| 123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107 |
- /*
- * Copyright 2009-2017 Alibaba Cloud All rights reserved.
- *
- * Licensed under the Apache License, Version 2.0 (the "License");
- * you may not use this file except in compliance with the License.
- * You may obtain a copy of the License at
- *
- * http://www.apache.org/licenses/LICENSE-2.0
- *
- * Unless required by applicable law or agreed to in writing, software
- * distributed under the License is distributed on an "AS IS" BASIS,
- * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
- * See the License for the specific language governing permissions and
- * limitations under the License.
- */
- #include <alibabacloud/core/InstanceProfileCredentialsProvider.h>
- #include <chrono>
- #include <iomanip>
- #include <chrono>
- #include <mutex>
- #include <sstream>
- #include <json/json.h>
- #include "EcsMetadataFetcher.h"
- using namespace AlibabaCloud;
- InstanceProfileCredentialsProvider::InstanceProfileCredentialsProvider(const std::string & roleName, int durationSeconds):
- CredentialsProvider(),
- durationSeconds_(durationSeconds),
- cachedMutex_(),
- cachedCredentials_("", ""),
- fetcher_(new EcsMetadataFetcher),
- expiry_()
- {
- fetcher_->setRoleName(roleName);
- }
- InstanceProfileCredentialsProvider::~InstanceProfileCredentialsProvider()
- {
- delete fetcher_;
- }
- std::string InstanceProfileCredentialsProvider::roleName()const
- {
- return fetcher_->roleName();
- }
- Credentials InstanceProfileCredentialsProvider::getCredentials()
- {
- loadCredentials();
- std::lock_guard<std::mutex> locker(cachedMutex_);
- return cachedCredentials_;
- }
- bool InstanceProfileCredentialsProvider::checkExpiry()const
- {
- auto now = std::chrono::system_clock::now();
- auto diff = std::chrono::duration_cast<std::chrono::seconds>(now - expiry_).count();
- return (diff > 0 - 60);
- }
- void InstanceProfileCredentialsProvider::loadCredentials()
- {
- if (checkExpiry())
- {
- std::lock_guard<std::mutex> locker(cachedMutex_);
- if (checkExpiry())
- {
- auto outcome = fetcher_->getMetadata();
- Json::Value value;
- Json::Reader reader;
- if (reader.parse(outcome, value))
- {
- if (value["Code"] == nullptr
- &&value["AccessKeyId"] == nullptr
- &&value["AccessKeySecret"] == nullptr
- &&value["SecurityToken"] == nullptr
- &&value["Expiration"] == nullptr)
- {
- cachedCredentials_ = Credentials("","");
- return;
- }
- auto code = value["Code"].asString();
- auto accessKeyId = value["AccessKeyId"].asString();
- auto accessKeySecret = value["AccessKeySecret"].asString();
- auto securityToken = value["SecurityToken"].asString();
- auto expiration = value["Expiration"].asString();
- cachedCredentials_ = Credentials(accessKeyId,
- accessKeySecret,
- securityToken);
- std::tm tm = {};
- #if defined(__GNUG__) && __GNUC__ < 5
- strptime(expiration.c_str(), "%Y-%m-%dT%H:%M:%SZ", &tm);
- #else
- std::stringstream ss(expiration);
- ss >> std::get_time(&tm, "%Y-%m-%dT%H:%M:%SZ");
- #endif
- expiry_ = std::chrono::system_clock::from_time_t(std::mktime(&tm));
- }
- }
- }
- }
|