builder = _header_serialization_settings.set_default_header(request_builder, ::http_1x::header::CONTENT_LENGTH, &content_length);
297 }
298 ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
299 }
300}
301#[derive(Debug)]
302struct AssumeRoleEndpointParamsInterceptor;
303
304#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
305impl ::aws_smithy_runtime_api::client::interceptors::Intercept for AssumeRoleEndpointParamsInterceptor {
306 fn name(&self) -> &'static str {
307 "AssumeRoleEndpointParamsInterceptor"
308 }
309
310 fn read_before_execution(
311 &self,
312 context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
313 '_,
314 ::aws_smithy_runtime_api::client::interceptors::context::Input,
315 ::aws_smithy_runtime_api::client::interceptors::context::Output,
316 ::aws_smithy_runtime_api::client::interceptors::context::Error,
317 >,
318 cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
319 ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
320 let _input = context
321 .input()
322 .downcast_ref::<AssumeRoleInput>()
323 .ok_or("failed to downcast to AssumeRoleInput")?;
324
325 let params = crate::config::endpoint::Params::builder()
326 .set_region(cfg.load::<::aws_types::region::Region>().map(|r| r.as_ref().to_owned()))
327 .set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
328 .set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
329 .set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
330 .build()
331 .map_err(|err| {
332 ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err)
333 })?;
334 cfg.interceptor_state()
335 .store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
336 ::std::result::Result::Ok(())
337 }
338}
339
340#[non_exhaustive]
345#[derive(::std::fmt::Debug)]
346pub enum AssumeRoleError {
347 ExpiredTokenException(crate::types::error::ExpiredTokenException),
349 MalformedPolicyDocumentException(crate::types::error::MalformedPolicyDocumentException),
351 PackedPolicyTooLargeException(crate::types::error::PackedPolicyTooLargeException),
354 RegionDisabledException(crate::types::error::RegionDisabledException),
356 #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
358 variable wildcard pattern and check `.code()`:
359 \
360 `err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
361 \
362 See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-AssumeRoleError) for what information is available for the error.")]
363 Unhandled(crate::error::sealed_unhandled::Unhandled),
364}
365impl AssumeRoleError {
366 pub fn unhandled(
368 err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>,
369 ) -> Self {
370 Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
371 source: err.into(),
372 meta: ::std::default::Default::default(),
373 })
374 }
375
376 pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
378 Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
379 source: err.clone().into(),
380 meta: err,
381 })
382 }
383 pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
388 match self {
389 Self::ExpiredTokenException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
390 Self::MalformedPolicyDocumentException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
391 Self::PackedPolicyTooLargeException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
392 Self::RegionDisabledException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
393 Self::Unhandled(e) => &e.meta,
394 }
395 }
396 pub fn is_expired_token_exception(&self) -> bool {
398 matches!(self, Self::ExpiredTokenException(_))
399 }
400 pub fn is_malformed_policy_document_exception(&self) -> bool {
402 matches!(self, Self::MalformedPolicyDocumentException(_))
403 }
404 pub fn is_packed_policy_too_large_exception(&self) -> bool {
406 matches!(self, Self::PackedPolicyTooLargeException(_))
407 }
408 pub fn is_region_disabled_exception(&self) -> bool {
410 matches!(self, Self::RegionDisabledException(_))
411 }
412}
413impl ::std::error::Error for AssumeRoleError {
414 fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
415 match self {
416 Self::ExpiredTokenException(_inner) => ::std::option::Option::Some(_inner),
417 Self::MalformedPolicyDocumentException(_inner) => ::std::option::Option::Some(_inner),
418 Self::PackedPolicyTooLargeException(_inner) => ::std::option::Option::Some(_inner),
419 Self::RegionDisabledException(_inner) => ::std::option::Option::Some(_inner),
420 Self::Unhandled(_inner) => ::std::option::Option::Some(&*_inner.source),
421 }
422 }
423}
424impl ::std::fmt::Display for AssumeRoleError {
425 fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
426 match self {
427 Self::ExpiredTokenException(_inner) => _inner.fmt(f),
428 Self::MalformedPolicyDocumentException(_inner) => _inner.fmt(f),
429 Self::PackedPolicyTooLargeException(_inner) => _inner.fmt(f),
430 Self::RegionDisabledException(_inner) => _inner.fmt(f),
431 Self::Unhandled(_inner) => {
432 if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
433 write!(f, "unhandled error ({code})")
434 } else {
435 f.write_str("unhandled error")
436 }
437 }
438 }
439 }
440}
441impl ::aws_smithy_types::retry::ProvideErrorKind for AssumeRoleError {
442 fn code(&self) -> ::std::option::Option<&str> {
443 ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
444 }
445 fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
446 ::std::option::Option::None
447 }
448}
449impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for AssumeRoleError {
450 fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
451 match self {
452 Self::ExpiredTokenException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
453 Self::MalformedPolicyDocumentException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
454 Self::PackedPolicyTooLargeException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
455 Self::RegionDisabledException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
456 Self::Unhandled(_inner) => &_inner.meta,
457 }
458 }
459}
460impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for AssumeRoleError {
461 fn create_unhandled_error(
462 source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
463 meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>,
464 ) -> Self {
465 Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
466 source,
467 meta: meta.unwrap_or_default(),
468 })
469 }
470}
471impl ::aws_types::request_id::RequestId for crate::operation::assume_role::AssumeRoleError {
472 fn request_id(&self) -> Option<&str> {
473 self.meta().request_id()
474 }
475}
476
477pub use crate::operation::assume_role::_assume_role_input::AssumeRoleInput;
478
479pub use crate::operation::assume_role::_assume_role_output::AssumeRoleOutput;
480
481mod _assume_role_input;
482
483mod _assume_role_output;
484
485pub mod builders;