mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
Start docs for AWS IAM auth
This commit is contained in:
Generated
+406
-258
@@ -1207,6 +1207,58 @@
|
|||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/@aws-sdk/client-secrets-manager/node_modules/@aws-sdk/client-sts": {
|
||||||
|
"version": "3.504.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-sdk/client-sts/-/client-sts-3.504.0.tgz",
|
||||||
|
"integrity": "sha512-IESs8FkL7B/uY+ml4wgoRkrr6xYo4PizcNw6JX17eveq1gRBCPKeGMjE6HTDOcIYZZ8rqz/UeuH3JD4UhrMOnA==",
|
||||||
|
"dependencies": {
|
||||||
|
"@aws-crypto/sha256-browser": "3.0.0",
|
||||||
|
"@aws-crypto/sha256-js": "3.0.0",
|
||||||
|
"@aws-sdk/core": "3.496.0",
|
||||||
|
"@aws-sdk/middleware-host-header": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-logger": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-recursion-detection": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-user-agent": "3.502.0",
|
||||||
|
"@aws-sdk/region-config-resolver": "3.502.0",
|
||||||
|
"@aws-sdk/types": "3.502.0",
|
||||||
|
"@aws-sdk/util-endpoints": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-browser": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-node": "3.502.0",
|
||||||
|
"@smithy/config-resolver": "^2.1.1",
|
||||||
|
"@smithy/core": "^1.3.1",
|
||||||
|
"@smithy/fetch-http-handler": "^2.4.1",
|
||||||
|
"@smithy/hash-node": "^2.1.1",
|
||||||
|
"@smithy/invalid-dependency": "^2.1.1",
|
||||||
|
"@smithy/middleware-content-length": "^2.1.1",
|
||||||
|
"@smithy/middleware-endpoint": "^2.4.1",
|
||||||
|
"@smithy/middleware-retry": "^2.1.1",
|
||||||
|
"@smithy/middleware-serde": "^2.1.1",
|
||||||
|
"@smithy/middleware-stack": "^2.1.1",
|
||||||
|
"@smithy/node-config-provider": "^2.2.1",
|
||||||
|
"@smithy/node-http-handler": "^2.3.1",
|
||||||
|
"@smithy/protocol-http": "^3.1.1",
|
||||||
|
"@smithy/smithy-client": "^2.3.1",
|
||||||
|
"@smithy/types": "^2.9.1",
|
||||||
|
"@smithy/url-parser": "^2.1.1",
|
||||||
|
"@smithy/util-base64": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-browser": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-node": "^2.2.1",
|
||||||
|
"@smithy/util-defaults-mode-browser": "^2.1.1",
|
||||||
|
"@smithy/util-defaults-mode-node": "^2.1.1",
|
||||||
|
"@smithy/util-endpoints": "^1.1.1",
|
||||||
|
"@smithy/util-middleware": "^2.1.1",
|
||||||
|
"@smithy/util-retry": "^2.1.1",
|
||||||
|
"@smithy/util-utf8": "^2.1.1",
|
||||||
|
"fast-xml-parser": "4.2.5",
|
||||||
|
"tslib": "^2.5.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=14.0.0"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"@aws-sdk/credential-provider-node": "^3.504.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/@aws-sdk/client-secrets-manager/node_modules/uuid": {
|
"node_modules/@aws-sdk/client-secrets-manager/node_modules/uuid": {
|
||||||
"version": "8.3.2",
|
"version": "8.3.2",
|
||||||
"resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz",
|
"resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz",
|
||||||
@@ -1314,7 +1366,7 @@
|
|||||||
"@aws-sdk/credential-provider-node": "^3.504.0"
|
"@aws-sdk/credential-provider-node": "^3.504.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@aws-sdk/client-sts": {
|
"node_modules/@aws-sdk/client-sso-oidc/node_modules/@aws-sdk/client-sts": {
|
||||||
"version": "3.504.0",
|
"version": "3.504.0",
|
||||||
"resolved": "https://registry.npmjs.org/@aws-sdk/client-sts/-/client-sts-3.504.0.tgz",
|
"resolved": "https://registry.npmjs.org/@aws-sdk/client-sts/-/client-sts-3.504.0.tgz",
|
||||||
"integrity": "sha512-IESs8FkL7B/uY+ml4wgoRkrr6xYo4PizcNw6JX17eveq1gRBCPKeGMjE6HTDOcIYZZ8rqz/UeuH3JD4UhrMOnA==",
|
"integrity": "sha512-IESs8FkL7B/uY+ml4wgoRkrr6xYo4PizcNw6JX17eveq1gRBCPKeGMjE6HTDOcIYZZ8rqz/UeuH3JD4UhrMOnA==",
|
||||||
@@ -1436,6 +1488,58 @@
|
|||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/@aws-sdk/credential-provider-ini/node_modules/@aws-sdk/client-sts": {
|
||||||
|
"version": "3.504.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-sdk/client-sts/-/client-sts-3.504.0.tgz",
|
||||||
|
"integrity": "sha512-IESs8FkL7B/uY+ml4wgoRkrr6xYo4PizcNw6JX17eveq1gRBCPKeGMjE6HTDOcIYZZ8rqz/UeuH3JD4UhrMOnA==",
|
||||||
|
"dependencies": {
|
||||||
|
"@aws-crypto/sha256-browser": "3.0.0",
|
||||||
|
"@aws-crypto/sha256-js": "3.0.0",
|
||||||
|
"@aws-sdk/core": "3.496.0",
|
||||||
|
"@aws-sdk/middleware-host-header": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-logger": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-recursion-detection": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-user-agent": "3.502.0",
|
||||||
|
"@aws-sdk/region-config-resolver": "3.502.0",
|
||||||
|
"@aws-sdk/types": "3.502.0",
|
||||||
|
"@aws-sdk/util-endpoints": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-browser": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-node": "3.502.0",
|
||||||
|
"@smithy/config-resolver": "^2.1.1",
|
||||||
|
"@smithy/core": "^1.3.1",
|
||||||
|
"@smithy/fetch-http-handler": "^2.4.1",
|
||||||
|
"@smithy/hash-node": "^2.1.1",
|
||||||
|
"@smithy/invalid-dependency": "^2.1.1",
|
||||||
|
"@smithy/middleware-content-length": "^2.1.1",
|
||||||
|
"@smithy/middleware-endpoint": "^2.4.1",
|
||||||
|
"@smithy/middleware-retry": "^2.1.1",
|
||||||
|
"@smithy/middleware-serde": "^2.1.1",
|
||||||
|
"@smithy/middleware-stack": "^2.1.1",
|
||||||
|
"@smithy/node-config-provider": "^2.2.1",
|
||||||
|
"@smithy/node-http-handler": "^2.3.1",
|
||||||
|
"@smithy/protocol-http": "^3.1.1",
|
||||||
|
"@smithy/smithy-client": "^2.3.1",
|
||||||
|
"@smithy/types": "^2.9.1",
|
||||||
|
"@smithy/url-parser": "^2.1.1",
|
||||||
|
"@smithy/util-base64": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-browser": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-node": "^2.2.1",
|
||||||
|
"@smithy/util-defaults-mode-browser": "^2.1.1",
|
||||||
|
"@smithy/util-defaults-mode-node": "^2.1.1",
|
||||||
|
"@smithy/util-endpoints": "^1.1.1",
|
||||||
|
"@smithy/util-middleware": "^2.1.1",
|
||||||
|
"@smithy/util-retry": "^2.1.1",
|
||||||
|
"@smithy/util-utf8": "^2.1.1",
|
||||||
|
"fast-xml-parser": "4.2.5",
|
||||||
|
"tslib": "^2.5.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=14.0.0"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"@aws-sdk/credential-provider-node": "^3.504.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/@aws-sdk/credential-provider-node": {
|
"node_modules/@aws-sdk/credential-provider-node": {
|
||||||
"version": "3.504.0",
|
"version": "3.504.0",
|
||||||
"resolved": "https://registry.npmjs.org/@aws-sdk/credential-provider-node/-/credential-provider-node-3.504.0.tgz",
|
"resolved": "https://registry.npmjs.org/@aws-sdk/credential-provider-node/-/credential-provider-node-3.504.0.tgz",
|
||||||
@@ -1505,6 +1609,58 @@
|
|||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
|
"node_modules/@aws-sdk/credential-provider-web-identity/node_modules/@aws-sdk/client-sts": {
|
||||||
|
"version": "3.504.0",
|
||||||
|
"resolved": "https://registry.npmjs.org/@aws-sdk/client-sts/-/client-sts-3.504.0.tgz",
|
||||||
|
"integrity": "sha512-IESs8FkL7B/uY+ml4wgoRkrr6xYo4PizcNw6JX17eveq1gRBCPKeGMjE6HTDOcIYZZ8rqz/UeuH3JD4UhrMOnA==",
|
||||||
|
"dependencies": {
|
||||||
|
"@aws-crypto/sha256-browser": "3.0.0",
|
||||||
|
"@aws-crypto/sha256-js": "3.0.0",
|
||||||
|
"@aws-sdk/core": "3.496.0",
|
||||||
|
"@aws-sdk/middleware-host-header": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-logger": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-recursion-detection": "3.502.0",
|
||||||
|
"@aws-sdk/middleware-user-agent": "3.502.0",
|
||||||
|
"@aws-sdk/region-config-resolver": "3.502.0",
|
||||||
|
"@aws-sdk/types": "3.502.0",
|
||||||
|
"@aws-sdk/util-endpoints": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-browser": "3.502.0",
|
||||||
|
"@aws-sdk/util-user-agent-node": "3.502.0",
|
||||||
|
"@smithy/config-resolver": "^2.1.1",
|
||||||
|
"@smithy/core": "^1.3.1",
|
||||||
|
"@smithy/fetch-http-handler": "^2.4.1",
|
||||||
|
"@smithy/hash-node": "^2.1.1",
|
||||||
|
"@smithy/invalid-dependency": "^2.1.1",
|
||||||
|
"@smithy/middleware-content-length": "^2.1.1",
|
||||||
|
"@smithy/middleware-endpoint": "^2.4.1",
|
||||||
|
"@smithy/middleware-retry": "^2.1.1",
|
||||||
|
"@smithy/middleware-serde": "^2.1.1",
|
||||||
|
"@smithy/middleware-stack": "^2.1.1",
|
||||||
|
"@smithy/node-config-provider": "^2.2.1",
|
||||||
|
"@smithy/node-http-handler": "^2.3.1",
|
||||||
|
"@smithy/protocol-http": "^3.1.1",
|
||||||
|
"@smithy/smithy-client": "^2.3.1",
|
||||||
|
"@smithy/types": "^2.9.1",
|
||||||
|
"@smithy/url-parser": "^2.1.1",
|
||||||
|
"@smithy/util-base64": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-browser": "^2.1.1",
|
||||||
|
"@smithy/util-body-length-node": "^2.2.1",
|
||||||
|
"@smithy/util-defaults-mode-browser": "^2.1.1",
|
||||||
|
"@smithy/util-defaults-mode-node": "^2.1.1",
|
||||||
|
"@smithy/util-endpoints": "^1.1.1",
|
||||||
|
"@smithy/util-middleware": "^2.1.1",
|
||||||
|
"@smithy/util-retry": "^2.1.1",
|
||||||
|
"@smithy/util-utf8": "^2.1.1",
|
||||||
|
"fast-xml-parser": "4.2.5",
|
||||||
|
"tslib": "^2.5.0"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">=14.0.0"
|
||||||
|
},
|
||||||
|
"peerDependencies": {
|
||||||
|
"@aws-sdk/credential-provider-node": "^3.504.0"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/@aws-sdk/middleware-host-header": {
|
"node_modules/@aws-sdk/middleware-host-header": {
|
||||||
"version": "3.502.0",
|
"version": "3.502.0",
|
||||||
"resolved": "https://registry.npmjs.org/@aws-sdk/middleware-host-header/-/middleware-host-header-3.502.0.tgz",
|
"resolved": "https://registry.npmjs.org/@aws-sdk/middleware-host-header/-/middleware-host-header-3.502.0.tgz",
|
||||||
@@ -3657,60 +3813,60 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/abort-controller": {
|
"node_modules/@smithy/abort-controller": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/abort-controller/-/abort-controller-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/abort-controller/-/abort-controller-2.2.0.tgz",
|
||||||
"integrity": "sha512-c2aYH2Wu1RVE3rLlVgg2kQOBJGM0WbjReQi5DnPTm2Zb7F0gk7J2aeQeaX2u/lQZoHl6gv8Oac7mt9alU3+f4A==",
|
"integrity": "sha512-wRlta7GuLWpTqtFfGo+nZyOO1vEvewdNR1R4rTxpC8XU6vG/NDyrFBhwLZsqg1NUoR1noVaXJPC/7ZK47QCySw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/config-resolver": {
|
"node_modules/@smithy/config-resolver": {
|
||||||
"version": "2.1.4",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/config-resolver/-/config-resolver-2.1.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/config-resolver/-/config-resolver-2.2.0.tgz",
|
||||||
"integrity": "sha512-AW2WUZmBAzgO3V3ovKtsUbI3aBNMeQKFDumoqkNxaVDWF/xfnxAWqBKDr/NuG7c06N2Rm4xeZLPiJH/d+na0HA==",
|
"integrity": "sha512-fsiMgd8toyUba6n1WRmr+qACzXltpdDkPTAaDqc8QqPBUzO+/JKwL6bUBseHVi8tu9l+3JOK+tSf7cay+4B3LA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-config-provider": "^2.2.1",
|
"@smithy/util-config-provider": "^2.3.0",
|
||||||
"@smithy/util-middleware": "^2.1.3",
|
"@smithy/util-middleware": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/core": {
|
"node_modules/@smithy/core": {
|
||||||
"version": "1.3.5",
|
"version": "1.4.2",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/core/-/core-1.3.5.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/core/-/core-1.4.2.tgz",
|
||||||
"integrity": "sha512-Rrc+e2Jj6Gu7Xbn0jvrzZlSiP2CZocIOfZ9aNUA82+1sa6GBnxqL9+iZ9EKHeD9aqD1nU8EK4+oN2EiFpSv7Yw==",
|
"integrity": "sha512-2fek3I0KZHWJlRLvRTqxTEri+qV0GRHrJIoLFuBMZB4EMg4WgeBGfF0X6abnrNYpq55KJ6R4D6x4f0vLnhzinA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/middleware-endpoint": "^2.4.4",
|
"@smithy/middleware-endpoint": "^2.5.1",
|
||||||
"@smithy/middleware-retry": "^2.1.4",
|
"@smithy/middleware-retry": "^2.3.1",
|
||||||
"@smithy/middleware-serde": "^2.1.3",
|
"@smithy/middleware-serde": "^2.3.0",
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/smithy-client": "^2.4.2",
|
"@smithy/smithy-client": "^2.5.1",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-middleware": "^2.1.3",
|
"@smithy/util-middleware": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/credential-provider-imds": {
|
"node_modules/@smithy/credential-provider-imds": {
|
||||||
"version": "2.2.4",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/credential-provider-imds/-/credential-provider-imds-2.2.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/credential-provider-imds/-/credential-provider-imds-2.3.0.tgz",
|
||||||
"integrity": "sha512-DdatjmBZQnhGe1FhI8gO98f7NmvQFSDiZTwC3WMvLTCKQUY+Y1SVkhJqIuLu50Eb7pTheoXQmK+hKYUgpUWsNA==",
|
"integrity": "sha512-BWB9mIukO1wjEOo1Ojgl6LrG4avcaC7T/ZP6ptmAaW4xluhSIPZhY+/PI5YKzlk+jsm+4sQZB45Bt1OfMeQa3w==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/property-provider": "^2.1.3",
|
"@smithy/property-provider": "^2.2.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/url-parser": "^2.1.3",
|
"@smithy/url-parser": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
@@ -3779,459 +3935,451 @@
|
|||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/fetch-http-handler": {
|
"node_modules/@smithy/fetch-http-handler": {
|
||||||
"version": "2.4.3",
|
"version": "2.5.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/fetch-http-handler/-/fetch-http-handler-2.4.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/fetch-http-handler/-/fetch-http-handler-2.5.0.tgz",
|
||||||
"integrity": "sha512-Fn/KYJFo6L5I4YPG8WQb2hOmExgRmNpVH5IK2zU3JKrY5FKW7y9ar5e0BexiIC9DhSKqKX+HeWq/Y18fq7Dkpw==",
|
"integrity": "sha512-BOWEBeppWhLn/no/JxUL/ghTfANTjT7kg3Ww2rPqTUY9R4yHPXxJ9JhMe3Z03LN3aPwiwlpDIUcVw1xDyHqEhw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/querystring-builder": "^2.1.3",
|
"@smithy/querystring-builder": "^2.2.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-base64": "^2.1.1",
|
"@smithy/util-base64": "^2.3.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/hash-node": {
|
"node_modules/@smithy/hash-node": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/hash-node/-/hash-node-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/hash-node/-/hash-node-2.2.0.tgz",
|
||||||
"integrity": "sha512-FsAPCUj7VNJIdHbSxMd5uiZiF20G2zdSDgrgrDrHqIs/VMxK85Vqk5kMVNNDMCZmMezp6UKnac0B4nAyx7HJ9g==",
|
"integrity": "sha512-zLWaC/5aWpMrHKpoDF6nqpNtBhlAYKF/7+9yMN7GpdR8CzohnWfGtMznPybnwSS8saaXBMxIGwJqR4HmRp6b3g==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-buffer-from": "^2.1.1",
|
"@smithy/util-buffer-from": "^2.2.0",
|
||||||
"@smithy/util-utf8": "^2.1.1",
|
"@smithy/util-utf8": "^2.3.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/invalid-dependency": {
|
"node_modules/@smithy/invalid-dependency": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/invalid-dependency/-/invalid-dependency-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/invalid-dependency/-/invalid-dependency-2.2.0.tgz",
|
||||||
"integrity": "sha512-wkra7d/G4CbngV4xsjYyAYOvdAhahQje/WymuQdVEnXFExJopEu7fbL5AEAlBPgWHXwu94VnCSG00gVzRfExyg==",
|
"integrity": "sha512-nEDASdbKFKPXN2O6lOlTgrEEOO9NHIeO+HVvZnkqc8h5U9g3BIhWsvzFo+UcUbliMHvKNPD/zVxDrkP1Sbgp8Q==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/is-array-buffer": {
|
"node_modules/@smithy/is-array-buffer": {
|
||||||
"version": "2.1.1",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/is-array-buffer/-/is-array-buffer-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/is-array-buffer/-/is-array-buffer-2.2.0.tgz",
|
||||||
"integrity": "sha512-xozSQrcUinPpNPNPds4S7z/FakDTh1MZWtRP/2vQtYB/u3HYrX2UXuZs+VhaKBd6Vc7g2XPr2ZtwGBNDN6fNKQ==",
|
"integrity": "sha512-GGP3O9QFD24uGeAXYUjwSTXARoqpZykHadOmA8G5vfJPK0/DC67qa//0qvqrJzL1xc8WQWX7/yc7fwudjPHPhA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/middleware-content-length": {
|
"node_modules/@smithy/middleware-content-length": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/middleware-content-length/-/middleware-content-length-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/middleware-content-length/-/middleware-content-length-2.2.0.tgz",
|
||||||
"integrity": "sha512-aJduhkC+dcXxdnv5ZpM3uMmtGmVFKx412R1gbeykS5HXDmRU6oSsyy2SoHENCkfOGKAQOjVE2WVqDJibC0d21g==",
|
"integrity": "sha512-5bl2LG1Ah/7E5cMSC+q+h3IpVHMeOkG0yLRyQT1p2aMJkSrZG7RlXHPuAgb7EyaFeidKEnnd/fNaLLaKlHGzDQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/middleware-endpoint": {
|
"node_modules/@smithy/middleware-endpoint": {
|
||||||
"version": "2.4.4",
|
"version": "2.5.1",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/middleware-endpoint/-/middleware-endpoint-2.4.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/middleware-endpoint/-/middleware-endpoint-2.5.1.tgz",
|
||||||
"integrity": "sha512-4yjHyHK2Jul4JUDBo2sTsWY9UshYUnXeb/TAK/MTaPEb8XQvDmpwSFnfIRDU45RY1a6iC9LCnmJNg/yHyfxqkw==",
|
"integrity": "sha512-1/8kFp6Fl4OsSIVTWHnNjLnTL8IqpIb/D3sTSczrKFnrE9VMNWxnrRKNvpUHOJ6zpGD5f62TPm7+17ilTJpiCQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/middleware-serde": "^2.1.3",
|
"@smithy/middleware-serde": "^2.3.0",
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/shared-ini-file-loader": "^2.3.4",
|
"@smithy/shared-ini-file-loader": "^2.4.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/url-parser": "^2.1.3",
|
"@smithy/url-parser": "^2.2.0",
|
||||||
"@smithy/util-middleware": "^2.1.3",
|
"@smithy/util-middleware": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/middleware-retry": {
|
"node_modules/@smithy/middleware-retry": {
|
||||||
"version": "2.1.4",
|
"version": "2.3.1",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/middleware-retry/-/middleware-retry-2.1.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/middleware-retry/-/middleware-retry-2.3.1.tgz",
|
||||||
"integrity": "sha512-Cyolv9YckZTPli1EkkaS39UklonxMd08VskiuMhURDjC0HHa/AD6aK/YoD21CHv9s0QLg0WMLvk9YeLTKkXaFQ==",
|
"integrity": "sha512-P2bGufFpFdYcWvqpyqqmalRtwFUNUA8vHjJR5iGqbfR6mp65qKOLcUd6lTr4S9Gn/enynSrSf3p3FVgVAf6bXA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/service-error-classification": "^2.1.3",
|
"@smithy/service-error-classification": "^2.1.5",
|
||||||
"@smithy/smithy-client": "^2.4.2",
|
"@smithy/smithy-client": "^2.5.1",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-middleware": "^2.1.3",
|
"@smithy/util-middleware": "^2.2.0",
|
||||||
"@smithy/util-retry": "^2.1.3",
|
"@smithy/util-retry": "^2.2.0",
|
||||||
"tslib": "^2.5.0",
|
"tslib": "^2.6.2",
|
||||||
"uuid": "^8.3.2"
|
"uuid": "^9.0.1"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/middleware-retry/node_modules/uuid": {
|
|
||||||
"version": "8.3.2",
|
|
||||||
"resolved": "https://registry.npmjs.org/uuid/-/uuid-8.3.2.tgz",
|
|
||||||
"integrity": "sha512-+NYs2QeMWy+GWFOEm9xnn6HCDp0l7QBD7ml8zLUmJ+93Q5NF0NocErnwkTkXVFNiX3/fpC6afS8Dhb/gz7R7eg==",
|
|
||||||
"bin": {
|
|
||||||
"uuid": "dist/bin/uuid"
|
|
||||||
}
|
|
||||||
},
|
|
||||||
"node_modules/@smithy/middleware-serde": {
|
"node_modules/@smithy/middleware-serde": {
|
||||||
"version": "2.1.3",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/middleware-serde/-/middleware-serde-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/middleware-serde/-/middleware-serde-2.3.0.tgz",
|
||||||
"integrity": "sha512-s76LId+TwASrHhUa9QS4k/zeXDUAuNuddKklQzRgumbzge5BftVXHXIqL4wQxKGLocPwfgAOXWx+HdWhQk9hTg==",
|
"integrity": "sha512-sIADe7ojwqTyvEQBe1nc/GXB9wdHhi9UwyX0lTyttmUWDJLP655ZYE1WngnNyXREme8I27KCaUhyhZWRXL0q7Q==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/middleware-stack": {
|
"node_modules/@smithy/middleware-stack": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/middleware-stack/-/middleware-stack-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/middleware-stack/-/middleware-stack-2.2.0.tgz",
|
||||||
"integrity": "sha512-opMFufVQgvBSld/b7mD7OOEBxF6STyraVr1xel1j0abVILM8ALJvRoFbqSWHGmaDlRGIiV9Q5cGbWi0sdiEaLQ==",
|
"integrity": "sha512-Qntc3jrtwwrsAC+X8wms8zhrTr0sFXnyEGhZd9sLtsJ/6gGQKFzNB+wWbOcpJd7BR8ThNCoKt76BuQahfMvpeA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/node-config-provider": {
|
"node_modules/@smithy/node-config-provider": {
|
||||||
"version": "2.2.4",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/node-config-provider/-/node-config-provider-2.2.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/node-config-provider/-/node-config-provider-2.3.0.tgz",
|
||||||
"integrity": "sha512-nqazHCp8r4KHSFhRQ+T0VEkeqvA0U+RhehBSr1gunUuNW3X7j0uDrWBxB2gE9eutzy6kE3Y7L+Dov/UXT871vg==",
|
"integrity": "sha512-0elK5/03a1JPWMDPaS726Iw6LpQg80gFut1tNpPfxFuChEEklo2yL823V94SpTZTxmKlXFtFgsP55uh3dErnIg==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/property-provider": "^2.1.3",
|
"@smithy/property-provider": "^2.2.0",
|
||||||
"@smithy/shared-ini-file-loader": "^2.3.4",
|
"@smithy/shared-ini-file-loader": "^2.4.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/node-http-handler": {
|
"node_modules/@smithy/node-http-handler": {
|
||||||
"version": "2.4.1",
|
"version": "2.5.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/node-http-handler/-/node-http-handler-2.4.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/node-http-handler/-/node-http-handler-2.5.0.tgz",
|
||||||
"integrity": "sha512-HCkb94soYhJMxPCa61wGKgmeKpJ3Gftx1XD6bcWEB2wMV1L9/SkQu/6/ysKBnbOzWRE01FGzwrTxucHypZ8rdg==",
|
"integrity": "sha512-mVGyPBzkkGQsPoxQUbxlEfRjrj6FPyA3u3u2VXGr9hT8wilsoQdZdvKpMBFMB8Crfhv5dNkKHIW0Yyuc7eABqA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/abort-controller": "^2.1.3",
|
"@smithy/abort-controller": "^2.2.0",
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/querystring-builder": "^2.1.3",
|
"@smithy/querystring-builder": "^2.2.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/property-provider": {
|
"node_modules/@smithy/property-provider": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/property-provider/-/property-provider-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/property-provider/-/property-provider-2.2.0.tgz",
|
||||||
"integrity": "sha512-bMz3se+ySKWNrgm7eIiQMa2HO/0fl2D0HvLAdg9pTMcpgp4SqOAh6bz7Ik6y7uQqSrk4rLjIKgbQ6yzYgGehCQ==",
|
"integrity": "sha512-+xiil2lFhtTRzXkx8F053AV46QnIw6e7MV8od5Mi68E1ICOjCeCHw2XfLnDEUHnT9WGUIkwcqavXjfwuJbGlpg==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/protocol-http": {
|
"node_modules/@smithy/protocol-http": {
|
||||||
"version": "3.2.1",
|
"version": "3.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/protocol-http/-/protocol-http-3.2.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/protocol-http/-/protocol-http-3.3.0.tgz",
|
||||||
"integrity": "sha512-KLrQkEw4yJCeAmAH7hctE8g9KwA7+H2nSJwxgwIxchbp/L0B5exTdOQi9D5HinPLlothoervGmhpYKelZ6AxIA==",
|
"integrity": "sha512-Xy5XK1AFWW2nlY/biWZXu6/krgbaf2dg0q492D8M5qthsnU2H+UgFeZLbM76FnH7s6RO/xhQRkj+T6KBO3JzgQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/querystring-builder": {
|
"node_modules/@smithy/querystring-builder": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/querystring-builder/-/querystring-builder-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/querystring-builder/-/querystring-builder-2.2.0.tgz",
|
||||||
"integrity": "sha512-kFD3PnNqKELe6m9GRHQw/ftFFSZpnSeQD4qvgDB6BQN6hREHELSosVFUMPN4M3MDKN2jAwk35vXHLoDrNfKu0A==",
|
"integrity": "sha512-L1kSeviUWL+emq3CUVSgdogoM/D9QMFaqxL/dd0X7PCNWmPXqt+ExtrBjqT0V7HLN03Vs9SuiLrG3zy3JGnE5A==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-uri-escape": "^2.1.1",
|
"@smithy/util-uri-escape": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/querystring-parser": {
|
"node_modules/@smithy/querystring-parser": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/querystring-parser/-/querystring-parser-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/querystring-parser/-/querystring-parser-2.2.0.tgz",
|
||||||
"integrity": "sha512-3+CWJoAqcBMR+yvz6D+Fc5VdoGFtfenW6wqSWATWajrRMGVwJGPT3Vy2eb2bnMktJc4HU4bpjeovFa566P3knQ==",
|
"integrity": "sha512-BvHCDrKfbG5Yhbpj4vsbuPV2GgcpHiAkLeIlcA1LtfpMz3jrqizP1+OguSNSj1MwBHEiN+jwNisXLGdajGDQJA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/service-error-classification": {
|
"node_modules/@smithy/service-error-classification": {
|
||||||
"version": "2.1.3",
|
"version": "2.1.5",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/service-error-classification/-/service-error-classification-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/service-error-classification/-/service-error-classification-2.1.5.tgz",
|
||||||
"integrity": "sha512-iUrpSsem97bbXHHT/v3s7vaq8IIeMo6P6cXdeYHrx0wOJpMeBGQF7CB0mbJSiTm3//iq3L55JiEm8rA7CTVI8A==",
|
"integrity": "sha512-uBDTIBBEdAQryvHdc5W8sS5YX7RQzF683XrHePVdFmAgKiMofU15FLSM0/HU03hKTnazdNRFa0YHS7+ArwoUSQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1"
|
"@smithy/types": "^2.12.0"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/shared-ini-file-loader": {
|
"node_modules/@smithy/shared-ini-file-loader": {
|
||||||
"version": "2.3.4",
|
"version": "2.4.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/shared-ini-file-loader/-/shared-ini-file-loader-2.3.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/shared-ini-file-loader/-/shared-ini-file-loader-2.4.0.tgz",
|
||||||
"integrity": "sha512-CiZmPg9GeDKbKmJGEFvJBsJcFnh0AQRzOtQAzj1XEa8N/0/uSN/v1LYzgO7ry8hhO8+9KB7+DhSW0weqBra4Aw==",
|
"integrity": "sha512-WyujUJL8e1B6Z4PBfAqC/aGY1+C7T0w20Gih3yrvJSk97gpiVfB+y7c46T4Nunk+ZngLq0rOIdeVeIklk0R3OA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/signature-v4": {
|
"node_modules/@smithy/signature-v4": {
|
||||||
"version": "2.1.3",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/signature-v4/-/signature-v4-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/signature-v4/-/signature-v4-2.3.0.tgz",
|
||||||
"integrity": "sha512-Jq4iPPdCmJojZTsPePn4r1ULShh6ONkokLuxp1Lnk4Sq7r7rJp4HlA1LbPBq4bD64TIzQezIpr1X+eh5NYkNxw==",
|
"integrity": "sha512-ui/NlpILU+6HAQBfJX8BBsDXuKSNrjTSuOYArRblcrErwKFutjrCNb/OExfVRyj9+26F9J+ZmfWT+fKWuDrH3Q==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/eventstream-codec": "^2.1.3",
|
"@smithy/is-array-buffer": "^2.2.0",
|
||||||
"@smithy/is-array-buffer": "^2.1.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/util-hex-encoding": "^2.2.0",
|
||||||
"@smithy/util-hex-encoding": "^2.1.1",
|
"@smithy/util-middleware": "^2.2.0",
|
||||||
"@smithy/util-middleware": "^2.1.3",
|
"@smithy/util-uri-escape": "^2.2.0",
|
||||||
"@smithy/util-uri-escape": "^2.1.1",
|
"@smithy/util-utf8": "^2.3.0",
|
||||||
"@smithy/util-utf8": "^2.1.1",
|
"tslib": "^2.6.2"
|
||||||
"tslib": "^2.5.0"
|
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/smithy-client": {
|
"node_modules/@smithy/smithy-client": {
|
||||||
"version": "2.4.2",
|
"version": "2.5.1",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/smithy-client/-/smithy-client-2.4.2.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/smithy-client/-/smithy-client-2.5.1.tgz",
|
||||||
"integrity": "sha512-ntAFYN51zu3N3mCd95YFcFi/8rmvm//uX+HnK24CRbI6k5Rjackn0JhgKz5zOx/tbNvOpgQIwhSX+1EvEsBLbA==",
|
"integrity": "sha512-jrbSQrYCho0yDaaf92qWgd+7nAeap5LtHTI51KXqmpIFCceKU3K9+vIVTUH72bOJngBMqa4kyu1VJhRcSrk/CQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/middleware-endpoint": "^2.4.4",
|
"@smithy/middleware-endpoint": "^2.5.1",
|
||||||
"@smithy/middleware-stack": "^2.1.3",
|
"@smithy/middleware-stack": "^2.2.0",
|
||||||
"@smithy/protocol-http": "^3.2.1",
|
"@smithy/protocol-http": "^3.3.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-stream": "^2.1.3",
|
"@smithy/util-stream": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/types": {
|
"node_modules/@smithy/types": {
|
||||||
"version": "2.10.1",
|
"version": "2.12.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/types/-/types-2.10.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/types/-/types-2.12.0.tgz",
|
||||||
"integrity": "sha512-hjQO+4ru4cQ58FluQvKKiyMsFg0A6iRpGm2kqdH8fniyNd2WyanoOsYJfMX/IFLuLxEoW6gnRkNZy1y6fUUhtA==",
|
"integrity": "sha512-QwYgloJ0sVNBeBuBs65cIkTbfzV/Q6ZNPCJ99EICFEdJYG50nGIY/uYXp+TbsdJReIuPr0a0kXmCvren3MbRRw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/url-parser": {
|
"node_modules/@smithy/url-parser": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/url-parser/-/url-parser-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/url-parser/-/url-parser-2.2.0.tgz",
|
||||||
"integrity": "sha512-X1NRA4WzK/ihgyzTpeGvI9Wn45y8HmqF4AZ/FazwAv8V203Ex+4lXqcYI70naX9ETqbqKVzFk88W6WJJzCggTQ==",
|
"integrity": "sha512-hoA4zm61q1mNTpksiSWp2nEl1dt3j726HdRhiNgVJQMj7mLp7dprtF57mOB6JvEk/x9d2bsuL5hlqZbBuHQylQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/querystring-parser": "^2.1.3",
|
"@smithy/querystring-parser": "^2.2.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-base64": {
|
"node_modules/@smithy/util-base64": {
|
||||||
"version": "2.1.1",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-base64/-/util-base64-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-base64/-/util-base64-2.3.0.tgz",
|
||||||
"integrity": "sha512-UfHVpY7qfF/MrgndI5PexSKVTxSZIdz9InghTFa49QOvuu9I52zLPLUHXvHpNuMb1iD2vmc6R+zbv/bdMipR/g==",
|
"integrity": "sha512-s3+eVwNeJuXUwuMbusncZNViuhv2LjVJ1nMwTqSA0XAC7gjKhqqxRdJPhR8+YrkoZ9IiIbFk/yK6ACe/xlF+hw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/util-buffer-from": "^2.1.1",
|
"@smithy/util-buffer-from": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"@smithy/util-utf8": "^2.3.0",
|
||||||
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-body-length-browser": {
|
"node_modules/@smithy/util-body-length-browser": {
|
||||||
"version": "2.1.1",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-body-length-browser/-/util-body-length-browser-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-body-length-browser/-/util-body-length-browser-2.2.0.tgz",
|
||||||
"integrity": "sha512-ekOGBLvs1VS2d1zM2ER4JEeBWAvIOUKeaFch29UjjJsxmZ/f0L3K3x0dEETgh3Q9bkZNHgT+rkdl/J/VUqSRag==",
|
"integrity": "sha512-dtpw9uQP7W+n3vOtx0CfBD5EWd7EPdIdsQnWTDoFf77e3VUf05uA7R7TGipIo8e4WL2kuPdnsr3hMQn9ziYj5w==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-body-length-node": {
|
"node_modules/@smithy/util-body-length-node": {
|
||||||
"version": "2.2.1",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-body-length-node/-/util-body-length-node-2.2.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-body-length-node/-/util-body-length-node-2.3.0.tgz",
|
||||||
"integrity": "sha512-/ggJG+ta3IDtpNVq4ktmEUtOkH1LW64RHB5B0hcr5ZaWBmo96UX2cIOVbjCqqDickTXqBWZ4ZO0APuaPrD7Abg==",
|
"integrity": "sha512-ITWT1Wqjubf2CJthb0BuT9+bpzBfXeMokH/AAa5EJQgbv9aPMVfnM76iFIZVFf50hYXGbtiV71BHAthNWd6+dw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-buffer-from": {
|
"node_modules/@smithy/util-buffer-from": {
|
||||||
"version": "2.1.1",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-buffer-from/-/util-buffer-from-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-buffer-from/-/util-buffer-from-2.2.0.tgz",
|
||||||
"integrity": "sha512-clhNjbyfqIv9Md2Mg6FffGVrJxw7bgK7s3Iax36xnfVj6cg0fUG7I4RH0XgXJF8bxi+saY5HR21g2UPKSxVCXg==",
|
"integrity": "sha512-IJdWBbTcMQ6DA0gdNhh/BwrLkDR+ADW5Kr1aZmd4k3DIF6ezMV4R2NIAmT08wQJ3yUK82thHWmC/TnK/wpMMIA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/is-array-buffer": "^2.1.1",
|
"@smithy/is-array-buffer": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-config-provider": {
|
"node_modules/@smithy/util-config-provider": {
|
||||||
"version": "2.2.1",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-config-provider/-/util-config-provider-2.2.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-config-provider/-/util-config-provider-2.3.0.tgz",
|
||||||
"integrity": "sha512-50VL/tx9oYYcjJn/qKqNy7sCtpD0+s8XEBamIFo4mFFTclKMNp+rsnymD796uybjiIquB7VCB/DeafduL0y2kw==",
|
"integrity": "sha512-HZkzrRcuFN1k70RLqlNK4FnPXKOpkik1+4JaBoHNJn+RnJGYqaa3c5/+XtLOXhlKzlRgNvyaLieHTW2VwGN0VQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-defaults-mode-browser": {
|
"node_modules/@smithy/util-defaults-mode-browser": {
|
||||||
"version": "2.1.4",
|
"version": "2.2.1",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-defaults-mode-browser/-/util-defaults-mode-browser-2.1.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-defaults-mode-browser/-/util-defaults-mode-browser-2.2.1.tgz",
|
||||||
"integrity": "sha512-J6XAVY+/g7jf03QMnvqPyU+8jqGrrtXoKWFVOS+n1sz0Lg8HjHJ1ANqaDN+KTTKZRZlvG8nU5ZrJOUL6VdwgcQ==",
|
"integrity": "sha512-RtKW+8j8skk17SYowucwRUjeh4mCtnm5odCL0Lm2NtHQBsYKrNW0od9Rhopu9wF1gHMfHeWF7i90NwBz/U22Kw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/property-provider": "^2.1.3",
|
"@smithy/property-provider": "^2.2.0",
|
||||||
"@smithy/smithy-client": "^2.4.2",
|
"@smithy/smithy-client": "^2.5.1",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"bowser": "^2.11.0",
|
"bowser": "^2.11.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 10.0.0"
|
"node": ">= 10.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-defaults-mode-node": {
|
"node_modules/@smithy/util-defaults-mode-node": {
|
||||||
"version": "2.2.3",
|
"version": "2.3.1",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-defaults-mode-node/-/util-defaults-mode-node-2.2.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-defaults-mode-node/-/util-defaults-mode-node-2.3.1.tgz",
|
||||||
"integrity": "sha512-ttUISrv1uVOjTlDa3nznX33f0pthoUlP+4grhTvOzcLhzArx8qHB94/untGACOG3nlf8vU20nI2iWImfzoLkYA==",
|
"integrity": "sha512-vkMXHQ0BcLFysBMWgSBLSk3+leMpFSyyFj8zQtv5ZyUBx8/owVh1/pPEkzmW/DR/Gy/5c8vjLDD9gZjXNKbrpA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/config-resolver": "^2.1.4",
|
"@smithy/config-resolver": "^2.2.0",
|
||||||
"@smithy/credential-provider-imds": "^2.2.4",
|
"@smithy/credential-provider-imds": "^2.3.0",
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/property-provider": "^2.1.3",
|
"@smithy/property-provider": "^2.2.0",
|
||||||
"@smithy/smithy-client": "^2.4.2",
|
"@smithy/smithy-client": "^2.5.1",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 10.0.0"
|
"node": ">= 10.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-endpoints": {
|
"node_modules/@smithy/util-endpoints": {
|
||||||
"version": "1.1.4",
|
"version": "1.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-endpoints/-/util-endpoints-1.1.4.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-endpoints/-/util-endpoints-1.2.0.tgz",
|
||||||
"integrity": "sha512-/qAeHmK5l4yQ4/bCIJ9p49wDe9rwWtOzhPHblu386fwPNT3pxmodgcs9jDCV52yK9b4rB8o9Sj31P/7Vzka1cg==",
|
"integrity": "sha512-BuDHv8zRjsE5zXd3PxFXFknzBG3owCpjq8G3FcsXW3CykYXuEqM3nTSsmLzw5q+T12ZYuDlVUZKBdpNbhVtlrQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/node-config-provider": "^2.2.4",
|
"@smithy/node-config-provider": "^2.3.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 14.0.0"
|
"node": ">= 14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-hex-encoding": {
|
"node_modules/@smithy/util-hex-encoding": {
|
||||||
"version": "2.1.1",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-hex-encoding/-/util-hex-encoding-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-hex-encoding/-/util-hex-encoding-2.2.0.tgz",
|
||||||
"integrity": "sha512-3UNdP2pkYUUBGEXzQI9ODTDK+Tcu1BlCyDBaRHwyxhA+8xLP8agEKQq4MGmpjqb4VQAjq9TwlCQX0kP6XDKYLg==",
|
"integrity": "sha512-7iKXR+/4TpLK194pVjKiasIyqMtTYJsgKgM242Y9uzt5dhHnUDvMNb+3xIhRJ9QhvqGii/5cRUt4fJn3dtXNHQ==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-middleware": {
|
"node_modules/@smithy/util-middleware": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-middleware/-/util-middleware-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-middleware/-/util-middleware-2.2.0.tgz",
|
||||||
"integrity": "sha512-/+2fm7AZ2ozl5h8wM++ZP0ovE9/tiUUAHIbCfGfb3Zd3+Dyk17WODPKXBeJ/TnK5U+x743QmA0xHzlSm8I/qhw==",
|
"integrity": "sha512-L1qpleXf9QD6LwLCJ5jddGkgWyuSvWBkJwWAZ6kFkdifdso+sk3L3O1HdmPvCdnCK3IS4qWyPxev01QMnfHSBw==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-retry": {
|
"node_modules/@smithy/util-retry": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-retry/-/util-retry-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-retry/-/util-retry-2.2.0.tgz",
|
||||||
"integrity": "sha512-Kbvd+GEMuozbNUU3B89mb99tbufwREcyx2BOX0X2+qHjq6Gvsah8xSDDgxISDwcOHoDqUWO425F0Uc/QIRhYkg==",
|
"integrity": "sha512-q9+pAFPTfftHXRytmZ7GzLFFrEGavqapFc06XxzZFcSIGERXMerXxCitjOG1prVDR9QdjqotF40SWvbqcCpf8g==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/service-error-classification": "^2.1.3",
|
"@smithy/service-error-classification": "^2.1.5",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">= 14.0.0"
|
"node": ">= 14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-stream": {
|
"node_modules/@smithy/util-stream": {
|
||||||
"version": "2.1.3",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-stream/-/util-stream-2.1.3.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-stream/-/util-stream-2.2.0.tgz",
|
||||||
"integrity": "sha512-HvpEQbP8raTy9n86ZfXiAkf3ezp1c3qeeO//zGqwZdrfaoOpGKQgF2Sv1IqZp7wjhna7pvczWaGUHjcOPuQwKw==",
|
"integrity": "sha512-17faEXbYWIRst1aU9SvPZyMdWmqIrduZjVOqCPMIsWFNxs5yQQgFrJL6b2SdiCzyW9mJoDjFtgi53xx7EH+BXA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/fetch-http-handler": "^2.4.3",
|
"@smithy/fetch-http-handler": "^2.5.0",
|
||||||
"@smithy/node-http-handler": "^2.4.1",
|
"@smithy/node-http-handler": "^2.5.0",
|
||||||
"@smithy/types": "^2.10.1",
|
"@smithy/types": "^2.12.0",
|
||||||
"@smithy/util-base64": "^2.1.1",
|
"@smithy/util-base64": "^2.3.0",
|
||||||
"@smithy/util-buffer-from": "^2.1.1",
|
"@smithy/util-buffer-from": "^2.2.0",
|
||||||
"@smithy/util-hex-encoding": "^2.1.1",
|
"@smithy/util-hex-encoding": "^2.2.0",
|
||||||
"@smithy/util-utf8": "^2.1.1",
|
"@smithy/util-utf8": "^2.3.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-uri-escape": {
|
"node_modules/@smithy/util-uri-escape": {
|
||||||
"version": "2.1.1",
|
"version": "2.2.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-uri-escape/-/util-uri-escape-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-uri-escape/-/util-uri-escape-2.2.0.tgz",
|
||||||
"integrity": "sha512-saVzI1h6iRBUVSqtnlOnc9ssU09ypo7n+shdQ8hBTZno/9rZ3AuRYvoHInV57VF7Qn7B+pFJG7qTzFiHxWlWBw==",
|
"integrity": "sha512-jtmJMyt1xMD/d8OtbVJ2gFZOSKc+ueYJZPW20ULW1GOp/q/YIM0wNh+u8ZFao9UaIGz4WoPW8hC64qlWLIfoDA==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
}
|
}
|
||||||
},
|
},
|
||||||
"node_modules/@smithy/util-utf8": {
|
"node_modules/@smithy/util-utf8": {
|
||||||
"version": "2.1.1",
|
"version": "2.3.0",
|
||||||
"resolved": "https://registry.npmjs.org/@smithy/util-utf8/-/util-utf8-2.1.1.tgz",
|
"resolved": "https://registry.npmjs.org/@smithy/util-utf8/-/util-utf8-2.3.0.tgz",
|
||||||
"integrity": "sha512-BqTpzYEcUMDwAKr7/mVRUtHDhs6ZoXDi9NypMvMfOr/+u1NW7JgqodPDECiiLboEm6bobcPcECxzjtQh865e9A==",
|
"integrity": "sha512-R8Rdn8Hy72KKcebgLiv8jQcQkXoLMOGGv5uI1/k0l+snqkOzQ1R0ChUBCxWMlBsFMekWjq0wRudIweFs7sKT5A==",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@smithy/util-buffer-from": "^2.1.1",
|
"@smithy/util-buffer-from": "^2.2.0",
|
||||||
"tslib": "^2.5.0"
|
"tslib": "^2.6.2"
|
||||||
},
|
},
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
|
|||||||
Vendored
+2
@@ -29,6 +29,7 @@ import { TAuthTokenServiceFactory } from "@app/services/auth-token/auth-token-se
|
|||||||
import { TGroupProjectServiceFactory } from "@app/services/group-project/group-project-service";
|
import { TGroupProjectServiceFactory } from "@app/services/group-project/group-project-service";
|
||||||
import { TIdentityServiceFactory } from "@app/services/identity/identity-service";
|
import { TIdentityServiceFactory } from "@app/services/identity/identity-service";
|
||||||
import { TIdentityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
import { TIdentityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
||||||
|
import { TIdentityAwsIamAuthServiceFactory } from "@app/services/identity-aws-iam-auth/identity-aws-iam-auth-service";
|
||||||
import { TIdentityProjectServiceFactory } from "@app/services/identity-project/identity-project-service";
|
import { TIdentityProjectServiceFactory } from "@app/services/identity-project/identity-project-service";
|
||||||
import { TIdentityUaServiceFactory } from "@app/services/identity-ua/identity-ua-service";
|
import { TIdentityUaServiceFactory } from "@app/services/identity-ua/identity-ua-service";
|
||||||
import { TIntegrationServiceFactory } from "@app/services/integration/integration-service";
|
import { TIntegrationServiceFactory } from "@app/services/integration/integration-service";
|
||||||
@@ -112,6 +113,7 @@ declare module "fastify" {
|
|||||||
identityAccessToken: TIdentityAccessTokenServiceFactory;
|
identityAccessToken: TIdentityAccessTokenServiceFactory;
|
||||||
identityProject: TIdentityProjectServiceFactory;
|
identityProject: TIdentityProjectServiceFactory;
|
||||||
identityUa: TIdentityUaServiceFactory;
|
identityUa: TIdentityUaServiceFactory;
|
||||||
|
identityAwsIamAuth: TIdentityAwsIamAuthServiceFactory;
|
||||||
secretApprovalPolicy: TSecretApprovalPolicyServiceFactory;
|
secretApprovalPolicy: TSecretApprovalPolicyServiceFactory;
|
||||||
secretApprovalRequest: TSecretApprovalRequestServiceFactory;
|
secretApprovalRequest: TSecretApprovalRequestServiceFactory;
|
||||||
secretRotation: TSecretRotationServiceFactory;
|
secretRotation: TSecretRotationServiceFactory;
|
||||||
|
|||||||
Vendored
+8
@@ -44,6 +44,9 @@ import {
|
|||||||
TIdentityAccessTokens,
|
TIdentityAccessTokens,
|
||||||
TIdentityAccessTokensInsert,
|
TIdentityAccessTokensInsert,
|
||||||
TIdentityAccessTokensUpdate,
|
TIdentityAccessTokensUpdate,
|
||||||
|
TIdentityAwsIamAuths,
|
||||||
|
TIdentityAwsIamAuthsInsert,
|
||||||
|
TIdentityAwsIamAuthsUpdate,
|
||||||
TIdentityOrgMemberships,
|
TIdentityOrgMemberships,
|
||||||
TIdentityOrgMembershipsInsert,
|
TIdentityOrgMembershipsInsert,
|
||||||
TIdentityOrgMembershipsUpdate,
|
TIdentityOrgMembershipsUpdate,
|
||||||
@@ -311,6 +314,11 @@ declare module "knex/types/tables" {
|
|||||||
TIdentityUniversalAuthsInsert,
|
TIdentityUniversalAuthsInsert,
|
||||||
TIdentityUniversalAuthsUpdate
|
TIdentityUniversalAuthsUpdate
|
||||||
>;
|
>;
|
||||||
|
[TableName.IdentityAwsIamAuth]: Knex.CompositeTableType<
|
||||||
|
TIdentityAwsIamAuths,
|
||||||
|
TIdentityAwsIamAuthsInsert,
|
||||||
|
TIdentityAwsIamAuthsUpdate
|
||||||
|
>;
|
||||||
[TableName.IdentityUaClientSecret]: Knex.CompositeTableType<
|
[TableName.IdentityUaClientSecret]: Knex.CompositeTableType<
|
||||||
TIdentityUaClientSecrets,
|
TIdentityUaClientSecrets,
|
||||||
TIdentityUaClientSecretsInsert,
|
TIdentityUaClientSecretsInsert,
|
||||||
|
|||||||
@@ -0,0 +1,29 @@
|
|||||||
|
import { Knex } from "knex";
|
||||||
|
|
||||||
|
import { TableName } from "../schemas";
|
||||||
|
import { createOnUpdateTrigger, dropOnUpdateTrigger } from "../utils";
|
||||||
|
|
||||||
|
export async function up(knex: Knex): Promise<void> {
|
||||||
|
if (!(await knex.schema.hasTable(TableName.IdentityAwsIamAuth))) {
|
||||||
|
await knex.schema.createTable(TableName.IdentityAwsIamAuth, (t) => {
|
||||||
|
t.uuid("id", { primaryKey: true }).defaultTo(knex.fn.uuid());
|
||||||
|
t.bigInteger("accessTokenTTL").defaultTo(7200).notNullable();
|
||||||
|
t.bigInteger("accessTokenMaxTTL").defaultTo(7200).notNullable();
|
||||||
|
t.bigInteger("accessTokenNumUsesLimit").defaultTo(0).notNullable();
|
||||||
|
t.jsonb("accessTokenTrustedIps").notNullable();
|
||||||
|
t.timestamps(true, true, true);
|
||||||
|
t.uuid("identityId").notNullable().unique();
|
||||||
|
t.foreign("identityId").references("id").inTable(TableName.Identity).onDelete("CASCADE");
|
||||||
|
t.string("stsEndpoint").notNullable();
|
||||||
|
t.string("allowedPrincipalArns").notNullable();
|
||||||
|
t.string("allowedAccountIds").notNullable();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
await createOnUpdateTrigger(knex, TableName.IdentityAwsIamAuth);
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function down(knex: Knex): Promise<void> {
|
||||||
|
await knex.schema.dropTableIfExists(TableName.IdentityAwsIamAuth);
|
||||||
|
await dropOnUpdateTrigger(knex, TableName.IdentityAwsIamAuth);
|
||||||
|
}
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
// Code generated by automation script, DO NOT EDIT.
|
||||||
|
// Automated by pulling database and generating zod schema
|
||||||
|
// To update. Just run npm run generate:schema
|
||||||
|
// Written by akhilmhdh.
|
||||||
|
|
||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { TImmutableDBKeys } from "./models";
|
||||||
|
|
||||||
|
export const IdentityAwsIamAuthsSchema = z.object({
|
||||||
|
id: z.string().uuid(),
|
||||||
|
accessTokenTTL: z.coerce.number().default(7200),
|
||||||
|
accessTokenMaxTTL: z.coerce.number().default(7200),
|
||||||
|
accessTokenNumUsesLimit: z.coerce.number().default(0),
|
||||||
|
accessTokenTrustedIps: z.unknown(),
|
||||||
|
createdAt: z.date(),
|
||||||
|
updatedAt: z.date(),
|
||||||
|
identityId: z.string().uuid(),
|
||||||
|
stsEndpoint: z.string(),
|
||||||
|
allowedPrincipalArns: z.string(),
|
||||||
|
allowedAccountIds: z.string()
|
||||||
|
});
|
||||||
|
|
||||||
|
export type TIdentityAwsIamAuths = z.infer<typeof IdentityAwsIamAuthsSchema>;
|
||||||
|
export type TIdentityAwsIamAuthsInsert = Omit<z.input<typeof IdentityAwsIamAuthsSchema>, TImmutableDBKeys>;
|
||||||
|
export type TIdentityAwsIamAuthsUpdate = Partial<Omit<z.input<typeof IdentityAwsIamAuthsSchema>, TImmutableDBKeys>>;
|
||||||
@@ -12,6 +12,7 @@ export * from "./group-project-memberships";
|
|||||||
export * from "./groups";
|
export * from "./groups";
|
||||||
export * from "./identities";
|
export * from "./identities";
|
||||||
export * from "./identity-access-tokens";
|
export * from "./identity-access-tokens";
|
||||||
|
export * from "./identity-aws-iam-auths";
|
||||||
export * from "./identity-org-memberships";
|
export * from "./identity-org-memberships";
|
||||||
export * from "./identity-project-additional-privilege";
|
export * from "./identity-project-additional-privilege";
|
||||||
export * from "./identity-project-membership-role";
|
export * from "./identity-project-membership-role";
|
||||||
|
|||||||
@@ -45,6 +45,7 @@ export enum TableName {
|
|||||||
IdentityAccessToken = "identity_access_tokens",
|
IdentityAccessToken = "identity_access_tokens",
|
||||||
IdentityUniversalAuth = "identity_universal_auths",
|
IdentityUniversalAuth = "identity_universal_auths",
|
||||||
IdentityUaClientSecret = "identity_ua_client_secrets",
|
IdentityUaClientSecret = "identity_ua_client_secrets",
|
||||||
|
IdentityAwsIamAuth = "identity_aws_iam_auths",
|
||||||
IdentityOrgMembership = "identity_org_memberships",
|
IdentityOrgMembership = "identity_org_memberships",
|
||||||
IdentityProjectMembership = "identity_project_memberships",
|
IdentityProjectMembership = "identity_project_memberships",
|
||||||
IdentityProjectMembershipRole = "identity_project_membership_role",
|
IdentityProjectMembershipRole = "identity_project_membership_role",
|
||||||
@@ -137,5 +138,6 @@ export enum ProjectUpgradeStatus {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export enum IdentityAuthMethod {
|
export enum IdentityAuthMethod {
|
||||||
Univeral = "universal-auth"
|
Univeral = "universal-auth",
|
||||||
|
AWS_IAM_AUTH = "aws-iam-auth"
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -66,6 +66,10 @@ export enum EventType {
|
|||||||
CREATE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "create-identity-universal-auth-client-secret",
|
CREATE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "create-identity-universal-auth-client-secret",
|
||||||
REVOKE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "revoke-identity-universal-auth-client-secret",
|
REVOKE_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRET = "revoke-identity-universal-auth-client-secret",
|
||||||
GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRETS = "get-identity-universal-auth-client-secret",
|
GET_IDENTITY_UNIVERSAL_AUTH_CLIENT_SECRETS = "get-identity-universal-auth-client-secret",
|
||||||
|
LOGIN_IDENTITY_AWS_IAM_AUTH = "login-identity-aws-iam-auth",
|
||||||
|
ADD_IDENTITY_AWS_IAM_AUTH = "add-identity-aws-iam-auth",
|
||||||
|
UPDATE_IDENTITY_AWS_IAM_AUTH = "update-identity-aws-iam-auth",
|
||||||
|
GET_IDENTITY_AWS_IAM_AUTH = "get-identity-aws-iam-auth",
|
||||||
CREATE_ENVIRONMENT = "create-environment",
|
CREATE_ENVIRONMENT = "create-environment",
|
||||||
UPDATE_ENVIRONMENT = "update-environment",
|
UPDATE_ENVIRONMENT = "update-environment",
|
||||||
DELETE_ENVIRONMENT = "delete-environment",
|
DELETE_ENVIRONMENT = "delete-environment",
|
||||||
@@ -406,6 +410,50 @@ interface RevokeIdentityUniversalAuthClientSecretEvent {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
interface LoginIdentityAwsIamAuthEvent {
|
||||||
|
type: EventType.LOGIN_IDENTITY_AWS_IAM_AUTH;
|
||||||
|
metadata: {
|
||||||
|
identityId: string;
|
||||||
|
identityAwsIamAuthId: string;
|
||||||
|
identityAccessTokenId: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface AddIdentityAwsIamAuthEvent {
|
||||||
|
type: EventType.ADD_IDENTITY_AWS_IAM_AUTH;
|
||||||
|
metadata: {
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint: string;
|
||||||
|
allowedPrincipalArns: string;
|
||||||
|
allowedAccountIds: string;
|
||||||
|
accessTokenTTL: number;
|
||||||
|
accessTokenMaxTTL: number;
|
||||||
|
accessTokenNumUsesLimit: number;
|
||||||
|
accessTokenTrustedIps: Array<TIdentityTrustedIp>;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface UpdateIdentityAwsIamAuthEvent {
|
||||||
|
type: EventType.UPDATE_IDENTITY_AWS_IAM_AUTH;
|
||||||
|
metadata: {
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint?: string;
|
||||||
|
allowedPrincipalArns?: string;
|
||||||
|
allowedAccountIds?: string;
|
||||||
|
accessTokenTTL?: number;
|
||||||
|
accessTokenMaxTTL?: number;
|
||||||
|
accessTokenNumUsesLimit?: number;
|
||||||
|
accessTokenTrustedIps?: Array<TIdentityTrustedIp>;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
interface GetIdentityAwsIamAuthEvent {
|
||||||
|
type: EventType.GET_IDENTITY_AWS_IAM_AUTH;
|
||||||
|
metadata: {
|
||||||
|
identityId: string;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
interface CreateEnvironmentEvent {
|
interface CreateEnvironmentEvent {
|
||||||
type: EventType.CREATE_ENVIRONMENT;
|
type: EventType.CREATE_ENVIRONMENT;
|
||||||
metadata: {
|
metadata: {
|
||||||
@@ -660,6 +708,10 @@ export type Event =
|
|||||||
| CreateIdentityUniversalAuthClientSecretEvent
|
| CreateIdentityUniversalAuthClientSecretEvent
|
||||||
| GetIdentityUniversalAuthClientSecretsEvent
|
| GetIdentityUniversalAuthClientSecretsEvent
|
||||||
| RevokeIdentityUniversalAuthClientSecretEvent
|
| RevokeIdentityUniversalAuthClientSecretEvent
|
||||||
|
| LoginIdentityAwsIamAuthEvent
|
||||||
|
| AddIdentityAwsIamAuthEvent
|
||||||
|
| UpdateIdentityAwsIamAuthEvent
|
||||||
|
| GetIdentityAwsIamAuthEvent
|
||||||
| CreateEnvironmentEvent
|
| CreateEnvironmentEvent
|
||||||
| UpdateEnvironmentEvent
|
| UpdateEnvironmentEvent
|
||||||
| DeleteEnvironmentEvent
|
| DeleteEnvironmentEvent
|
||||||
|
|||||||
@@ -92,6 +92,18 @@ export const UNIVERSAL_AUTH = {
|
|||||||
}
|
}
|
||||||
} as const;
|
} as const;
|
||||||
|
|
||||||
|
export const AWS_IAM_AUTH = {
|
||||||
|
LOGIN: {
|
||||||
|
identityId: "The ID of the identity to login.",
|
||||||
|
iamHttpRequestMethod: "The HTTP request method used in the signed request.",
|
||||||
|
iamRequestUrl:
|
||||||
|
"The base64-encoded HTTP URL used in the signed request. Most likely, the base64-encoding of https://sts.amazonaws.com/",
|
||||||
|
iamRequestBody:
|
||||||
|
"The base64-encoded body of the signed request. Most likely, the base64-encoding of Action=GetCallerIdentity&Version=2011-06-15.",
|
||||||
|
iamRequestHeaders: "The base64-encoded headers of the sts:GetCallerIdentity signed request."
|
||||||
|
}
|
||||||
|
} as const;
|
||||||
|
|
||||||
export const ORGANIZATIONS = {
|
export const ORGANIZATIONS = {
|
||||||
LIST_USER_MEMBERSHIPS: {
|
LIST_USER_MEMBERSHIPS: {
|
||||||
organizationId: "The ID of the organization to get memberships from."
|
organizationId: "The ID of the organization to get memberships from."
|
||||||
|
|||||||
@@ -70,6 +70,8 @@ import { identityOrgDALFactory } from "@app/services/identity/identity-org-dal";
|
|||||||
import { identityServiceFactory } from "@app/services/identity/identity-service";
|
import { identityServiceFactory } from "@app/services/identity/identity-service";
|
||||||
import { identityAccessTokenDALFactory } from "@app/services/identity-access-token/identity-access-token-dal";
|
import { identityAccessTokenDALFactory } from "@app/services/identity-access-token/identity-access-token-dal";
|
||||||
import { identityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
import { identityAccessTokenServiceFactory } from "@app/services/identity-access-token/identity-access-token-service";
|
||||||
|
import { identityAwsIamAuthDALFactory } from "@app/services/identity-aws-iam-auth/identity-aws-iam-auth-dal";
|
||||||
|
import { identityAwsIamAuthServiceFactory } from "@app/services/identity-aws-iam-auth/identity-aws-iam-auth-service";
|
||||||
import { identityProjectDALFactory } from "@app/services/identity-project/identity-project-dal";
|
import { identityProjectDALFactory } from "@app/services/identity-project/identity-project-dal";
|
||||||
import { identityProjectMembershipRoleDALFactory } from "@app/services/identity-project/identity-project-membership-role-dal";
|
import { identityProjectMembershipRoleDALFactory } from "@app/services/identity-project/identity-project-membership-role-dal";
|
||||||
import { identityProjectServiceFactory } from "@app/services/identity-project/identity-project-service";
|
import { identityProjectServiceFactory } from "@app/services/identity-project/identity-project-service";
|
||||||
@@ -191,6 +193,7 @@ export const registerRoutes = async (
|
|||||||
|
|
||||||
const identityUaDAL = identityUaDALFactory(db);
|
const identityUaDAL = identityUaDALFactory(db);
|
||||||
const identityUaClientSecretDAL = identityUaClientSecretDALFactory(db);
|
const identityUaClientSecretDAL = identityUaClientSecretDALFactory(db);
|
||||||
|
const identityAwsIamAuthDAL = identityAwsIamAuthDALFactory(db);
|
||||||
|
|
||||||
const auditLogDAL = auditLogDALFactory(db);
|
const auditLogDAL = auditLogDALFactory(db);
|
||||||
const trustedIpDAL = trustedIpDALFactory(db);
|
const trustedIpDAL = trustedIpDALFactory(db);
|
||||||
@@ -637,6 +640,14 @@ export const registerRoutes = async (
|
|||||||
identityUaDAL,
|
identityUaDAL,
|
||||||
licenseService
|
licenseService
|
||||||
});
|
});
|
||||||
|
const identityAWSIAMAuthService = identityAwsIamAuthServiceFactory({
|
||||||
|
identityAccessTokenDAL,
|
||||||
|
identityAwsIamAuthDAL,
|
||||||
|
identityOrgMembershipDAL,
|
||||||
|
identityDAL,
|
||||||
|
licenseService,
|
||||||
|
permissionService
|
||||||
|
});
|
||||||
|
|
||||||
const dynamicSecretProviders = buildDynamicSecretProviders();
|
const dynamicSecretProviders = buildDynamicSecretProviders();
|
||||||
const dynamicSecretQueueService = dynamicSecretLeaseQueueServiceFactory({
|
const dynamicSecretQueueService = dynamicSecretLeaseQueueServiceFactory({
|
||||||
@@ -706,6 +717,7 @@ export const registerRoutes = async (
|
|||||||
identityAccessToken: identityAccessTokenService,
|
identityAccessToken: identityAccessTokenService,
|
||||||
identityProject: identityProjectService,
|
identityProject: identityProjectService,
|
||||||
identityUa: identityUaService,
|
identityUa: identityUaService,
|
||||||
|
identityAwsIamAuth: identityAWSIAMAuthService,
|
||||||
secretApprovalPolicy: sapService,
|
secretApprovalPolicy: sapService,
|
||||||
secretApprovalRequest: sarService,
|
secretApprovalRequest: sarService,
|
||||||
secretRotation: secretRotationService,
|
secretRotation: secretRotationService,
|
||||||
|
|||||||
@@ -0,0 +1,269 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
import { IdentityAwsIamAuthsSchema } from "@app/db/schemas";
|
||||||
|
import { EventType } from "@app/ee/services/audit-log/audit-log-types";
|
||||||
|
import { AWS_IAM_AUTH } from "@app/lib/api-docs";
|
||||||
|
import { readLimit, writeLimit } from "@app/server/config/rateLimiter";
|
||||||
|
import { verifyAuth } from "@app/server/plugins/auth/verify-auth";
|
||||||
|
import { AuthMode } from "@app/services/auth/auth-type";
|
||||||
|
import { TIdentityTrustedIp } from "@app/services/identity/identity-types";
|
||||||
|
import {
|
||||||
|
validateAccountIds,
|
||||||
|
validatePrincipalArns
|
||||||
|
} from "@app/services/identity-aws-iam-auth/identity-aws-iam-auth-validators";
|
||||||
|
|
||||||
|
export const registerIdentityAwsIamAuthRouter = async (server: FastifyZodProvider) => {
|
||||||
|
server.route({
|
||||||
|
method: "POST",
|
||||||
|
url: "/aws-iam-auth/login",
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
|
schema: {
|
||||||
|
description: "Login with Universal Auth",
|
||||||
|
body: z.object({
|
||||||
|
identityId: z.string().describe(AWS_IAM_AUTH.LOGIN.identityId),
|
||||||
|
iamHttpRequestMethod: z.string().default("POST").describe(AWS_IAM_AUTH.LOGIN.iamHttpRequestMethod),
|
||||||
|
iamRequestBody: z.string().describe(AWS_IAM_AUTH.LOGIN.iamRequestBody),
|
||||||
|
iamRequestHeaders: z.string().describe(AWS_IAM_AUTH.LOGIN.iamRequestHeaders)
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
accessToken: z.string(),
|
||||||
|
expiresIn: z.coerce.number(),
|
||||||
|
accessTokenMaxTTL: z.coerce.number(),
|
||||||
|
tokenType: z.literal("Bearer")
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
const { identityAwsIamAuth, accessToken, identityAccessToken, identityMembershipOrg } =
|
||||||
|
await server.services.identityAwsIamAuth.login(req.body);
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: identityMembershipOrg?.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.LOGIN_IDENTITY_AWS_IAM_AUTH,
|
||||||
|
metadata: {
|
||||||
|
identityId: identityAwsIamAuth.identityId,
|
||||||
|
identityAccessTokenId: identityAccessToken.id,
|
||||||
|
identityAwsIamAuthId: identityAwsIamAuth.id
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return {
|
||||||
|
accessToken,
|
||||||
|
tokenType: "Bearer" as const,
|
||||||
|
expiresIn: identityAwsIamAuth.accessTokenTTL,
|
||||||
|
accessTokenMaxTTL: identityAwsIamAuth.accessTokenMaxTTL
|
||||||
|
};
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "POST",
|
||||||
|
url: "/aws-iam-auth/identities/:identityId",
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
|
schema: {
|
||||||
|
description: "Attach AWS IAM Auth configuration onto identity",
|
||||||
|
security: [
|
||||||
|
{
|
||||||
|
bearerAuth: []
|
||||||
|
}
|
||||||
|
],
|
||||||
|
params: z.object({
|
||||||
|
identityId: z.string().trim()
|
||||||
|
}),
|
||||||
|
body: z.object({
|
||||||
|
stsEndpoint: z.string().trim().min(1).default("https://sts.amazonaws.com/"),
|
||||||
|
allowedPrincipalArns: validatePrincipalArns,
|
||||||
|
allowedAccountIds: validateAccountIds,
|
||||||
|
accessTokenTrustedIps: z
|
||||||
|
.object({
|
||||||
|
ipAddress: z.string().trim()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
.min(1)
|
||||||
|
.default([{ ipAddress: "0.0.0.0/0" }, { ipAddress: "::/0" }]),
|
||||||
|
accessTokenTTL: z
|
||||||
|
.number()
|
||||||
|
.int()
|
||||||
|
.min(1)
|
||||||
|
.refine((value) => value !== 0, {
|
||||||
|
message: "accessTokenTTL must have a non zero number"
|
||||||
|
})
|
||||||
|
.default(2592000),
|
||||||
|
accessTokenMaxTTL: z
|
||||||
|
.number()
|
||||||
|
.int()
|
||||||
|
.refine((value) => value !== 0, {
|
||||||
|
message: "accessTokenMaxTTL must have a non zero number"
|
||||||
|
})
|
||||||
|
.default(2592000),
|
||||||
|
accessTokenNumUsesLimit: z.number().int().min(0).default(0)
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
identityAwsIamAuth: IdentityAwsIamAuthsSchema
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
const identityAwsIamAuth = await server.services.identityAwsIamAuth.attachAwsIamAuth({
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorId: req.permission.id,
|
||||||
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
actorOrgId: req.permission.orgId,
|
||||||
|
...req.body,
|
||||||
|
identityId: req.params.identityId
|
||||||
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: identityAwsIamAuth.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.ADD_IDENTITY_AWS_IAM_AUTH,
|
||||||
|
metadata: {
|
||||||
|
identityId: identityAwsIamAuth.identityId,
|
||||||
|
stsEndpoint: identityAwsIamAuth.stsEndpoint,
|
||||||
|
allowedPrincipalArns: identityAwsIamAuth.allowedPrincipalArns,
|
||||||
|
allowedAccountIds: identityAwsIamAuth.allowedAccountIds,
|
||||||
|
accessTokenTTL: identityAwsIamAuth.accessTokenTTL,
|
||||||
|
accessTokenMaxTTL: identityAwsIamAuth.accessTokenMaxTTL,
|
||||||
|
accessTokenTrustedIps: identityAwsIamAuth.accessTokenTrustedIps as TIdentityTrustedIp[],
|
||||||
|
accessTokenNumUsesLimit: identityAwsIamAuth.accessTokenNumUsesLimit
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return { identityAwsIamAuth };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "PATCH",
|
||||||
|
url: "/aws-iam-auth/identities/:identityId",
|
||||||
|
config: {
|
||||||
|
rateLimit: writeLimit
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
|
schema: {
|
||||||
|
description: "Update AWS IAM Auth configuration on identity",
|
||||||
|
security: [
|
||||||
|
{
|
||||||
|
bearerAuth: []
|
||||||
|
}
|
||||||
|
],
|
||||||
|
params: z.object({
|
||||||
|
identityId: z.string()
|
||||||
|
}),
|
||||||
|
body: z.object({
|
||||||
|
stsEndpoint: z.string().trim().min(1).optional(),
|
||||||
|
allowedPrincipalArns: validatePrincipalArns,
|
||||||
|
allowedAccountIds: validateAccountIds,
|
||||||
|
accessTokenTrustedIps: z
|
||||||
|
.object({
|
||||||
|
ipAddress: z.string().trim()
|
||||||
|
})
|
||||||
|
.array()
|
||||||
|
.min(1)
|
||||||
|
.optional(),
|
||||||
|
accessTokenTTL: z.number().int().min(0).optional(),
|
||||||
|
accessTokenNumUsesLimit: z.number().int().min(0).optional(),
|
||||||
|
accessTokenMaxTTL: z
|
||||||
|
.number()
|
||||||
|
.int()
|
||||||
|
.refine((value) => value !== 0, {
|
||||||
|
message: "accessTokenMaxTTL must have a non zero number"
|
||||||
|
})
|
||||||
|
.optional()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
identityAwsIamAuth: IdentityAwsIamAuthsSchema
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
const identityAwsIamAuth = await server.services.identityAwsIamAuth.updateAwsIamAuth({
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorId: req.permission.id,
|
||||||
|
actorAuthMethod: req.permission.authMethod,
|
||||||
|
actorOrgId: req.permission.orgId,
|
||||||
|
...req.body,
|
||||||
|
identityId: req.params.identityId
|
||||||
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: identityAwsIamAuth.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.UPDATE_IDENTITY_AWS_IAM_AUTH,
|
||||||
|
metadata: {
|
||||||
|
identityId: identityAwsIamAuth.identityId,
|
||||||
|
stsEndpoint: identityAwsIamAuth.stsEndpoint,
|
||||||
|
allowedPrincipalArns: identityAwsIamAuth.allowedPrincipalArns,
|
||||||
|
allowedAccountIds: identityAwsIamAuth.allowedAccountIds,
|
||||||
|
accessTokenTTL: identityAwsIamAuth.accessTokenTTL,
|
||||||
|
accessTokenMaxTTL: identityAwsIamAuth.accessTokenMaxTTL,
|
||||||
|
accessTokenTrustedIps: identityAwsIamAuth.accessTokenTrustedIps as TIdentityTrustedIp[],
|
||||||
|
accessTokenNumUsesLimit: identityAwsIamAuth.accessTokenNumUsesLimit
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
return { identityAwsIamAuth };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
server.route({
|
||||||
|
method: "GET",
|
||||||
|
url: "/aws-iam-auth/identities/:identityId",
|
||||||
|
config: {
|
||||||
|
rateLimit: readLimit
|
||||||
|
},
|
||||||
|
onRequest: verifyAuth([AuthMode.JWT, AuthMode.IDENTITY_ACCESS_TOKEN]),
|
||||||
|
schema: {
|
||||||
|
description: "Retrieve AWS IAM Auth configuration on identity",
|
||||||
|
security: [
|
||||||
|
{
|
||||||
|
bearerAuth: []
|
||||||
|
}
|
||||||
|
],
|
||||||
|
params: z.object({
|
||||||
|
identityId: z.string()
|
||||||
|
}),
|
||||||
|
response: {
|
||||||
|
200: z.object({
|
||||||
|
identityAwsIamAuth: IdentityAwsIamAuthsSchema
|
||||||
|
})
|
||||||
|
}
|
||||||
|
},
|
||||||
|
handler: async (req) => {
|
||||||
|
const identityAwsIamAuth = await server.services.identityAwsIamAuth.getAwsIamAuth({
|
||||||
|
identityId: req.params.identityId,
|
||||||
|
actor: req.permission.type,
|
||||||
|
actorId: req.permission.id,
|
||||||
|
actorOrgId: req.permission.orgId,
|
||||||
|
actorAuthMethod: req.permission.authMethod
|
||||||
|
});
|
||||||
|
|
||||||
|
await server.services.auditLog.createAuditLog({
|
||||||
|
...req.auditLogInfo,
|
||||||
|
orgId: identityAwsIamAuth.orgId,
|
||||||
|
event: {
|
||||||
|
type: EventType.GET_IDENTITY_AWS_IAM_AUTH,
|
||||||
|
metadata: {
|
||||||
|
identityId: identityAwsIamAuth.identityId
|
||||||
|
}
|
||||||
|
}
|
||||||
|
});
|
||||||
|
return { identityAwsIamAuth };
|
||||||
|
}
|
||||||
|
});
|
||||||
|
};
|
||||||
@@ -2,6 +2,7 @@ import { registerAdminRouter } from "./admin-router";
|
|||||||
import { registerAuthRoutes } from "./auth-router";
|
import { registerAuthRoutes } from "./auth-router";
|
||||||
import { registerProjectBotRouter } from "./bot-router";
|
import { registerProjectBotRouter } from "./bot-router";
|
||||||
import { registerIdentityAccessTokenRouter } from "./identity-access-token-router";
|
import { registerIdentityAccessTokenRouter } from "./identity-access-token-router";
|
||||||
|
import { registerIdentityAwsIamAuthRouter } from "./identity-aws-iam-auth-router";
|
||||||
import { registerIdentityRouter } from "./identity-router";
|
import { registerIdentityRouter } from "./identity-router";
|
||||||
import { registerIdentityUaRouter } from "./identity-ua";
|
import { registerIdentityUaRouter } from "./identity-ua";
|
||||||
import { registerIntegrationAuthRouter } from "./integration-auth-router";
|
import { registerIntegrationAuthRouter } from "./integration-auth-router";
|
||||||
@@ -28,6 +29,7 @@ export const registerV1Routes = async (server: FastifyZodProvider) => {
|
|||||||
await authRouter.register(registerAuthRoutes);
|
await authRouter.register(registerAuthRoutes);
|
||||||
await authRouter.register(registerIdentityUaRouter);
|
await authRouter.register(registerIdentityUaRouter);
|
||||||
await authRouter.register(registerIdentityAccessTokenRouter);
|
await authRouter.register(registerIdentityAccessTokenRouter);
|
||||||
|
await authRouter.register(registerIdentityAwsIamAuthRouter);
|
||||||
},
|
},
|
||||||
{ prefix: "/auth" }
|
{ prefix: "/auth" }
|
||||||
);
|
);
|
||||||
|
|||||||
@@ -0,0 +1,11 @@
|
|||||||
|
import { TDbClient } from "@app/db";
|
||||||
|
import { TableName } from "@app/db/schemas";
|
||||||
|
import { ormify } from "@app/lib/knex";
|
||||||
|
|
||||||
|
export type TIdentityAwsIamAuthDALFactory = ReturnType<typeof identityAwsIamAuthDALFactory>;
|
||||||
|
|
||||||
|
export const identityAwsIamAuthDALFactory = (db: TDbClient) => {
|
||||||
|
const awsIamAuthOrm = ormify(db, TableName.IdentityAwsIamAuth);
|
||||||
|
|
||||||
|
return awsIamAuthOrm;
|
||||||
|
};
|
||||||
@@ -0,0 +1,315 @@
|
|||||||
|
/* eslint-disable @typescript-eslint/no-unsafe-assignment */
|
||||||
|
import { ForbiddenError } from "@casl/ability";
|
||||||
|
import axios from "axios";
|
||||||
|
import jwt from "jsonwebtoken";
|
||||||
|
|
||||||
|
import { IdentityAuthMethod } from "@app/db/schemas";
|
||||||
|
import { TLicenseServiceFactory } from "@app/ee/services/license/license-service";
|
||||||
|
import { OrgPermissionActions, OrgPermissionSubjects } from "@app/ee/services/permission/org-permission";
|
||||||
|
import { TPermissionServiceFactory } from "@app/ee/services/permission/permission-service";
|
||||||
|
import { getConfig } from "@app/lib/config/env";
|
||||||
|
import { BadRequestError, UnauthorizedError } from "@app/lib/errors";
|
||||||
|
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
||||||
|
|
||||||
|
import { AuthTokenType } from "../auth/auth-type";
|
||||||
|
import { TIdentityDALFactory } from "../identity/identity-dal";
|
||||||
|
import { TIdentityOrgDALFactory } from "../identity/identity-org-dal";
|
||||||
|
import { TIdentityAccessTokenDALFactory } from "../identity-access-token/identity-access-token-dal";
|
||||||
|
import { TIdentityAccessTokenJwtPayload } from "../identity-access-token/identity-access-token-types";
|
||||||
|
import { extractPrincipalArn } from "./identity-aws-iam-auth.fns";
|
||||||
|
import { TIdentityAwsIamAuthDALFactory } from "./identity-aws-iam-auth-dal";
|
||||||
|
import {
|
||||||
|
TAttachAWSIAMAuthDTO,
|
||||||
|
TAWSGetCallerIdentityHeaders,
|
||||||
|
TGetAWSIAMAuthDTO,
|
||||||
|
TGetCallerIdentityResponse,
|
||||||
|
TLoginAWSIAMAuthDTO,
|
||||||
|
TUpdateAWSIAMAuthDTO
|
||||||
|
} from "./identity-aws-iam-auth-types";
|
||||||
|
|
||||||
|
type TIdentityAwsIamAuthServiceFactoryDep = {
|
||||||
|
identityAccessTokenDAL: Pick<TIdentityAccessTokenDALFactory, "create">;
|
||||||
|
identityAwsIamAuthDAL: Pick<TIdentityAwsIamAuthDALFactory, "findOne" | "transaction" | "create" | "updateById">;
|
||||||
|
identityOrgMembershipDAL: Pick<TIdentityOrgDALFactory, "findOne">;
|
||||||
|
identityDAL: Pick<TIdentityDALFactory, "updateById">;
|
||||||
|
licenseService: Pick<TLicenseServiceFactory, "getPlan">;
|
||||||
|
permissionService: Pick<TPermissionServiceFactory, "getOrgPermission">;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TIdentityAwsIamAuthServiceFactory = ReturnType<typeof identityAwsIamAuthServiceFactory>;
|
||||||
|
|
||||||
|
export const identityAwsIamAuthServiceFactory = ({
|
||||||
|
identityAccessTokenDAL,
|
||||||
|
identityAwsIamAuthDAL,
|
||||||
|
identityOrgMembershipDAL,
|
||||||
|
identityDAL,
|
||||||
|
licenseService,
|
||||||
|
permissionService
|
||||||
|
}: TIdentityAwsIamAuthServiceFactoryDep) => {
|
||||||
|
const login = async ({
|
||||||
|
identityId,
|
||||||
|
iamHttpRequestMethod,
|
||||||
|
iamRequestBody,
|
||||||
|
iamRequestHeaders
|
||||||
|
}: TLoginAWSIAMAuthDTO) => {
|
||||||
|
const identityAwsIamAuth = await identityAwsIamAuthDAL.findOne({ identityId });
|
||||||
|
if (!identityAwsIamAuth) throw new UnauthorizedError();
|
||||||
|
|
||||||
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId: identityAwsIamAuth.identityId });
|
||||||
|
|
||||||
|
const headers: TAWSGetCallerIdentityHeaders = JSON.parse(Buffer.from(iamRequestHeaders, "base64").toString());
|
||||||
|
const body: string = Buffer.from(iamRequestBody, "base64").toString();
|
||||||
|
|
||||||
|
const {
|
||||||
|
data: {
|
||||||
|
GetCallerIdentityResponse: {
|
||||||
|
GetCallerIdentityResult: { Account, Arn }
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}: { data: TGetCallerIdentityResponse } = await axios({
|
||||||
|
method: iamHttpRequestMethod,
|
||||||
|
url: identityAwsIamAuth.stsEndpoint,
|
||||||
|
headers,
|
||||||
|
data: body
|
||||||
|
});
|
||||||
|
|
||||||
|
if (identityAwsIamAuth.allowedAccountIds) {
|
||||||
|
// validate if Account is in the list of allowed Account IDs
|
||||||
|
|
||||||
|
const isAccountAllowed = identityAwsIamAuth.allowedAccountIds
|
||||||
|
.split(",")
|
||||||
|
.map((accountId) => accountId.trim())
|
||||||
|
.some((accountId) => accountId === Account);
|
||||||
|
|
||||||
|
if (!isAccountAllowed) throw new UnauthorizedError();
|
||||||
|
}
|
||||||
|
|
||||||
|
if (identityAwsIamAuth.allowedPrincipalArns) {
|
||||||
|
// validate if Arn is in the list of allowed Principal ARNs
|
||||||
|
|
||||||
|
const isArnAllowed = identityAwsIamAuth.allowedPrincipalArns
|
||||||
|
.split(",")
|
||||||
|
.map((principalArn) => principalArn.trim())
|
||||||
|
.some((principalArn) => {
|
||||||
|
// convert wildcard ARN to a regular expression: "arn:aws:iam::123456789012:*" -> "^arn:aws:iam::123456789012:.*$"
|
||||||
|
// considers exact matches + wildcard matches
|
||||||
|
const regex = new RegExp(`^${principalArn.replace(/\*/g, ".*")}$`);
|
||||||
|
return regex.test(extractPrincipalArn(Arn));
|
||||||
|
});
|
||||||
|
|
||||||
|
if (!isArnAllowed) throw new UnauthorizedError();
|
||||||
|
}
|
||||||
|
|
||||||
|
const identityAccessToken = await identityAwsIamAuthDAL.transaction(async (tx) => {
|
||||||
|
const newToken = await identityAccessTokenDAL.create(
|
||||||
|
{
|
||||||
|
identityId: identityAwsIamAuth.identityId,
|
||||||
|
isAccessTokenRevoked: false,
|
||||||
|
accessTokenTTL: identityAwsIamAuth.accessTokenTTL,
|
||||||
|
accessTokenMaxTTL: identityAwsIamAuth.accessTokenMaxTTL,
|
||||||
|
accessTokenNumUses: 0,
|
||||||
|
accessTokenNumUsesLimit: identityAwsIamAuth.accessTokenNumUsesLimit
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
return newToken;
|
||||||
|
});
|
||||||
|
|
||||||
|
const appCfg = getConfig();
|
||||||
|
const accessToken = jwt.sign(
|
||||||
|
{
|
||||||
|
identityId: identityAwsIamAuth.identityId,
|
||||||
|
identityAccessTokenId: identityAccessToken.id,
|
||||||
|
authTokenType: AuthTokenType.IDENTITY_ACCESS_TOKEN
|
||||||
|
} as TIdentityAccessTokenJwtPayload,
|
||||||
|
appCfg.AUTH_SECRET,
|
||||||
|
{
|
||||||
|
expiresIn:
|
||||||
|
Number(identityAccessToken.accessTokenMaxTTL) === 0
|
||||||
|
? undefined
|
||||||
|
: Number(identityAccessToken.accessTokenMaxTTL)
|
||||||
|
}
|
||||||
|
);
|
||||||
|
|
||||||
|
return { accessToken, identityAwsIamAuth, identityAccessToken, identityMembershipOrg };
|
||||||
|
};
|
||||||
|
|
||||||
|
const attachAwsIamAuth = async ({
|
||||||
|
identityId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps,
|
||||||
|
actorId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actor,
|
||||||
|
actorOrgId
|
||||||
|
}: TAttachAWSIAMAuthDTO) => {
|
||||||
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId });
|
||||||
|
if (!identityMembershipOrg) throw new BadRequestError({ message: "Failed to find identity" });
|
||||||
|
if (identityMembershipOrg.identity.authMethod)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to add AWS IAM Auth to already configured identity"
|
||||||
|
});
|
||||||
|
|
||||||
|
if (accessTokenMaxTTL > 0 && accessTokenTTL > accessTokenMaxTTL) {
|
||||||
|
throw new BadRequestError({ message: "Access token TTL cannot be greater than max TTL" });
|
||||||
|
}
|
||||||
|
|
||||||
|
const { permission } = await permissionService.getOrgPermission(
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
identityMembershipOrg.orgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Create, OrgPermissionSubjects.Identity);
|
||||||
|
|
||||||
|
const plan = await licenseService.getPlan(identityMembershipOrg.orgId);
|
||||||
|
const reformattedAccessTokenTrustedIps = accessTokenTrustedIps.map((accessTokenTrustedIp) => {
|
||||||
|
if (
|
||||||
|
!plan.ipAllowlisting &&
|
||||||
|
accessTokenTrustedIp.ipAddress !== "0.0.0.0/0" &&
|
||||||
|
accessTokenTrustedIp.ipAddress !== "::/0"
|
||||||
|
)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message:
|
||||||
|
"Failed to add IP access range to access token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
|
});
|
||||||
|
if (!isValidIpOrCidr(accessTokenTrustedIp.ipAddress))
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "The IP is not a valid IPv4, IPv6, or CIDR block"
|
||||||
|
});
|
||||||
|
return extractIPDetails(accessTokenTrustedIp.ipAddress);
|
||||||
|
});
|
||||||
|
|
||||||
|
const identityAwsIamAuth = await identityAwsIamAuthDAL.transaction(async (tx) => {
|
||||||
|
const doc = await identityAwsIamAuthDAL.create(
|
||||||
|
{
|
||||||
|
identityId: identityMembershipOrg.identityId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps: JSON.stringify(reformattedAccessTokenTrustedIps)
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
await identityDAL.updateById(
|
||||||
|
identityMembershipOrg.identityId,
|
||||||
|
{
|
||||||
|
authMethod: IdentityAuthMethod.AWS_IAM_AUTH
|
||||||
|
},
|
||||||
|
tx
|
||||||
|
);
|
||||||
|
return doc;
|
||||||
|
});
|
||||||
|
return { ...identityAwsIamAuth, orgId: identityMembershipOrg.orgId };
|
||||||
|
};
|
||||||
|
|
||||||
|
const updateAwsIamAuth = async ({
|
||||||
|
identityId,
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps,
|
||||||
|
actorId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actor,
|
||||||
|
actorOrgId
|
||||||
|
}: TUpdateAWSIAMAuthDTO) => {
|
||||||
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId });
|
||||||
|
if (!identityMembershipOrg) throw new BadRequestError({ message: "Failed to find identity" });
|
||||||
|
if (identityMembershipOrg.identity?.authMethod !== IdentityAuthMethod.AWS_IAM_AUTH)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to update AWS IAM Auth"
|
||||||
|
});
|
||||||
|
|
||||||
|
const identityAwsIamAuth = await identityAwsIamAuthDAL.findOne({ identityId });
|
||||||
|
|
||||||
|
if (
|
||||||
|
(accessTokenMaxTTL || identityAwsIamAuth.accessTokenMaxTTL) > 0 &&
|
||||||
|
(accessTokenTTL || identityAwsIamAuth.accessTokenMaxTTL) >
|
||||||
|
(accessTokenMaxTTL || identityAwsIamAuth.accessTokenMaxTTL)
|
||||||
|
) {
|
||||||
|
throw new BadRequestError({ message: "Access token TTL cannot be greater than max TTL" });
|
||||||
|
}
|
||||||
|
|
||||||
|
const { permission } = await permissionService.getOrgPermission(
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
identityMembershipOrg.orgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Edit, OrgPermissionSubjects.Identity);
|
||||||
|
|
||||||
|
const plan = await licenseService.getPlan(identityMembershipOrg.orgId);
|
||||||
|
const reformattedAccessTokenTrustedIps = accessTokenTrustedIps?.map((accessTokenTrustedIp) => {
|
||||||
|
if (
|
||||||
|
!plan.ipAllowlisting &&
|
||||||
|
accessTokenTrustedIp.ipAddress !== "0.0.0.0/0" &&
|
||||||
|
accessTokenTrustedIp.ipAddress !== "::/0"
|
||||||
|
)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message:
|
||||||
|
"Failed to add IP access range to access token due to plan restriction. Upgrade plan to add IP access range."
|
||||||
|
});
|
||||||
|
if (!isValidIpOrCidr(accessTokenTrustedIp.ipAddress))
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "The IP is not a valid IPv4, IPv6, or CIDR block"
|
||||||
|
});
|
||||||
|
return extractIPDetails(accessTokenTrustedIp.ipAddress);
|
||||||
|
});
|
||||||
|
|
||||||
|
const updatedAwsIamAuth = await identityAwsIamAuthDAL.updateById(identityAwsIamAuth.id, {
|
||||||
|
stsEndpoint,
|
||||||
|
allowedPrincipalArns,
|
||||||
|
allowedAccountIds,
|
||||||
|
accessTokenMaxTTL,
|
||||||
|
accessTokenTTL,
|
||||||
|
accessTokenNumUsesLimit,
|
||||||
|
accessTokenTrustedIps: reformattedAccessTokenTrustedIps
|
||||||
|
? JSON.stringify(reformattedAccessTokenTrustedIps)
|
||||||
|
: undefined
|
||||||
|
});
|
||||||
|
|
||||||
|
return { ...updatedAwsIamAuth, orgId: identityMembershipOrg.orgId };
|
||||||
|
};
|
||||||
|
|
||||||
|
const getAwsIamAuth = async ({ identityId, actorId, actor, actorAuthMethod, actorOrgId }: TGetAWSIAMAuthDTO) => {
|
||||||
|
const identityMembershipOrg = await identityOrgMembershipDAL.findOne({ identityId });
|
||||||
|
if (!identityMembershipOrg) throw new BadRequestError({ message: "Failed to find identity" });
|
||||||
|
if (identityMembershipOrg.identity?.authMethod !== IdentityAuthMethod.AWS_IAM_AUTH)
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "The identity does not have AWS IAM Auth attached"
|
||||||
|
});
|
||||||
|
|
||||||
|
const awsIamIdentityAuth = await identityAwsIamAuthDAL.findOne({ identityId });
|
||||||
|
|
||||||
|
const { permission } = await permissionService.getOrgPermission(
|
||||||
|
actor,
|
||||||
|
actorId,
|
||||||
|
identityMembershipOrg.orgId,
|
||||||
|
actorAuthMethod,
|
||||||
|
actorOrgId
|
||||||
|
);
|
||||||
|
ForbiddenError.from(permission).throwUnlessCan(OrgPermissionActions.Read, OrgPermissionSubjects.Identity);
|
||||||
|
return { ...awsIamIdentityAuth, orgId: identityMembershipOrg.orgId };
|
||||||
|
};
|
||||||
|
|
||||||
|
return {
|
||||||
|
login,
|
||||||
|
attachAwsIamAuth,
|
||||||
|
updateAwsIamAuth,
|
||||||
|
getAwsIamAuth
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,54 @@
|
|||||||
|
import { TProjectPermission } from "@app/lib/types";
|
||||||
|
|
||||||
|
export type TLoginAWSIAMAuthDTO = {
|
||||||
|
identityId: string;
|
||||||
|
iamHttpRequestMethod: string;
|
||||||
|
iamRequestBody: string;
|
||||||
|
iamRequestHeaders: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TAttachAWSIAMAuthDTO = {
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint: string;
|
||||||
|
allowedPrincipalArns: string;
|
||||||
|
allowedAccountIds: string;
|
||||||
|
accessTokenTTL: number;
|
||||||
|
accessTokenMaxTTL: number;
|
||||||
|
accessTokenNumUsesLimit: number;
|
||||||
|
accessTokenTrustedIps: { ipAddress: string }[];
|
||||||
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export type TUpdateAWSIAMAuthDTO = {
|
||||||
|
identityId: string;
|
||||||
|
stsEndpoint?: string;
|
||||||
|
allowedPrincipalArns?: string;
|
||||||
|
allowedAccountIds?: string;
|
||||||
|
accessTokenTTL?: number;
|
||||||
|
accessTokenMaxTTL?: number;
|
||||||
|
accessTokenNumUsesLimit?: number;
|
||||||
|
accessTokenTrustedIps?: { ipAddress: string }[];
|
||||||
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export type TGetAWSIAMAuthDTO = {
|
||||||
|
identityId: string;
|
||||||
|
} & Omit<TProjectPermission, "projectId">;
|
||||||
|
|
||||||
|
export type TAWSGetCallerIdentityHeaders = {
|
||||||
|
"Content-Type": string;
|
||||||
|
Host: string;
|
||||||
|
"X-Amz-Date": string;
|
||||||
|
"Content-Length": number;
|
||||||
|
"x-amz-security-token": string;
|
||||||
|
Authorization: string;
|
||||||
|
};
|
||||||
|
|
||||||
|
export type TGetCallerIdentityResponse = {
|
||||||
|
GetCallerIdentityResponse: {
|
||||||
|
GetCallerIdentityResult: {
|
||||||
|
Account: string;
|
||||||
|
Arn: string;
|
||||||
|
UserId: string;
|
||||||
|
};
|
||||||
|
ResponseMetadata: { RequestId: string };
|
||||||
|
};
|
||||||
|
};
|
||||||
@@ -0,0 +1,58 @@
|
|||||||
|
import { z } from "zod";
|
||||||
|
|
||||||
|
const twelveDigitRegex = /^\d{12}$/;
|
||||||
|
const arnRegex = /^arn:aws:iam::\d{12}:(user\/[A-Za-z0-9]+|role\/[A-Za-z0-9]+|\*)$/;
|
||||||
|
|
||||||
|
export const validateAccountIds = z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.default("")
|
||||||
|
// Custom validation to ensure each part is a 12-digit number
|
||||||
|
.refine(
|
||||||
|
(data) => {
|
||||||
|
if (data === "") return true;
|
||||||
|
// Split the string by commas to check each supposed number
|
||||||
|
const accountIds = data.split(",").map((id) => id.trim());
|
||||||
|
// Return true only if every item matches the 12-digit requirement
|
||||||
|
return accountIds.every((id) => twelveDigitRegex.test(id));
|
||||||
|
},
|
||||||
|
{
|
||||||
|
message: "Each account ID must be a 12-digit number."
|
||||||
|
}
|
||||||
|
)
|
||||||
|
// Transform the string to normalize space after commas
|
||||||
|
.transform((data) => {
|
||||||
|
if (data === "") return "";
|
||||||
|
// Trim each ID and join with ', ' to ensure formatting
|
||||||
|
return data
|
||||||
|
.split(",")
|
||||||
|
.map((id) => id.trim())
|
||||||
|
.join(", ");
|
||||||
|
});
|
||||||
|
|
||||||
|
export const validatePrincipalArns = z
|
||||||
|
.string()
|
||||||
|
.trim()
|
||||||
|
.default("")
|
||||||
|
// Custom validation for ARN format
|
||||||
|
.refine(
|
||||||
|
(data) => {
|
||||||
|
// Skip validation if the string is empty
|
||||||
|
if (data === "") return true;
|
||||||
|
// Split the string by commas to check each supposed ARN
|
||||||
|
const arns = data.split(",");
|
||||||
|
// Return true only if every item matches one of the allowed ARN formats
|
||||||
|
return arns.every((arn) => arnRegex.test(arn.trim()));
|
||||||
|
},
|
||||||
|
{
|
||||||
|
message:
|
||||||
|
"Each ARN must be in the format of 'arn:aws:iam::123456789012:user/UserName', 'arn:aws:iam::123456789012:role/RoleName', or 'arn:aws:iam::123456789012:*'."
|
||||||
|
}
|
||||||
|
)
|
||||||
|
// Transform to normalize the spaces around commas
|
||||||
|
.transform((data) =>
|
||||||
|
data
|
||||||
|
.split(",")
|
||||||
|
.map((arn) => arn.trim())
|
||||||
|
.join(", ")
|
||||||
|
);
|
||||||
@@ -0,0 +1,67 @@
|
|||||||
|
/**
|
||||||
|
* Extracts the identity ARN from the GetCallerIdentity response to one of the following formats:
|
||||||
|
* - arn:aws:iam::123456789012:user/MyUserName
|
||||||
|
* - arn:aws:iam::123456789012:role/MyRoleName
|
||||||
|
*/
|
||||||
|
export const extractPrincipalArn = (arn: string) => {
|
||||||
|
// split the ARN into parts using ":" as the delimiter
|
||||||
|
const fullParts = arn.split(":");
|
||||||
|
if (fullParts.length !== 6) {
|
||||||
|
throw new Error(`Unrecognized ARN: contains ${fullParts.length} colon-separated parts, expected 6`);
|
||||||
|
}
|
||||||
|
const [prefix, partition, service, , accountNumber, resource] = fullParts;
|
||||||
|
if (prefix !== "arn") {
|
||||||
|
throw new Error('Unrecognized ARN: does not begin with "arn:"');
|
||||||
|
}
|
||||||
|
|
||||||
|
// structure to hold the parsed data
|
||||||
|
const entity = {
|
||||||
|
Partition: partition,
|
||||||
|
Service: service,
|
||||||
|
AccountNumber: accountNumber,
|
||||||
|
Type: "",
|
||||||
|
Path: "",
|
||||||
|
FriendlyName: "",
|
||||||
|
SessionInfo: ""
|
||||||
|
};
|
||||||
|
|
||||||
|
// validate the service is either 'iam' or 'sts'
|
||||||
|
if (entity.Service !== "iam" && entity.Service !== "sts") {
|
||||||
|
throw new Error(`Unrecognized service: ${entity.Service}, not one of iam or sts`);
|
||||||
|
}
|
||||||
|
|
||||||
|
// parse the last part of the ARN which describes the resource
|
||||||
|
const parts = resource.split("/");
|
||||||
|
if (parts.length < 2) {
|
||||||
|
throw new Error(`Unrecognized ARN: "${resource}" contains fewer than 2 slash-separated parts`);
|
||||||
|
}
|
||||||
|
|
||||||
|
const [type, ...rest] = parts;
|
||||||
|
entity.Type = type;
|
||||||
|
entity.FriendlyName = parts[parts.length - 1];
|
||||||
|
|
||||||
|
// handle different types of resources
|
||||||
|
switch (entity.Type) {
|
||||||
|
case "assumed-role": {
|
||||||
|
if (rest.length < 2) {
|
||||||
|
throw new Error(`Unrecognized ARN: "${resource}" contains fewer than 3 slash-separated parts`);
|
||||||
|
}
|
||||||
|
// assumed roles use a special format where the friendly name is the role name
|
||||||
|
const [roleName, sessionId] = rest;
|
||||||
|
entity.Type = "role"; // treat assumed role case as role
|
||||||
|
entity.FriendlyName = roleName;
|
||||||
|
entity.SessionInfo = sessionId;
|
||||||
|
break;
|
||||||
|
}
|
||||||
|
case "user":
|
||||||
|
case "role":
|
||||||
|
case "instance-profile":
|
||||||
|
// standard cases: just join back the path if there's any
|
||||||
|
entity.Path = rest.slice(0, -1).join("/");
|
||||||
|
break;
|
||||||
|
default:
|
||||||
|
throw new Error(`Unrecognized principal type: "${entity.Type}"`);
|
||||||
|
}
|
||||||
|
|
||||||
|
return `arn:aws:iam::${entity.AccountNumber}:${entity.Type}/${entity.FriendlyName}`;
|
||||||
|
};
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
---
|
||||||
|
title: AWS IAM Auth
|
||||||
|
description: "Learn how to authenticate with Infisical from AWS."
|
||||||
|
---
|
||||||
|
|
||||||
|
**AWS IAM Auth** is an AWS-native authentication method that can be configured for a [machine identity](/documentation/platform/identities/machine-identities) to access Infisical from AWS.
|
||||||
|
|
||||||
|
In this method, each identity is configured to represent one or more IAM principals in AWS with shared privileges.
|
||||||
|
|
||||||
|
## Workflow
|
||||||
|
|
||||||
|
TODO
|
||||||
@@ -80,6 +80,7 @@ using the Universal Auth authentication method.
|
|||||||

|

|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
<Step title="Accessing the Infisical API with the identity">
|
<Step title="Accessing the Infisical API with the identity">
|
||||||
To access the Infisical API as the identity, you should first perform a login operation
|
To access the Infisical API as the identity, you should first perform a login operation
|
||||||
@@ -115,6 +116,7 @@ using the Universal Auth authentication method.
|
|||||||
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
If an identity access token expires, it can no longer authenticate with the Infisical API. In this case,
|
||||||
a new access token should be obtained by performing another login operation.
|
a new access token should be obtained by performing another login operation.
|
||||||
</Note>
|
</Note>
|
||||||
|
|
||||||
</Step>
|
</Step>
|
||||||
</Steps>
|
</Steps>
|
||||||
|
|
||||||
@@ -134,7 +136,8 @@ using the Universal Auth authentication method.
|
|||||||
|
|
||||||
In certain cases, you may want to extend the lifespan of an access token; to do so, you must set a max TTL parameter.
|
In certain cases, you may want to extend the lifespan of an access token; to do so, you must set a max TTL parameter.
|
||||||
|
|
||||||
A token can be renewed any number of time and each call to renew it will extend the toke life by increments of access token TTL.
|
A token can be renewed any number of time and each call to renew it will extend the toke life by increments of access token TTL.
|
||||||
Regardless of how frequently an access token is renewed, its lifespan remains bound to the maximum TTL determined at its creation
|
Regardless of how frequently an access token is renewed, its lifespan remains bound to the maximum TTL determined at its creation
|
||||||
|
|
||||||
</Accordion>
|
</Accordion>
|
||||||
</AccordionGroup>
|
</AccordionGroup>
|
||||||
+2
-3
@@ -152,6 +152,7 @@
|
|||||||
"documentation/platform/auth-methods/email-password",
|
"documentation/platform/auth-methods/email-password",
|
||||||
"documentation/platform/token",
|
"documentation/platform/token",
|
||||||
"documentation/platform/identities/universal-auth",
|
"documentation/platform/identities/universal-auth",
|
||||||
|
"documentation/platform/identities/aws-iam-auth",
|
||||||
"documentation/platform/mfa",
|
"documentation/platform/mfa",
|
||||||
{
|
{
|
||||||
"group": "SSO",
|
"group": "SSO",
|
||||||
@@ -210,9 +211,7 @@
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
"group": "Reference architectures",
|
"group": "Reference architectures",
|
||||||
"pages": [
|
"pages": ["self-hosting/reference-architectures/aws-ecs"]
|
||||||
"self-hosting/reference-architectures/aws-ecs"
|
|
||||||
]
|
|
||||||
},
|
},
|
||||||
"self-hosting/ee",
|
"self-hosting/ee",
|
||||||
"self-hosting/faq"
|
"self-hosting/faq"
|
||||||
|
|||||||
Reference in New Issue
Block a user