Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat(object_store): Add support for session token (STS) in AWS credentials #50702

Conversation

refucktor
Copy link
Contributor

@refucktor refucktor commented Feb 6, 2025

Summary

Support using a Session Token for temporal AWS Credentials

Checklist

- Pass session token, either null or with value, to the AWS Credentials constructor

Signed-off-by: Hector Valcarcel <hmvalcarcel@gmail.com>
@refucktor refucktor force-pushed the feat/support-aws-session-token branch from fcea40d to 6b4c859 Compare February 6, 2025 15:24
@joshtrichards joshtrichards added enhancement feature: object storage 3. to review Waiting for reviews pending documentation This pull request needs an associated documentation update labels Feb 6, 2025
@joshtrichards
Copy link
Member

I wonder what it'd take to add an integration test for this... 🤔

https://min.io/docs/minio/linux/developers/security-token-service.html
https://github.com/minio/minio/tree/master/docs/sts

@joshtrichards joshtrichards changed the title Add support for session token in AWS credentials feat(object_store): Add support for session token (STS) in AWS credentials Feb 6, 2025
@joshtrichards
Copy link
Member

How does the expiration/rotation of STS credentials work here given that the Nextcloud use case for S3 is ongoing not temporary?

@refucktor
Copy link
Contributor Author

@joshtrichards that could be an interesting step. However, I would recommend trying a different direction for the integration tests, something like a combination of:

then you can manage all the outside platforms directly via code 😉

Copy link
Contributor

Hello there,
Thank you so much for taking the time and effort to create a pull request to our Nextcloud project.

We hope that the review process is going smooth and is helpful for you. We want to ensure your pull request is reviewed to your satisfaction. If you have a moment, our community management team would very much appreciate your feedback on your experience with this PR review process.

Your feedback is valuable to us as we continuously strive to improve our community developer experience. Please take a moment to complete our short survey by clicking on the following link: https://cloud.nextcloud.com/apps/forms/s/i9Ago4EQRZ7TWxjfmeEpPkf6

Thank you for contributing to Nextcloud and we hope to hear from you soon!

(If you believe you should not receive this message, you can add yourself to the blocklist.)

@susnux susnux added this to the Nextcloud 32 milestone Mar 2, 2025
Copy link
Member

@icewind1991 icewind1991 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I don't know enough about S3 to judge the use case, but the code itself seems fine

@refucktor refucktor requested a review from a team as a code owner March 4, 2025 17:27
@refucktor refucktor requested review from artonge, nfebe and provokateurin and removed request for a team March 4, 2025 17:27
@artonge artonge added 4. to release Ready to be released and/or waiting for tests to finish and removed 3. to review Waiting for reviews labels Mar 5, 2025
@nextcloud nextcloud deleted a comment from backportbot bot Mar 5, 2025
@AndyScherzinger AndyScherzinger merged commit fdb246c into nextcloud:master Mar 5, 2025
177 of 180 checks passed
Copy link

welcome bot commented Mar 5, 2025

Thanks for your first pull request and welcome to the community! Feel free to keep them coming! If you are looking for issues to tackle then have a look at this selection: https://github.com/nextcloud/server/issues?q=is%3Aopen+is%3Aissue+label%3A%22good+first+issue%22

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
4. to release Ready to be released and/or waiting for tests to finish backport-request enhancement feature: object storage feedback-requested pending documentation This pull request needs an associated documentation update
Projects
None yet
6 participants