Skip to main content

aws_sdk_sts/operation/
get_delegated_access_token.rs

1// Code generated by software.amazon.smithy.rust.codegen.smithy-rs. DO NOT EDIT.
2/// Orchestration and serialization glue logic for `GetDelegatedAccessToken`.
3#[derive(::std::clone::Clone, ::std::default::Default, ::std::fmt::Debug)]
4#[non_exhaustive]
5pub struct GetDelegatedAccessToken;
6impl GetDelegatedAccessToken {
7    /// Creates a new `GetDelegatedAccessToken`
8    pub fn new() -> Self {
9        Self
10    }
11    pub(crate) async fn orchestrate(
12        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
13        input: crate::operation::get_delegated_access_token::GetDelegatedAccessTokenInput,
14    ) -> ::std::result::Result<
15        crate::operation::get_delegated_access_token::GetDelegatedAccessTokenOutput,
16        ::aws_smithy_runtime_api::client::result::SdkError<
17            crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError,
18            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
19        >,
20    > {
21        let map_err = |err: ::aws_smithy_runtime_api::client::result::SdkError<
22            ::aws_smithy_runtime_api::client::interceptors::context::Error,
23            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
24        >| {
25            err.map_service_error(|err| {
26                err.downcast::<crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError>()
27                    .expect("correct error type")
28            })
29        };
30        let context = Self::orchestrate_with_stop_point(runtime_plugins, input, ::aws_smithy_runtime::client::orchestrator::StopPoint::None)
31            .await
32            .map_err(map_err)?;
33        let output = context.finalize().map_err(map_err)?;
34        ::std::result::Result::Ok(
35            output
36                .downcast::<crate::operation::get_delegated_access_token::GetDelegatedAccessTokenOutput>()
37                .expect("correct output type"),
38        )
39    }
40
41    pub(crate) async fn orchestrate_with_stop_point(
42        runtime_plugins: &::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
43        input: crate::operation::get_delegated_access_token::GetDelegatedAccessTokenInput,
44        stop_point: ::aws_smithy_runtime::client::orchestrator::StopPoint,
45    ) -> ::std::result::Result<
46        ::aws_smithy_runtime_api::client::interceptors::context::InterceptorContext,
47        ::aws_smithy_runtime_api::client::result::SdkError<
48            ::aws_smithy_runtime_api::client::interceptors::context::Error,
49            ::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
50        >,
51    > {
52        let input = ::aws_smithy_runtime_api::client::interceptors::context::Input::erase(input);
53        use ::tracing::Instrument;
54        ::aws_smithy_runtime::client::orchestrator::invoke_with_stop_point("STS", "GetDelegatedAccessToken", input, runtime_plugins, stop_point)
55            // Create a parent span for the entire operation. Includes a random, internal-only,
56            // seven-digit ID for the operation orchestration so that it can be correlated in the logs.
57            .instrument(::tracing::debug_span!(
58                "STS.GetDelegatedAccessToken",
59                "rpc.service" = "STS",
60                "rpc.method" = "GetDelegatedAccessToken",
61                "sdk_invocation_id" = ::fastrand::u32(1_000_000..10_000_000),
62                "rpc.system" = "aws-api",
63            ))
64            .await
65    }
66
67    pub(crate) fn operation_runtime_plugins(
68        client_runtime_plugins: ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins,
69        client_config: &crate::config::Config,
70        config_override: ::std::option::Option<crate::config::Builder>,
71    ) -> ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugins {
72        let mut runtime_plugins = client_runtime_plugins.with_operation_plugin(Self::new());
73
74        if let ::std::option::Option::Some(config_override) = config_override {
75            for plugin in config_override.runtime_plugins.iter().cloned() {
76                runtime_plugins = runtime_plugins.with_operation_plugin(plugin);
77            }
78            runtime_plugins = runtime_plugins.with_operation_plugin(crate::config::ConfigOverrideRuntimePlugin::new(
79                config_override,
80                client_config.config.clone(),
81                &client_config.runtime_components,
82            ));
83        }
84        runtime_plugins
85    }
86}
87impl ::aws_smithy_runtime_api::client::runtime_plugin::RuntimePlugin for GetDelegatedAccessToken {
88    fn config(&self) -> ::std::option::Option<::aws_smithy_types::config_bag::FrozenLayer> {
89        let mut cfg = ::aws_smithy_types::config_bag::Layer::new("GetDelegatedAccessToken");
90
91        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedRequestSerializer::new(
92            GetDelegatedAccessTokenRequestSerializer,
93        ));
94        cfg.store_put(::aws_smithy_runtime_api::client::ser_de::SharedResponseDeserializer::new(
95            GetDelegatedAccessTokenResponseDeserializer,
96        ));
97
98        cfg.store_put(::aws_smithy_runtime_api::client::auth::AuthSchemeOptionResolverParams::new(
99            crate::config::auth::Params::builder()
100                .operation_name("GetDelegatedAccessToken")
101                .build()
102                .expect("required fields set"),
103        ));
104
105        cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::SensitiveOutput);
106        cfg.store_put(::aws_smithy_runtime_api::client::orchestrator::Metadata::new(
107            "GetDelegatedAccessToken",
108            "STS",
109        ));
110        let mut signing_options = ::aws_runtime::auth::SigningOptions::default();
111        signing_options.double_uri_encode = true;
112        signing_options.content_sha256_header = false;
113        signing_options.normalize_uri_path = true;
114        signing_options.payload_override = None;
115
116        cfg.store_put(::aws_runtime::auth::SigV4OperationSigningConfig {
117            signing_options,
118            ..::std::default::Default::default()
119        });
120
121        ::std::option::Option::Some(cfg.freeze())
122    }
123
124    fn runtime_components(
125        &self,
126        _: &::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder,
127    ) -> ::std::borrow::Cow<'_, ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder> {
128        #[allow(unused_mut)]
129        let mut rcb = ::aws_smithy_runtime_api::client::runtime_components::RuntimeComponentsBuilder::new("GetDelegatedAccessToken")
130            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
131                ::aws_smithy_runtime::client::stalled_stream_protection::StalledStreamProtectionInterceptor::default(),
132            ))
133            .with_interceptor(::aws_smithy_runtime_api::client::interceptors::SharedInterceptor::permanent(
134                GetDelegatedAccessTokenEndpointParamsInterceptor,
135            ))
136            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::TransientErrorClassifier::<
137                crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError,
138            >::new())
139            .with_retry_classifier(::aws_smithy_runtime::client::retries::classifiers::ModeledAsRetryableClassifier::<
140                crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError,
141            >::new())
142            .with_retry_classifier(
143                ::aws_runtime::retries::classifiers::AwsErrorCodeClassifier::<
144                    crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError,
145                >::builder()
146                .transient_errors({
147                    let mut transient_errors: Vec<&'static str> = ::aws_runtime::retries::classifiers::TRANSIENT_ERRORS.into();
148                    transient_errors.push("IDPCommunicationError");
149                    ::std::borrow::Cow::Owned(transient_errors)
150                })
151                .build(),
152            )
153            .with_retry_classifier(::aws_runtime::service_clock_skew::ServiceClockSkewClassifier::<
154                crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError,
155            >::new());
156
157        ::std::borrow::Cow::Owned(rcb)
158    }
159}
160
161#[derive(Debug)]
162struct GetDelegatedAccessTokenResponseDeserializer;
163impl ::aws_smithy_runtime_api::client::ser_de::DeserializeResponse for GetDelegatedAccessTokenResponseDeserializer {
164    fn deserialize_nonstreaming_with_config(
165        &self,
166        response: &::aws_smithy_runtime_api::client::orchestrator::HttpResponse,
167        _cfg: &::aws_smithy_types::config_bag::ConfigBag,
168    ) -> ::aws_smithy_runtime_api::client::interceptors::context::OutputOrError {
169        let (success, status) = (response.status().is_success(), response.status().as_u16());
170        let headers = response.headers();
171        let body = response.body().bytes().expect("body loaded");
172        #[allow(unused_mut)]
173        let mut force_error = false;
174        ::tracing::debug!(request_id = ?::aws_types::request_id::RequestId::request_id(response));
175        let parse_result = if !success && status != 200 || force_error {
176            crate::protocol_serde::shape_get_delegated_access_token::de_get_delegated_access_token_http_error(status, headers, body, _cfg)
177        } else {
178            crate::protocol_serde::shape_get_delegated_access_token::de_get_delegated_access_token_http_response(status, headers, body, _cfg)
179        };
180        crate::protocol_serde::type_erase_result(parse_result)
181    }
182}
183#[derive(Debug)]
184struct GetDelegatedAccessTokenRequestSerializer;
185impl ::aws_smithy_runtime_api::client::ser_de::SerializeRequest for GetDelegatedAccessTokenRequestSerializer {
186    #[allow(unused_mut, clippy::let_and_return, clippy::needless_borrow, clippy::useless_conversion)]
187    fn serialize_input(
188        &self,
189        input: ::aws_smithy_runtime_api::client::interceptors::context::Input,
190        _cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
191    ) -> ::std::result::Result<::aws_smithy_runtime_api::client::orchestrator::HttpRequest, ::aws_smithy_runtime_api::box_error::BoxError> {
192        let input = input
193            .downcast::<crate::operation::get_delegated_access_token::GetDelegatedAccessTokenInput>()
194            .expect("correct type");
195        let _header_serialization_settings = _cfg
196            .load::<crate::serialization_settings::HeaderSerializationSettings>()
197            .cloned()
198            .unwrap_or_default();
199        let mut request_builder = {
200            #[allow(clippy::uninlined_format_args)]
201            fn uri_base(
202                _input: &crate::operation::get_delegated_access_token::GetDelegatedAccessTokenInput,
203                output: &mut ::std::string::String,
204            ) -> ::std::result::Result<(), ::aws_smithy_types::error::operation::BuildError> {
205                use ::std::fmt::Write as _;
206                ::std::write!(output, "/").expect("formatting should succeed");
207                ::std::result::Result::Ok(())
208            }
209            #[allow(clippy::unnecessary_wraps)]
210            fn update_http_builder(
211                input: &crate::operation::get_delegated_access_token::GetDelegatedAccessTokenInput,
212                builder: ::http_1x::request::Builder,
213            ) -> ::std::result::Result<::http_1x::request::Builder, ::aws_smithy_types::error::operation::BuildError> {
214                let mut uri = ::std::string::String::new();
215                uri_base(input, &mut uri)?;
216                ::std::result::Result::Ok(builder.method("POST").uri(uri))
217            }
218            let mut builder = update_http_builder(&input, ::http_1x::request::Builder::new())?;
219            builder =
220                _header_serialization_settings.set_default_header(builder, ::http_1x::header::CONTENT_TYPE, "application/x-www-form-urlencoded");
221            builder
222        };
223        let body = ::aws_smithy_types::body::SdkBody::from(
224            crate::protocol_serde::shape_get_delegated_access_token_input::ser_get_delegated_access_token_input_input_input(&input)?,
225        );
226        if let Some(content_length) = body.content_length() {
227            let content_length = content_length.to_string();
228            request_builder = _header_serialization_settings.set_default_header(request_builder, ::http_1x::header::CONTENT_LENGTH, &content_length);
229        }
230        ::std::result::Result::Ok(request_builder.body(body).expect("valid request").try_into().unwrap())
231    }
232}
233#[derive(Debug)]
234struct GetDelegatedAccessTokenEndpointParamsInterceptor;
235
236#[::aws_smithy_runtime_api::client::interceptors::dyn_dispatch_hint]
237impl ::aws_smithy_runtime_api::client::interceptors::Intercept for GetDelegatedAccessTokenEndpointParamsInterceptor {
238    fn name(&self) -> &'static str {
239        "GetDelegatedAccessTokenEndpointParamsInterceptor"
240    }
241
242    fn read_before_execution(
243        &self,
244        context: &::aws_smithy_runtime_api::client::interceptors::context::BeforeSerializationInterceptorContextRef<
245            '_,
246            ::aws_smithy_runtime_api::client::interceptors::context::Input,
247            ::aws_smithy_runtime_api::client::interceptors::context::Output,
248            ::aws_smithy_runtime_api::client::interceptors::context::Error,
249        >,
250        cfg: &mut ::aws_smithy_types::config_bag::ConfigBag,
251    ) -> ::std::result::Result<(), ::aws_smithy_runtime_api::box_error::BoxError> {
252        let _input = context
253            .input()
254            .downcast_ref::<GetDelegatedAccessTokenInput>()
255            .ok_or("failed to downcast to GetDelegatedAccessTokenInput")?;
256
257        let params = crate::config::endpoint::Params::builder()
258            .set_region(cfg.load::<::aws_types::region::Region>().map(|r| r.as_ref().to_owned()))
259            .set_use_dual_stack(cfg.load::<::aws_types::endpoint_config::UseDualStack>().map(|ty| ty.0))
260            .set_use_fips(cfg.load::<::aws_types::endpoint_config::UseFips>().map(|ty| ty.0))
261            .set_endpoint(cfg.load::<::aws_types::endpoint_config::EndpointUrl>().map(|ty| ty.0.clone()))
262            .build()
263            .map_err(|err| {
264                ::aws_smithy_runtime_api::client::interceptors::error::ContextAttachedError::new("endpoint params could not be built", err)
265            })?;
266        cfg.interceptor_state()
267            .store_put(::aws_smithy_runtime_api::client::endpoint::EndpointResolverParams::new(params));
268        ::std::result::Result::Ok(())
269    }
270}
271
272// The get_* functions below are generated from JMESPath expressions in the
273// operationContextParams trait. They target the operation's input shape.
274
275/// Error type for the `GetDelegatedAccessTokenError` operation.
276#[non_exhaustive]
277#[derive(::std::fmt::Debug)]
278pub enum GetDelegatedAccessTokenError {
279    /// <p>The trade-in token provided in the request has expired and can no longer be exchanged for credentials. Request a new token and retry the operation.</p>
280    ExpiredTradeInTokenException(crate::types::error::ExpiredTradeInTokenException),
281    /// <p>The request was rejected because the total packed size of the session policies and session tags combined was too large. An Amazon Web Services conversion compresses the session policy document, session policy ARNs, and session tags into a packed binary format that has a separate limit. The error message indicates by percentage how close the policies and tags are to the upper size limit. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_session-tags.html">Passing Session Tags in STS</a> in the <i>IAM User Guide</i>.</p>
282    /// <p>You could receive this error even though you meet other defined session policy and session tag limits. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/reference_iam-quotas.html#reference_iam-limits-entity-length">IAM and STS Entity Character Limits</a> in the <i>IAM User Guide</i>.</p>
283    PackedPolicyTooLargeException(crate::types::error::PackedPolicyTooLargeException),
284    /// <p>STS is not activated in the requested region for the account that is being asked to generate credentials. The account administrator must use the IAM console to activate STS in that region. For more information, see <a href="https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentials_temp_enable-regions.html#sts-regions-activate-deactivate">Activating and Deactivating STS in an Amazon Web Services Region</a> in the <i>IAM User Guide</i>.</p>
285    RegionDisabledException(crate::types::error::RegionDisabledException),
286    /// An unexpected error occurred (e.g., invalid JSON returned by the service or an unknown error code).
287    #[deprecated(note = "Matching `Unhandled` directly is not forwards compatible. Instead, match using a \
288    variable wildcard pattern and check `.code()`:
289     \
290    &nbsp;&nbsp;&nbsp;`err if err.code() == Some(\"SpecificExceptionCode\") => { /* handle the error */ }`
291     \
292    See [`ProvideErrorMetadata`](#impl-ProvideErrorMetadata-for-GetDelegatedAccessTokenError) for what information is available for the error.")]
293    Unhandled(crate::error::sealed_unhandled::Unhandled),
294}
295impl GetDelegatedAccessTokenError {
296    /// Creates the `GetDelegatedAccessTokenError::Unhandled` variant from any error type.
297    pub fn unhandled(
298        err: impl ::std::convert::Into<::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>>,
299    ) -> Self {
300        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
301            source: err.into(),
302            meta: ::std::default::Default::default(),
303        })
304    }
305
306    /// Creates the `GetDelegatedAccessTokenError::Unhandled` variant from an [`ErrorMetadata`](::aws_smithy_types::error::ErrorMetadata).
307    pub fn generic(err: ::aws_smithy_types::error::ErrorMetadata) -> Self {
308        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
309            source: err.clone().into(),
310            meta: err,
311        })
312    }
313    ///
314    /// Returns error metadata, which includes the error code, message,
315    /// request ID, and potentially additional information.
316    ///
317    pub fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
318        match self {
319            Self::ExpiredTradeInTokenException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
320            Self::PackedPolicyTooLargeException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
321            Self::RegionDisabledException(e) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(e),
322            Self::Unhandled(e) => &e.meta,
323        }
324    }
325    /// Returns `true` if the error kind is `GetDelegatedAccessTokenError::ExpiredTradeInTokenException`.
326    pub fn is_expired_trade_in_token_exception(&self) -> bool {
327        matches!(self, Self::ExpiredTradeInTokenException(_))
328    }
329    /// Returns `true` if the error kind is `GetDelegatedAccessTokenError::PackedPolicyTooLargeException`.
330    pub fn is_packed_policy_too_large_exception(&self) -> bool {
331        matches!(self, Self::PackedPolicyTooLargeException(_))
332    }
333    /// Returns `true` if the error kind is `GetDelegatedAccessTokenError::RegionDisabledException`.
334    pub fn is_region_disabled_exception(&self) -> bool {
335        matches!(self, Self::RegionDisabledException(_))
336    }
337}
338impl ::std::error::Error for GetDelegatedAccessTokenError {
339    fn source(&self) -> ::std::option::Option<&(dyn ::std::error::Error + 'static)> {
340        match self {
341            Self::ExpiredTradeInTokenException(_inner) => ::std::option::Option::Some(_inner),
342            Self::PackedPolicyTooLargeException(_inner) => ::std::option::Option::Some(_inner),
343            Self::RegionDisabledException(_inner) => ::std::option::Option::Some(_inner),
344            Self::Unhandled(_inner) => ::std::option::Option::Some(&*_inner.source),
345        }
346    }
347}
348impl ::std::fmt::Display for GetDelegatedAccessTokenError {
349    fn fmt(&self, f: &mut ::std::fmt::Formatter<'_>) -> ::std::fmt::Result {
350        match self {
351            Self::ExpiredTradeInTokenException(_inner) => _inner.fmt(f),
352            Self::PackedPolicyTooLargeException(_inner) => _inner.fmt(f),
353            Self::RegionDisabledException(_inner) => _inner.fmt(f),
354            Self::Unhandled(_inner) => {
355                if let ::std::option::Option::Some(code) = ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self) {
356                    write!(f, "unhandled error ({code})")
357                } else {
358                    f.write_str("unhandled error")
359                }
360            }
361        }
362    }
363}
364impl ::aws_smithy_types::retry::ProvideErrorKind for GetDelegatedAccessTokenError {
365    fn code(&self) -> ::std::option::Option<&str> {
366        ::aws_smithy_types::error::metadata::ProvideErrorMetadata::code(self)
367    }
368    fn retryable_error_kind(&self) -> ::std::option::Option<::aws_smithy_types::retry::ErrorKind> {
369        ::std::option::Option::None
370    }
371}
372impl ::aws_smithy_types::error::metadata::ProvideErrorMetadata for GetDelegatedAccessTokenError {
373    fn meta(&self) -> &::aws_smithy_types::error::ErrorMetadata {
374        match self {
375            Self::ExpiredTradeInTokenException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
376            Self::PackedPolicyTooLargeException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
377            Self::RegionDisabledException(_inner) => ::aws_smithy_types::error::metadata::ProvideErrorMetadata::meta(_inner),
378            Self::Unhandled(_inner) => &_inner.meta,
379        }
380    }
381}
382impl ::aws_smithy_runtime_api::client::result::CreateUnhandledError for GetDelegatedAccessTokenError {
383    fn create_unhandled_error(
384        source: ::std::boxed::Box<dyn ::std::error::Error + ::std::marker::Send + ::std::marker::Sync + 'static>,
385        meta: ::std::option::Option<::aws_smithy_types::error::ErrorMetadata>,
386    ) -> Self {
387        Self::Unhandled(crate::error::sealed_unhandled::Unhandled {
388            source,
389            meta: meta.unwrap_or_default(),
390        })
391    }
392}
393impl ::aws_types::request_id::RequestId for crate::operation::get_delegated_access_token::GetDelegatedAccessTokenError {
394    fn request_id(&self) -> Option<&str> {
395        self.meta().request_id()
396    }
397}
398
399pub use crate::operation::get_delegated_access_token::_get_delegated_access_token_input::GetDelegatedAccessTokenInput;
400
401pub use crate::operation::get_delegated_access_token::_get_delegated_access_token_output::GetDelegatedAccessTokenOutput;
402
403mod _get_delegated_access_token_input;
404
405mod _get_delegated_access_token_output;
406
407/// Builders
408pub mod builders;