UEA-Prodem

This commit is contained in:
2026-06-10 12:38:42 -03:00
parent 3f33154e16
commit c41625e542
9352 changed files with 1128292 additions and 14752 deletions
+201
View File
@@ -0,0 +1,201 @@
Apache License
Version 2.0, January 2004
http://www.apache.org/licenses/
TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
1. Definitions.
"License" shall mean the terms and conditions for use, reproduction,
and distribution as defined by Sections 1 through 9 of this document.
"Licensor" shall mean the copyright owner or entity authorized by
the copyright owner that is granting the License.
"Legal Entity" shall mean the union of the acting entity and all
other entities that control, are controlled by, or are under common
control with that entity. For the purposes of this definition,
"control" means (i) the power, direct or indirect, to cause the
direction or management of such entity, whether by contract or
otherwise, or (ii) ownership of fifty percent (50%) or more of the
outstanding shares, or (iii) beneficial ownership of such entity.
"You" (or "Your") shall mean an individual or Legal Entity
exercising permissions granted by this License.
"Source" form shall mean the preferred form for making modifications,
including but not limited to software source code, documentation
source, and configuration files.
"Object" form shall mean any form resulting from mechanical
transformation or translation of a Source form, including but
not limited to compiled object code, generated documentation,
and conversions to other media types.
"Work" shall mean the work of authorship, whether in Source or
Object form, made available under the License, as indicated by a
copyright notice that is included in or attached to the work
(an example is provided in the Appendix below).
"Derivative Works" shall mean any work, whether in Source or Object
form, that is based on (or derived from) the Work and for which the
editorial revisions, annotations, elaborations, or other modifications
represent, as a whole, an original work of authorship. For the purposes
of this License, Derivative Works shall not include works that remain
separable from, or merely link (or bind by name) to the interfaces of,
the Work and Derivative Works thereof.
"Contribution" shall mean any work of authorship, including
the original version of the Work and any modifications or additions
to that Work or Derivative Works thereof, that is intentionally
submitted to Licensor for inclusion in the Work by the copyright owner
or by an individual or Legal Entity authorized to submit on behalf of
the copyright owner. For the purposes of this definition, "submitted"
means any form of electronic, verbal, or written communication sent
to the Licensor or its representatives, including but not limited to
communication on electronic mailing lists, source code control systems,
and issue tracking systems that are managed by, or on behalf of, the
Licensor for the purpose of discussing and improving the Work, but
excluding communication that is conspicuously marked or otherwise
designated in writing by the copyright owner as "Not a Contribution."
"Contributor" shall mean Licensor and any individual or Legal Entity
on behalf of whom a Contribution has been received by Licensor and
subsequently incorporated within the Work.
2. Grant of Copyright License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
copyright license to reproduce, prepare Derivative Works of,
publicly display, publicly perform, sublicense, and distribute the
Work and such Derivative Works in Source or Object form.
3. Grant of Patent License. Subject to the terms and conditions of
this License, each Contributor hereby grants to You a perpetual,
worldwide, non-exclusive, no-charge, royalty-free, irrevocable
(except as stated in this section) patent license to make, have made,
use, offer to sell, sell, import, and otherwise transfer the Work,
where such license applies only to those patent claims licensable
by such Contributor that are necessarily infringed by their
Contribution(s) alone or by combination of their Contribution(s)
with the Work to which such Contribution(s) was submitted. If You
institute patent litigation against any entity (including a
cross-claim or counterclaim in a lawsuit) alleging that the Work
or a Contribution incorporated within the Work constitutes direct
or contributory patent infringement, then any patent licenses
granted to You under this License for that Work shall terminate
as of the date such litigation is filed.
4. Redistribution. You may reproduce and distribute copies of the
Work or Derivative Works thereof in any medium, with or without
modifications, and in Source or Object form, provided that You
meet the following conditions:
(a) You must give any other recipients of the Work or
Derivative Works a copy of this License; and
(b) You must cause any modified files to carry prominent notices
stating that You changed the files; and
(c) You must retain, in the Source form of any Derivative Works
that You distribute, all copyright, patent, trademark, and
attribution notices from the Source form of the Work,
excluding those notices that do not pertain to any part of
the Derivative Works; and
(d) If the Work includes a "NOTICE" text file as part of its
distribution, then any Derivative Works that You distribute must
include a readable copy of the attribution notices contained
within such NOTICE file, excluding those notices that do not
pertain to any part of the Derivative Works, in at least one
of the following places: within a NOTICE text file distributed
as part of the Derivative Works; within the Source form or
documentation, if provided along with the Derivative Works; or,
within a display generated by the Derivative Works, if and
wherever such third-party notices normally appear. The contents
of the NOTICE file are for informational purposes only and
do not modify the License. You may add Your own attribution
notices within Derivative Works that You distribute, alongside
or as an addendum to the NOTICE text from the Work, provided
that such additional attribution notices cannot be construed
as modifying the License.
You may add Your own copyright statement to Your modifications and
may provide additional or different license terms and conditions
for use, reproduction, or distribution of Your modifications, or
for any such Derivative Works as a whole, provided Your use,
reproduction, and distribution of the Work otherwise complies with
the conditions stated in this License.
5. Submission of Contributions. Unless You explicitly state otherwise,
any Contribution intentionally submitted for inclusion in the Work
by You to the Licensor shall be under the terms and conditions of
this License, without any additional terms or conditions.
Notwithstanding the above, nothing herein shall supersede or modify
the terms of any separate license agreement you may have executed
with Licensor regarding such Contributions.
6. Trademarks. This License does not grant permission to use the trade
names, trademarks, service marks, or product names of the Licensor,
except as required for reasonable and customary use in describing the
origin of the Work and reproducing the content of the NOTICE file.
7. Disclaimer of Warranty. Unless required by applicable law or
agreed to in writing, Licensor provides the Work (and each
Contributor provides its Contributions) on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or
implied, including, without limitation, any warranties or conditions
of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A
PARTICULAR PURPOSE. You are solely responsible for determining the
appropriateness of using or redistributing the Work and assume any
risks associated with Your exercise of permissions under this License.
8. Limitation of Liability. In no event and under no legal theory,
whether in tort (including negligence), contract, or otherwise,
unless required by applicable law (such as deliberate and grossly
negligent acts) or agreed to in writing, shall any Contributor be
liable to You for damages, including any direct, indirect, special,
incidental, or consequential damages of any character arising as a
result of this License or out of the use or inability to use the
Work (including but not limited to damages for loss of goodwill,
work stoppage, computer failure or malfunction, or any and all
other commercial damages or losses), even if such Contributor
has been advised of the possibility of such damages.
9. Accepting Warranty or Additional Liability. While redistributing
the Work or Derivative Works thereof, You may choose to offer,
and charge a fee for, acceptance of support, warranty, indemnity,
or other liability obligations and/or rights consistent with this
License. However, in accepting such obligations, You may act only
on Your own behalf and on Your sole responsibility, not on behalf
of any other Contributor, and only if You agree to indemnify,
defend, and hold each Contributor harmless for any liability
incurred by, or claims asserted against, such Contributor by reason
of your accepting any such warranty or additional liability.
END OF TERMS AND CONDITIONS
APPENDIX: How to apply the Apache License to your work.
To apply the Apache License to your work, attach the following
boilerplate notice, with the fields enclosed by brackets "{}"
replaced with your own identifying information. (Don't include
the brackets!) The text should be enclosed in the appropriate
comment syntax for the file format. We also recommend that a
file or class name and description of purpose be included on the
same "printed page" as the copyright notice for easier
identification within third-party archives.
Copyright 2019 Amazon.com, Inc. or its affiliates. All Rights Reserved.
Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.
+4
View File
@@ -0,0 +1,4 @@
# @aws-sdk/middleware-sdk-s3
[![NPM version](https://img.shields.io/npm/v/@aws-sdk/middleware-sdk-s3/latest.svg)](https://www.npmjs.com/package/@aws-sdk/middleware-sdk-s3)
[![NPM downloads](https://img.shields.io/npm/dm/@aws-sdk/middleware-sdk-s3.svg)](https://www.npmjs.com/package/@aws-sdk/middleware-sdk-s3)
+34
View File
@@ -0,0 +1,34 @@
"use strict";
Object.defineProperty(exports, "__esModule", { value: true });
exports.S3RestXmlProtocol = exports.getValidateBucketNamePlugin = exports.validateBucketNameMiddlewareOptions = exports.validateBucketNameMiddleware = exports.getThrow200ExceptionsPlugin = exports.throw200ExceptionsMiddlewareOptions = exports.throw200ExceptionsMiddleware = exports.s3ExpressHttpSigningMiddlewareOptions = exports.s3ExpressHttpSigningMiddleware = exports.getS3ExpressHttpSigningPlugin = exports.s3ExpressMiddlewareOptions = exports.s3ExpressMiddleware = exports.getS3ExpressPlugin = exports.NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS = exports.SignatureV4S3Express = exports.S3ExpressIdentityProviderImpl = exports.S3ExpressIdentityCacheEntry = exports.S3ExpressIdentityCache = exports.getS3ExpiresMiddlewarePlugin = exports.s3ExpiresMiddlewareOptions = exports.s3ExpiresMiddleware = exports.resolveS3Config = exports.getRegionRedirectMiddlewarePlugin = exports.regionRedirectMiddlewareOptions = exports.regionRedirectMiddleware = exports.regionRedirectEndpointMiddlewareOptions = exports.regionRedirectEndpointMiddleware = exports.getCheckContentLengthHeaderPlugin = exports.checkContentLengthHeaderMiddlewareOptions = exports.checkContentLengthHeader = void 0;
var index_browser_1 = require("./submodules/s3/index.browser");
Object.defineProperty(exports, "checkContentLengthHeader", { enumerable: true, get: function () { return index_browser_1.checkContentLengthHeader; } });
Object.defineProperty(exports, "checkContentLengthHeaderMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.checkContentLengthHeaderMiddlewareOptions; } });
Object.defineProperty(exports, "getCheckContentLengthHeaderPlugin", { enumerable: true, get: function () { return index_browser_1.getCheckContentLengthHeaderPlugin; } });
Object.defineProperty(exports, "regionRedirectEndpointMiddleware", { enumerable: true, get: function () { return index_browser_1.regionRedirectEndpointMiddleware; } });
Object.defineProperty(exports, "regionRedirectEndpointMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.regionRedirectEndpointMiddlewareOptions; } });
Object.defineProperty(exports, "regionRedirectMiddleware", { enumerable: true, get: function () { return index_browser_1.regionRedirectMiddleware; } });
Object.defineProperty(exports, "regionRedirectMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.regionRedirectMiddlewareOptions; } });
Object.defineProperty(exports, "getRegionRedirectMiddlewarePlugin", { enumerable: true, get: function () { return index_browser_1.getRegionRedirectMiddlewarePlugin; } });
Object.defineProperty(exports, "resolveS3Config", { enumerable: true, get: function () { return index_browser_1.resolveS3Config; } });
Object.defineProperty(exports, "s3ExpiresMiddleware", { enumerable: true, get: function () { return index_browser_1.s3ExpiresMiddleware; } });
Object.defineProperty(exports, "s3ExpiresMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.s3ExpiresMiddlewareOptions; } });
Object.defineProperty(exports, "getS3ExpiresMiddlewarePlugin", { enumerable: true, get: function () { return index_browser_1.getS3ExpiresMiddlewarePlugin; } });
Object.defineProperty(exports, "S3ExpressIdentityCache", { enumerable: true, get: function () { return index_browser_1.S3ExpressIdentityCache; } });
Object.defineProperty(exports, "S3ExpressIdentityCacheEntry", { enumerable: true, get: function () { return index_browser_1.S3ExpressIdentityCacheEntry; } });
Object.defineProperty(exports, "S3ExpressIdentityProviderImpl", { enumerable: true, get: function () { return index_browser_1.S3ExpressIdentityProviderImpl; } });
Object.defineProperty(exports, "SignatureV4S3Express", { enumerable: true, get: function () { return index_browser_1.SignatureV4S3Express; } });
Object.defineProperty(exports, "NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS", { enumerable: true, get: function () { return index_browser_1.NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS; } });
Object.defineProperty(exports, "getS3ExpressPlugin", { enumerable: true, get: function () { return index_browser_1.getS3ExpressPlugin; } });
Object.defineProperty(exports, "s3ExpressMiddleware", { enumerable: true, get: function () { return index_browser_1.s3ExpressMiddleware; } });
Object.defineProperty(exports, "s3ExpressMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.s3ExpressMiddlewareOptions; } });
Object.defineProperty(exports, "getS3ExpressHttpSigningPlugin", { enumerable: true, get: function () { return index_browser_1.getS3ExpressHttpSigningPlugin; } });
Object.defineProperty(exports, "s3ExpressHttpSigningMiddleware", { enumerable: true, get: function () { return index_browser_1.s3ExpressHttpSigningMiddleware; } });
Object.defineProperty(exports, "s3ExpressHttpSigningMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.s3ExpressHttpSigningMiddlewareOptions; } });
Object.defineProperty(exports, "throw200ExceptionsMiddleware", { enumerable: true, get: function () { return index_browser_1.throw200ExceptionsMiddleware; } });
Object.defineProperty(exports, "throw200ExceptionsMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.throw200ExceptionsMiddlewareOptions; } });
Object.defineProperty(exports, "getThrow200ExceptionsPlugin", { enumerable: true, get: function () { return index_browser_1.getThrow200ExceptionsPlugin; } });
Object.defineProperty(exports, "validateBucketNameMiddleware", { enumerable: true, get: function () { return index_browser_1.validateBucketNameMiddleware; } });
Object.defineProperty(exports, "validateBucketNameMiddlewareOptions", { enumerable: true, get: function () { return index_browser_1.validateBucketNameMiddlewareOptions; } });
Object.defineProperty(exports, "getValidateBucketNamePlugin", { enumerable: true, get: function () { return index_browser_1.getValidateBucketNamePlugin; } });
Object.defineProperty(exports, "S3RestXmlProtocol", { enumerable: true, get: function () { return index_browser_1.S3RestXmlProtocol; } });
+548
View File
@@ -0,0 +1,548 @@
'use strict';
var client = require('@smithy/core/client');
var protocols = require('@smithy/core/protocols');
var serde = require('@smithy/core/serde');
var signatureV4MultiRegion = require('@aws-sdk/signature-v4-multi-region');
var config = require('@smithy/core/config');
var client$1 = require('@aws-sdk/core/client');
var core = require('@smithy/core');
var node_stream = require('node:stream');
var util = require('@aws-sdk/core/util');
var protocols$1 = require('@aws-sdk/core/protocols');
var schema = require('@smithy/core/schema');
const CONTENT_LENGTH_HEADER = "content-length";
const DECODED_CONTENT_LENGTH_HEADER = "x-amz-decoded-content-length";
function checkContentLengthHeader() {
return (next, context) => async (args) => {
const { request } = args;
if (protocols.HttpRequest.isInstance(request)) {
if (!(CONTENT_LENGTH_HEADER in request.headers) && !(DECODED_CONTENT_LENGTH_HEADER in request.headers)) {
const message = `Are you using a Stream of unknown length as the Body of a PutObject request? Consider using Upload instead from @aws-sdk/lib-storage.`;
if (typeof context?.logger?.warn === "function" && !(context.logger instanceof client.NoOpLogger)) {
context.logger.warn(message);
}
else {
console.warn(message);
}
}
}
return next({ ...args });
};
}
const checkContentLengthHeaderMiddlewareOptions = {
step: "finalizeRequest",
tags: ["CHECK_CONTENT_LENGTH_HEADER"],
name: "getCheckContentLengthHeaderPlugin",
override: true,
};
const getCheckContentLengthHeaderPlugin = (unused) => ({
applyToStack: (clientStack) => {
clientStack.add(checkContentLengthHeader(), checkContentLengthHeaderMiddlewareOptions);
},
});
const regionRedirectEndpointMiddleware = (config) => {
return (next, context) => async (args) => {
const originalRegion = await config.region();
const regionProviderRef = config.region;
let unlock = () => { };
if (context.__s3RegionRedirect) {
Object.defineProperty(config, "region", {
writable: false,
value: async () => {
return context.__s3RegionRedirect;
},
});
unlock = () => Object.defineProperty(config, "region", {
writable: true,
value: regionProviderRef,
});
}
try {
const result = await next(args);
if (context.__s3RegionRedirect) {
unlock();
const region = await config.region();
if (originalRegion !== region) {
throw new Error("Region was not restored following S3 region redirect.");
}
}
return result;
}
catch (e) {
unlock();
throw e;
}
};
};
const regionRedirectEndpointMiddlewareOptions = {
tags: ["REGION_REDIRECT", "S3"],
name: "regionRedirectEndpointMiddleware",
override: true,
relation: "before",
toMiddleware: "endpointV2Middleware",
};
function regionRedirectMiddleware(clientConfig) {
return (next, context) => async (args) => {
try {
return await next(args);
}
catch (err) {
if (clientConfig.followRegionRedirects) {
const statusCode = err?.$metadata?.httpStatusCode;
const isHeadBucket = context.commandName === "HeadBucketCommand";
const bucketRegionHeader = err?.$response?.headers?.["x-amz-bucket-region"];
if (bucketRegionHeader) {
if (statusCode === 301 ||
(statusCode === 400 && (err?.name === "IllegalLocationConstraintException" || isHeadBucket))) {
try {
const actualRegion = bucketRegionHeader;
context.logger?.debug(`Redirecting from ${await clientConfig.region()} to ${actualRegion}`);
context.__s3RegionRedirect = actualRegion;
}
catch (e) {
throw new Error("Region redirect failed: " + e);
}
return next(args);
}
}
}
throw err;
}
};
}
const regionRedirectMiddlewareOptions = {
step: "initialize",
tags: ["REGION_REDIRECT", "S3"],
name: "regionRedirectMiddleware",
override: true,
};
const getRegionRedirectMiddlewarePlugin = (clientConfig) => ({
applyToStack: (clientStack) => {
clientStack.add(regionRedirectMiddleware(clientConfig), regionRedirectMiddlewareOptions);
clientStack.addRelativeTo(regionRedirectEndpointMiddleware(clientConfig), regionRedirectEndpointMiddlewareOptions);
},
});
class S3ExpressIdentityCache {
data;
lastPurgeTime = Date.now();
static EXPIRED_CREDENTIAL_PURGE_INTERVAL_MS = 30_000;
constructor(data = {}) {
this.data = data;
}
get(key) {
const entry = this.data[key];
if (!entry) {
return;
}
return entry;
}
set(key, entry) {
this.data[key] = entry;
return entry;
}
delete(key) {
delete this.data[key];
}
async purgeExpired() {
const now = Date.now();
if (this.lastPurgeTime + S3ExpressIdentityCache.EXPIRED_CREDENTIAL_PURGE_INTERVAL_MS > now) {
return;
}
for (const key in this.data) {
const entry = this.data[key];
if (!entry.isRefreshing) {
const credential = await entry.identity;
if (credential.expiration) {
if (credential.expiration.getTime() < now) {
delete this.data[key];
}
}
}
}
}
}
class S3ExpressIdentityCacheEntry {
_identity;
isRefreshing;
accessed;
constructor(_identity, isRefreshing = false, accessed = Date.now()) {
this._identity = _identity;
this.isRefreshing = isRefreshing;
this.accessed = accessed;
}
get identity() {
this.accessed = Date.now();
return this._identity;
}
}
class S3ExpressIdentityProviderImpl {
createSessionFn;
cache;
static REFRESH_WINDOW_MS = 60_000;
constructor(createSessionFn, cache = new S3ExpressIdentityCache()) {
this.createSessionFn = createSessionFn;
this.cache = cache;
}
async getS3ExpressIdentity(awsIdentity, identityProperties) {
const key = identityProperties.Bucket;
const { cache } = this;
const entry = cache.get(key);
if (entry) {
return entry.identity.then((identity) => {
const isExpired = (identity.expiration?.getTime() ?? 0) < Date.now();
if (isExpired) {
return cache.set(key, new S3ExpressIdentityCacheEntry(this.getIdentity(key))).identity;
}
const isExpiringSoon = (identity.expiration?.getTime() ?? 0) < Date.now() + S3ExpressIdentityProviderImpl.REFRESH_WINDOW_MS;
if (isExpiringSoon && !entry.isRefreshing) {
entry.isRefreshing = true;
this.getIdentity(key).then((id) => {
cache.set(key, new S3ExpressIdentityCacheEntry(Promise.resolve(id)));
});
}
return identity;
});
}
return cache.set(key, new S3ExpressIdentityCacheEntry(this.getIdentity(key))).identity;
}
async getIdentity(key) {
await this.cache.purgeExpired().catch((error) => {
console.warn("Error while clearing expired entries in S3ExpressIdentityCache: \n" + error);
});
const session = await this.createSessionFn(key);
if (!session.Credentials?.AccessKeyId || !session.Credentials?.SecretAccessKey) {
throw new Error("s3#createSession response credential missing AccessKeyId or SecretAccessKey.");
}
const identity = {
accessKeyId: session.Credentials.AccessKeyId,
secretAccessKey: session.Credentials.SecretAccessKey,
sessionToken: session.Credentials.SessionToken,
expiration: session.Credentials.Expiration ? new Date(session.Credentials.Expiration) : undefined,
};
return identity;
}
}
const resolveS3Config = (input, { session, }) => {
const [s3ClientProvider, CreateSessionCommandCtor] = session;
const { forcePathStyle, useAccelerateEndpoint, disableMultiregionAccessPoints, followRegionRedirects, s3ExpressIdentityProvider, bucketEndpoint, expectContinueHeader, } = input;
return Object.assign(input, {
forcePathStyle: forcePathStyle ?? false,
useAccelerateEndpoint: useAccelerateEndpoint ?? false,
disableMultiregionAccessPoints: disableMultiregionAccessPoints ?? false,
followRegionRedirects: followRegionRedirects ?? false,
s3ExpressIdentityProvider: s3ExpressIdentityProvider ??
new S3ExpressIdentityProviderImpl(async (key) => s3ClientProvider().send(new CreateSessionCommandCtor({
Bucket: key,
}))),
bucketEndpoint: bucketEndpoint ?? false,
expectContinueHeader: expectContinueHeader ?? 2_097_152,
});
};
const s3ExpiresMiddleware = (config) => {
return (next, context) => async (args) => {
const result = await next(args);
const { response } = result;
if (protocols.HttpResponse.isInstance(response)) {
if (response.headers.expires) {
response.headers.expiresstring = response.headers.expires;
try {
serde.parseRfc7231DateTime(response.headers.expires);
}
catch (e) {
context.logger?.warn(`AWS SDK Warning for ${context.clientName}::${context.commandName} response parsing (${response.headers.expires}): ${e}`);
delete response.headers.expires;
}
}
}
return result;
};
};
const s3ExpiresMiddlewareOptions = {
tags: ["S3"],
name: "s3ExpiresMiddleware",
override: true,
relation: "after",
toMiddleware: "deserializerMiddleware",
};
const getS3ExpiresMiddlewarePlugin = (clientConfig) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(s3ExpiresMiddleware(), s3ExpiresMiddlewareOptions);
},
});
class SignatureV4S3Express extends signatureV4MultiRegion.SignatureV4SignWithCredentials {
}
const S3_EXPRESS_BUCKET_TYPE = "Directory";
const S3_EXPRESS_BACKEND = "S3Express";
const S3_EXPRESS_AUTH_SCHEME = "sigv4-s3express";
const SESSION_TOKEN_QUERY_PARAM = "X-Amz-S3session-Token";
const SESSION_TOKEN_HEADER = SESSION_TOKEN_QUERY_PARAM.toLowerCase();
const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_ENV_NAME = "AWS_S3_DISABLE_EXPRESS_SESSION_AUTH";
const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_INI_NAME = "s3_disable_express_session_auth";
const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS = {
environmentVariableSelector: (env) => config.booleanSelector(env, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_ENV_NAME, config.SelectorType.ENV),
configFileSelector: (profile) => config.booleanSelector(profile, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_INI_NAME, config.SelectorType.CONFIG),
default: false,
};
const s3ExpressMiddleware = (options) => {
return (next, context) => async (args) => {
if (context.endpointV2) {
const endpoint = context.endpointV2;
const isS3ExpressAuth = endpoint.properties?.authSchemes?.[0]?.name === S3_EXPRESS_AUTH_SCHEME;
const isS3ExpressBucket = endpoint.properties?.backend === S3_EXPRESS_BACKEND ||
endpoint.properties?.bucketType === S3_EXPRESS_BUCKET_TYPE;
if (isS3ExpressBucket) {
client$1.setFeature(context, "S3_EXPRESS_BUCKET", "J");
context.isS3ExpressBucket = true;
}
if (isS3ExpressAuth) {
const requestBucket = args.input.Bucket;
if (requestBucket) {
const s3ExpressIdentity = await options.s3ExpressIdentityProvider.getS3ExpressIdentity(await options.credentials(), {
Bucket: requestBucket,
});
context.s3ExpressIdentity = s3ExpressIdentity;
if (protocols.HttpRequest.isInstance(args.request) && s3ExpressIdentity.sessionToken) {
args.request.headers[SESSION_TOKEN_HEADER] = s3ExpressIdentity.sessionToken;
}
}
}
}
return next(args);
};
};
const s3ExpressMiddlewareOptions = {
name: "s3ExpressMiddleware",
step: "build",
tags: ["S3", "S3_EXPRESS"],
override: true,
};
const getS3ExpressPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(s3ExpressMiddleware(options), s3ExpressMiddlewareOptions);
},
});
const signS3Express = async (s3ExpressIdentity, signingOptions, request, sigV4MultiRegionSigner) => {
const signedRequest = await sigV4MultiRegionSigner.signWithCredentials(request, s3ExpressIdentity, {});
if (signedRequest.headers["X-Amz-Security-Token"] || signedRequest.headers["x-amz-security-token"]) {
throw new Error("X-Amz-Security-Token must not be set for s3-express requests.");
}
return signedRequest;
};
const defaultErrorHandler = (signingProperties) => (error) => {
throw error;
};
const defaultSuccessHandler = (httpResponse, signingProperties) => { };
const s3ExpressHttpSigningMiddlewareOptions = core.httpSigningMiddlewareOptions;
const s3ExpressHttpSigningMiddleware = (config) => (next, context) => async (args) => {
if (!protocols.HttpRequest.isInstance(args.request)) {
return next(args);
}
const smithyContext = client.getSmithyContext(context);
const scheme = smithyContext.selectedHttpAuthScheme;
if (!scheme) {
throw new Error(`No HttpAuthScheme was selected: unable to sign request`);
}
const { httpAuthOption: { signingProperties = {} }, identity, signer, } = scheme;
let request;
if (context.s3ExpressIdentity) {
request = await signS3Express(context.s3ExpressIdentity, signingProperties, args.request, await config.signer());
}
else {
request = await signer.sign(args.request, identity, signingProperties);
}
const output = await next({
...args,
request,
}).catch((signer.errorHandler || defaultErrorHandler)(signingProperties));
(signer.successHandler || defaultSuccessHandler)(output.response, signingProperties);
return output;
};
const getS3ExpressHttpSigningPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(s3ExpressHttpSigningMiddleware(config), core.httpSigningMiddlewareOptions);
},
});
function toStream(bytes) {
return node_stream.Readable.from(Buffer.from(bytes));
}
const THROW_IF_EMPTY_BODY = {
CopyObjectCommand: true,
UploadPartCopyCommand: true,
CompleteMultipartUploadCommand: true,
};
const throw200ExceptionsMiddleware = (config) => (next, context) => async (args) => {
const result = await next(args);
const { response } = result;
if (!protocols.HttpResponse.isInstance(response)) {
return result;
}
const { statusCode, body } = response;
if (statusCode < 200 || statusCode >= 300) {
return result;
}
const bodyBytes = await collectBody(body, config);
response.body = toStream(bodyBytes);
if (bodyBytes.length === 0 && THROW_IF_EMPTY_BODY[context.commandName]) {
const err = new Error("S3 aborted request");
err.$metadata = {
httpStatusCode: 503,
};
err.name = "InternalError";
throw err;
}
const bodyStringTail = config.utf8Encoder(bodyBytes.subarray(bodyBytes.length - 16));
if (bodyStringTail && bodyStringTail.endsWith("</Error>")) {
response.statusCode = 503;
}
return result;
};
const collectBody = (streamBody = new Uint8Array(), context) => {
if (streamBody instanceof Uint8Array) {
return Promise.resolve(streamBody);
}
return context.streamCollector(streamBody) || Promise.resolve(new Uint8Array());
};
const throw200ExceptionsMiddlewareOptions = {
relation: "after",
toMiddleware: "deserializerMiddleware",
tags: ["THROW_200_EXCEPTIONS", "S3"],
name: "throw200ExceptionsMiddleware",
override: true,
};
const getThrow200ExceptionsPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(throw200ExceptionsMiddleware(config), throw200ExceptionsMiddlewareOptions);
},
});
function bucketEndpointMiddleware(options) {
return (next, context) => async (args) => {
if (options.bucketEndpoint) {
const endpoint = context.endpointV2;
if (endpoint) {
const bucket = args.input.Bucket;
if (typeof bucket === "string") {
try {
const bucketEndpointUrl = new URL(bucket);
context.endpointV2 = {
...endpoint,
url: bucketEndpointUrl,
};
}
catch (e) {
const warning = `@aws-sdk/middleware-sdk-s3: bucketEndpoint=true was set but Bucket=${bucket} could not be parsed as URL.`;
if (context.logger?.constructor?.name === "NoOpLogger") {
console.warn(warning);
}
else {
context.logger?.warn?.(warning);
}
throw e;
}
}
}
}
return next(args);
};
}
const bucketEndpointMiddlewareOptions = {
name: "bucketEndpointMiddleware",
override: true,
relation: "after",
toMiddleware: "endpointV2Middleware",
};
function validateBucketNameMiddleware({ bucketEndpoint }) {
return (next) => async (args) => {
const { input: { Bucket }, } = args;
if (!bucketEndpoint && typeof Bucket === "string" && !util.validate(Bucket) && Bucket.indexOf("/") >= 0) {
const err = new Error(`Bucket name shouldn't contain '/', received '${Bucket}'`);
err.name = "InvalidBucketName";
throw err;
}
return next({ ...args });
};
}
const validateBucketNameMiddlewareOptions = {
step: "initialize",
tags: ["VALIDATE_BUCKET_NAME"],
name: "validateBucketNameMiddleware",
override: true,
};
const getValidateBucketNamePlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(validateBucketNameMiddleware(options), validateBucketNameMiddlewareOptions);
clientStack.addRelativeTo(bucketEndpointMiddleware(options), bucketEndpointMiddlewareOptions);
},
});
class S3RestXmlProtocol extends protocols$1.AwsRestXmlProtocol {
async serializeRequest(operationSchema, input, context) {
const request = await super.serializeRequest(operationSchema, input, context);
const ns = schema.NormalizedSchema.of(operationSchema.input);
const staticStructureSchema = ns.getSchema();
let bucketMemberIndex = 0;
const requiredMemberCount = staticStructureSchema[6] ?? 0;
if (input && typeof input === "object") {
for (const [memberName, memberNs] of ns.structIterator()) {
if (++bucketMemberIndex > requiredMemberCount) {
break;
}
if (memberName === "Bucket") {
if (!input.Bucket && memberNs.getMergedTraits().httpLabel) {
throw new Error(`No value provided for input HTTP label: Bucket.`);
}
break;
}
}
}
return request;
}
}
exports.NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS = NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS;
exports.S3ExpressIdentityCache = S3ExpressIdentityCache;
exports.S3ExpressIdentityCacheEntry = S3ExpressIdentityCacheEntry;
exports.S3ExpressIdentityProviderImpl = S3ExpressIdentityProviderImpl;
exports.S3RestXmlProtocol = S3RestXmlProtocol;
exports.SignatureV4S3Express = SignatureV4S3Express;
exports.checkContentLengthHeader = checkContentLengthHeader;
exports.checkContentLengthHeaderMiddlewareOptions = checkContentLengthHeaderMiddlewareOptions;
exports.getCheckContentLengthHeaderPlugin = getCheckContentLengthHeaderPlugin;
exports.getRegionRedirectMiddlewarePlugin = getRegionRedirectMiddlewarePlugin;
exports.getS3ExpiresMiddlewarePlugin = getS3ExpiresMiddlewarePlugin;
exports.getS3ExpressHttpSigningPlugin = getS3ExpressHttpSigningPlugin;
exports.getS3ExpressPlugin = getS3ExpressPlugin;
exports.getThrow200ExceptionsPlugin = getThrow200ExceptionsPlugin;
exports.getValidateBucketNamePlugin = getValidateBucketNamePlugin;
exports.regionRedirectEndpointMiddleware = regionRedirectEndpointMiddleware;
exports.regionRedirectEndpointMiddlewareOptions = regionRedirectEndpointMiddlewareOptions;
exports.regionRedirectMiddleware = regionRedirectMiddleware;
exports.regionRedirectMiddlewareOptions = regionRedirectMiddlewareOptions;
exports.resolveS3Config = resolveS3Config;
exports.s3ExpiresMiddleware = s3ExpiresMiddleware;
exports.s3ExpiresMiddlewareOptions = s3ExpiresMiddlewareOptions;
exports.s3ExpressHttpSigningMiddleware = s3ExpressHttpSigningMiddleware;
exports.s3ExpressHttpSigningMiddlewareOptions = s3ExpressHttpSigningMiddlewareOptions;
exports.s3ExpressMiddleware = s3ExpressMiddleware;
exports.s3ExpressMiddlewareOptions = s3ExpressMiddlewareOptions;
exports.throw200ExceptionsMiddleware = throw200ExceptionsMiddleware;
exports.throw200ExceptionsMiddlewareOptions = throw200ExceptionsMiddlewareOptions;
exports.validateBucketNameMiddleware = validateBucketNameMiddleware;
exports.validateBucketNameMiddlewareOptions = validateBucketNameMiddlewareOptions;
@@ -0,0 +1,215 @@
'use strict';
var s3 = require('@aws-sdk/middleware-sdk-s3/s3');
var client = require('@aws-sdk/core/client');
var util = require('@aws-sdk/core/util');
var protocols = require('@smithy/core/protocols');
function resolveS3ControlConfig(input) {
const { useArnRegion } = input;
return Object.assign(input, {
useArnRegion: typeof useArnRegion === "function" ? useArnRegion : () => Promise.resolve(useArnRegion),
});
}
const CONTEXT_OUTPOST_ID = "outpost_id";
const CONTEXT_ACCOUNT_ID = "account_id";
const CONTEXT_ARN_REGION = "outpost_arn_region";
const CONTEXT_SIGNING_SERVICE = "signing_service";
const CONTEXT_SIGNING_REGION = "signing_region";
const parseOutpostArnablesMiddleaware = (options) => (next, context) => async (args) => {
const { input } = args;
const parameter = input.Name && util.validate(input.Name) ? "Name" : input.Bucket && util.validate(input.Bucket) ? "Bucket" : undefined;
if (!parameter)
return next(args);
const clientRegion = await options.region();
const useArnRegion = await options.useArnRegion();
const useFipsEndpoint = await options.useFipsEndpoint();
const useDualstackEndpoint = await options.useDualstackEndpoint();
const baseRegion = clientRegion;
let clientPartition;
let signingRegion;
if (options.regionInfoProvider) {
({ partition: clientPartition, signingRegion = baseRegion } = (await options.regionInfoProvider(baseRegion, {
useFipsEndpoint,
useDualstackEndpoint,
})));
}
else {
signingRegion = context.endpointV2?.properties?.authSchemes?.[0]?.signingRegion || baseRegion;
clientPartition = client.partition(signingRegion).name;
}
const validatorOptions = {
clientPartition};
let arn;
if (parameter === "Name") {
arn = util.parse(input.Name);
validateOutpostsArn(arn, validatorOptions);
const { outpostId, accesspointName } = parseOutpostsAccessPointArnResource(arn.resource);
input.Name = accesspointName;
context[CONTEXT_OUTPOST_ID] = outpostId;
}
else {
arn = util.parse(input.Bucket);
validateOutpostsArn(arn, validatorOptions);
const { outpostId, bucketName } = parseOutpostBucketArnResource(arn.resource);
input.Bucket = bucketName;
context[CONTEXT_OUTPOST_ID] = outpostId;
}
context[CONTEXT_SIGNING_SERVICE] = arn.service;
context[CONTEXT_SIGNING_REGION] = useArnRegion ? arn.region : signingRegion;
if (!input.AccountId) {
input.AccountId = arn.accountId;
}
if (useArnRegion)
context[CONTEXT_ARN_REGION] = arn.region;
return next(args);
};
const parseOutpostArnablesMiddleawareOptions = {
toMiddleware: "serializerMiddleware",
relation: "before",
tags: ["CONVERT_ARN", "OUTPOST_BUCKET_ARN", "OUTPOST_ACCESS_POINT_ARN", "OUTPOST"],
name: "parseOutpostArnablesMiddleaware",
};
const validateOutpostsArn = (arn, { clientPartition }) => {
const { service, partition, accountId, region } = arn;
s3.validateOutpostService(service);
s3.validatePartition(partition, { clientPartition });
s3.validateAccountId(accountId);
};
const parseOutpostsAccessPointArnResource = (resource) => {
const { outpostId, accesspointName } = s3.getArnResources(resource);
if (!outpostId) {
throw new Error("ARN resource should begin with 'outpost'");
}
return {
outpostId,
accesspointName,
};
};
const parseOutpostBucketArnResource = (resource) => {
const delimiter = resource.includes(":") ? ":" : "/";
const [resourceType, ...rest] = resource.split(delimiter);
if (resourceType === "outpost") {
if (!rest[0] || rest[1] !== "bucket" || !rest[2] || rest.length !== 3) {
throw new Error(`Outpost Bucket ARN should have resource outpost${delimiter}{outpostId}${delimiter}bucket${delimiter}{bucketName}`);
}
const [outpostId, _, bucketName] = rest;
return { outpostId, bucketName };
}
else {
throw new Error(`ARN resource should begin with 'outpost${delimiter}'`);
}
};
const REGEX_S3CONTROL_HOSTNAME = /^(.+\.)?s3-control(-fips)?[.-]([a-z0-9-]+)\./;
const getOutpostEndpoint = (hostname, { isCustomEndpoint, regionOverride, useFipsEndpoint }) => {
if (isCustomEndpoint) {
return hostname;
}
const match = hostname.match(REGEX_S3CONTROL_HOSTNAME);
if (!match) {
return hostname;
}
const [matched, prefix, fips, region] = hostname.match(REGEX_S3CONTROL_HOSTNAME);
return [
`s3-outposts${useFipsEndpoint ? "-fips" : ""}`,
regionOverride || region,
hostname.replace(new RegExp(`^${matched}`), ""),
]
.filter((part) => part !== undefined)
.join(".");
};
const ACCOUNT_ID_HEADER = "x-amz-account-id";
const OUTPOST_ID_HEADER = "x-amz-outpost-id";
const updateArnablesRequestMiddleware = (config) => (next, context) => async (args) => {
const { request } = args;
if (!protocols.HttpRequest.isInstance(request)) {
return next(args);
}
if (context[CONTEXT_ACCOUNT_ID]) {
request.headers[ACCOUNT_ID_HEADER] = context[CONTEXT_ACCOUNT_ID];
}
if (context[CONTEXT_OUTPOST_ID]) {
const { isCustomEndpoint } = config;
const useFipsEndpoint = await config.useFipsEndpoint();
request.headers[OUTPOST_ID_HEADER] = context[CONTEXT_OUTPOST_ID];
request.hostname = getOutpostEndpoint(request.hostname, {
isCustomEndpoint,
regionOverride: context[CONTEXT_ARN_REGION],
useFipsEndpoint,
});
}
return next(args);
};
const updateArnablesRequestMiddlewareOptions = {
toMiddleware: "serializerMiddleware",
relation: "after",
name: "updateArnablesRequestMiddleware",
tags: ["ACCOUNT_ID", "OUTPOST_ID", "OUTPOST"],
};
const getProcessArnablesPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(parseOutpostArnablesMiddleaware(options), parseOutpostArnablesMiddleawareOptions);
clientStack.addRelativeTo(updateArnablesRequestMiddleware(options), updateArnablesRequestMiddlewareOptions);
},
});
const hostPrefixDeduplicationMiddleware = () => {
return (next, context) => (args) => {
return next(args);
};
};
const hostPrefixDeduplicationMiddlewareOptions = {
tags: ["HOST_PREFIX_DEDUPLICATION", "ENDPOINT_V2", "ENDPOINT"],
toMiddleware: "serializerMiddleware",
relation: "after",
name: "hostPrefixDeduplicationMiddleware",
override: true,
};
const getHostPrefixDeduplicationPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(hostPrefixDeduplicationMiddleware(), hostPrefixDeduplicationMiddlewareOptions);
},
});
const redirectFromPostIdMiddleware = (config) => (next, context) => async (args) => {
const { input, request } = args;
if (!protocols.HttpRequest.isInstance(request))
return next(args);
if (input.OutpostId) {
const { isCustomEndpoint } = config;
const useFipsEndpoint = await config.useFipsEndpoint();
request.hostname = getOutpostEndpoint(request.hostname, { isCustomEndpoint, useFipsEndpoint });
context[CONTEXT_SIGNING_SERVICE] = "s3-outposts";
}
return next(args);
};
const redirectFromPostIdMiddlewareOptions = {
step: "build",
name: "redirectFromPostIdMiddleware",
tags: ["OUTPOST"],
override: true,
};
const getRedirectFromPostIdPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(redirectFromPostIdMiddleware(options), redirectFromPostIdMiddlewareOptions);
},
});
exports.getHostPrefixDeduplicationPlugin = getHostPrefixDeduplicationPlugin;
exports.getOutpostEndpoint = getOutpostEndpoint;
exports.getProcessArnablesPlugin = getProcessArnablesPlugin;
exports.getRedirectFromPostIdPlugin = getRedirectFromPostIdPlugin;
exports.hostPrefixDeduplicationMiddleware = hostPrefixDeduplicationMiddleware;
exports.hostPrefixDeduplicationMiddlewareOptions = hostPrefixDeduplicationMiddlewareOptions;
exports.parseOutpostArnablesMiddleaware = parseOutpostArnablesMiddleaware;
exports.parseOutpostArnablesMiddleawareOptions = parseOutpostArnablesMiddleawareOptions;
exports.redirectFromPostIdMiddleware = redirectFromPostIdMiddleware;
exports.redirectFromPostIdMiddlewareOptions = redirectFromPostIdMiddlewareOptions;
exports.resolveS3ControlConfig = resolveS3ControlConfig;
exports.updateArnablesRequestMiddleware = updateArnablesRequestMiddleware;
exports.updateArnablesRequestMiddlewareOptions = updateArnablesRequestMiddlewareOptions;
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
+1
View File
@@ -0,0 +1 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, resolveS3Config, s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, S3ExpressIdentityCache, S3ExpressIdentityCacheEntry, S3ExpressIdentityProviderImpl, SignatureV4S3Express, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS, getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, S3RestXmlProtocol, } from "./submodules/s3/index.browser";
+1
View File
@@ -0,0 +1 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, resolveS3Config, s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, S3ExpressIdentityCache, S3ExpressIdentityCacheEntry, S3ExpressIdentityProviderImpl, SignatureV4S3Express, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS, getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, S3RestXmlProtocol, } from "./submodules/s3/index";
@@ -0,0 +1,7 @@
export { NODE_USE_ARN_REGION_CONFIG_OPTIONS } from "@aws-sdk/middleware-sdk-s3/s3";
export function resolveS3ControlConfig(input) {
const { useArnRegion } = input;
return Object.assign(input, {
useArnRegion: typeof useArnRegion === "function" ? useArnRegion : () => Promise.resolve(useArnRegion),
});
}
@@ -0,0 +1,5 @@
export const CONTEXT_OUTPOST_ID = "outpost_id";
export const CONTEXT_ACCOUNT_ID = "account_id";
export const CONTEXT_ARN_REGION = "outpost_arn_region";
export const CONTEXT_SIGNING_SERVICE = "signing_service";
export const CONTEXT_SIGNING_REGION = "signing_region";
@@ -0,0 +1,7 @@
export { resolveS3ControlConfig } from "./configurations";
export { getProcessArnablesPlugin } from "./middleware-process-arnables/getProcessArnablesPlugin";
export { parseOutpostArnablesMiddleaware, parseOutpostArnablesMiddleawareOptions, } from "./middleware-process-arnables/parse-outpost-arnables";
export { updateArnablesRequestMiddleware, updateArnablesRequestMiddlewareOptions, } from "./middleware-process-arnables/update-arnables-request";
export { getOutpostEndpoint } from "./middleware-process-arnables/getOutpostEndpoint";
export { hostPrefixDeduplicationMiddleware, hostPrefixDeduplicationMiddlewareOptions, getHostPrefixDeduplicationPlugin, } from "./middleware-host-prefix-deduplication/hostPrefixDeduplicationMiddleware";
export { redirectFromPostIdMiddleware, redirectFromPostIdMiddlewareOptions, getRedirectFromPostIdPlugin, } from "./middleware-redirect-from-postid/redirect-from-postid";
@@ -0,0 +1,17 @@
export const hostPrefixDeduplicationMiddleware = () => {
return (next, context) => (args) => {
return next(args);
};
};
export const hostPrefixDeduplicationMiddlewareOptions = {
tags: ["HOST_PREFIX_DEDUPLICATION", "ENDPOINT_V2", "ENDPOINT"],
toMiddleware: "serializerMiddleware",
relation: "after",
name: "hostPrefixDeduplicationMiddleware",
override: true,
};
export const getHostPrefixDeduplicationPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(hostPrefixDeduplicationMiddleware(), hostPrefixDeduplicationMiddlewareOptions);
},
});
@@ -0,0 +1,18 @@
const REGEX_S3CONTROL_HOSTNAME = /^(.+\.)?s3-control(-fips)?[.-]([a-z0-9-]+)\./;
export const getOutpostEndpoint = (hostname, { isCustomEndpoint, regionOverride, useFipsEndpoint }) => {
if (isCustomEndpoint) {
return hostname;
}
const match = hostname.match(REGEX_S3CONTROL_HOSTNAME);
if (!match) {
return hostname;
}
const [matched, prefix, fips, region] = hostname.match(REGEX_S3CONTROL_HOSTNAME);
return [
`s3-outposts${useFipsEndpoint ? "-fips" : ""}`,
regionOverride || region,
hostname.replace(new RegExp(`^${matched}`), ""),
]
.filter((part) => part !== undefined)
.join(".");
};
@@ -0,0 +1,8 @@
import { parseOutpostArnablesMiddleaware, parseOutpostArnablesMiddleawareOptions } from "./parse-outpost-arnables";
import { updateArnablesRequestMiddleware, updateArnablesRequestMiddlewareOptions } from "./update-arnables-request";
export const getProcessArnablesPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(parseOutpostArnablesMiddleaware(options), parseOutpostArnablesMiddleawareOptions);
clientStack.addRelativeTo(updateArnablesRequestMiddleware(options), updateArnablesRequestMiddlewareOptions);
},
});
@@ -0,0 +1,94 @@
import { partition } from "@aws-sdk/core/client";
import { parse as parseArn, validate as validateArn } from "@aws-sdk/core/util";
import { getArnResources as getS3AccesspointArnResources, validateAccountId, validateOutpostService, validatePartition, } from "@aws-sdk/middleware-sdk-s3/s3";
import { CONTEXT_ARN_REGION, CONTEXT_OUTPOST_ID, CONTEXT_SIGNING_REGION, CONTEXT_SIGNING_SERVICE } from "../constants";
export const parseOutpostArnablesMiddleaware = (options) => (next, context) => async (args) => {
const { input } = args;
const parameter = input.Name && validateArn(input.Name) ? "Name" : input.Bucket && validateArn(input.Bucket) ? "Bucket" : undefined;
if (!parameter)
return next(args);
const clientRegion = await options.region();
const useArnRegion = await options.useArnRegion();
const useFipsEndpoint = await options.useFipsEndpoint();
const useDualstackEndpoint = await options.useDualstackEndpoint();
const baseRegion = clientRegion;
let clientPartition;
let signingRegion;
if (options.regionInfoProvider) {
({ partition: clientPartition, signingRegion = baseRegion } = (await options.regionInfoProvider(baseRegion, {
useFipsEndpoint,
useDualstackEndpoint,
})));
}
else {
signingRegion = context.endpointV2?.properties?.authSchemes?.[0]?.signingRegion || baseRegion;
clientPartition = partition(signingRegion).name;
}
const validatorOptions = {
useFipsEndpoint,
useDualstackEndpoint,
clientRegion,
clientPartition,
signingRegion,
useArnRegion,
};
let arn;
if (parameter === "Name") {
arn = parseArn(input.Name);
validateOutpostsArn(arn, validatorOptions);
const { outpostId, accesspointName } = parseOutpostsAccessPointArnResource(arn.resource);
input.Name = accesspointName;
context[CONTEXT_OUTPOST_ID] = outpostId;
}
else {
arn = parseArn(input.Bucket);
validateOutpostsArn(arn, validatorOptions);
const { outpostId, bucketName } = parseOutpostBucketArnResource(arn.resource);
input.Bucket = bucketName;
context[CONTEXT_OUTPOST_ID] = outpostId;
}
context[CONTEXT_SIGNING_SERVICE] = arn.service;
context[CONTEXT_SIGNING_REGION] = useArnRegion ? arn.region : signingRegion;
if (!input.AccountId) {
input.AccountId = arn.accountId;
}
if (useArnRegion)
context[CONTEXT_ARN_REGION] = arn.region;
return next(args);
};
export const parseOutpostArnablesMiddleawareOptions = {
toMiddleware: "serializerMiddleware",
relation: "before",
tags: ["CONVERT_ARN", "OUTPOST_BUCKET_ARN", "OUTPOST_ACCESS_POINT_ARN", "OUTPOST"],
name: "parseOutpostArnablesMiddleaware",
};
const validateOutpostsArn = (arn, { clientPartition }) => {
const { service, partition, accountId, region } = arn;
validateOutpostService(service);
validatePartition(partition, { clientPartition });
validateAccountId(accountId);
};
const parseOutpostsAccessPointArnResource = (resource) => {
const { outpostId, accesspointName } = getS3AccesspointArnResources(resource);
if (!outpostId) {
throw new Error("ARN resource should begin with 'outpost'");
}
return {
outpostId,
accesspointName,
};
};
const parseOutpostBucketArnResource = (resource) => {
const delimiter = resource.includes(":") ? ":" : "/";
const [resourceType, ...rest] = resource.split(delimiter);
if (resourceType === "outpost") {
if (!rest[0] || rest[1] !== "bucket" || !rest[2] || rest.length !== 3) {
throw new Error(`Outpost Bucket ARN should have resource outpost${delimiter}{outpostId}${delimiter}bucket${delimiter}{bucketName}`);
}
const [outpostId, _, bucketName] = rest;
return { outpostId, bucketName };
}
else {
throw new Error(`ARN resource should begin with 'outpost${delimiter}'`);
}
};
@@ -0,0 +1,31 @@
import { HttpRequest } from "@smithy/core/protocols";
import { CONTEXT_ACCOUNT_ID, CONTEXT_ARN_REGION, CONTEXT_OUTPOST_ID } from "../constants";
import { getOutpostEndpoint } from "./getOutpostEndpoint";
const ACCOUNT_ID_HEADER = "x-amz-account-id";
const OUTPOST_ID_HEADER = "x-amz-outpost-id";
export const updateArnablesRequestMiddleware = (config) => (next, context) => async (args) => {
const { request } = args;
if (!HttpRequest.isInstance(request)) {
return next(args);
}
if (context[CONTEXT_ACCOUNT_ID]) {
request.headers[ACCOUNT_ID_HEADER] = context[CONTEXT_ACCOUNT_ID];
}
if (context[CONTEXT_OUTPOST_ID]) {
const { isCustomEndpoint } = config;
const useFipsEndpoint = await config.useFipsEndpoint();
request.headers[OUTPOST_ID_HEADER] = context[CONTEXT_OUTPOST_ID];
request.hostname = getOutpostEndpoint(request.hostname, {
isCustomEndpoint,
regionOverride: context[CONTEXT_ARN_REGION],
useFipsEndpoint,
});
}
return next(args);
};
export const updateArnablesRequestMiddlewareOptions = {
toMiddleware: "serializerMiddleware",
relation: "after",
name: "updateArnablesRequestMiddleware",
tags: ["ACCOUNT_ID", "OUTPOST_ID", "OUTPOST"],
};
@@ -0,0 +1,26 @@
import { HttpRequest } from "@smithy/core/protocols";
import { CONTEXT_SIGNING_SERVICE } from "../constants";
import { getOutpostEndpoint } from "../middleware-process-arnables/getOutpostEndpoint";
export const redirectFromPostIdMiddleware = (config) => (next, context) => async (args) => {
const { input, request } = args;
if (!HttpRequest.isInstance(request))
return next(args);
if (input.OutpostId) {
const { isCustomEndpoint } = config;
const useFipsEndpoint = await config.useFipsEndpoint();
request.hostname = getOutpostEndpoint(request.hostname, { isCustomEndpoint, useFipsEndpoint });
context[CONTEXT_SIGNING_SERVICE] = "s3-outposts";
}
return next(args);
};
export const redirectFromPostIdMiddlewareOptions = {
step: "build",
name: "redirectFromPostIdMiddleware",
tags: ["OUTPOST"],
override: true,
};
export const getRedirectFromPostIdPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(redirectFromPostIdMiddleware(options), redirectFromPostIdMiddlewareOptions);
},
});
@@ -0,0 +1,8 @@
import { booleanSelector, SelectorType } from "@smithy/core/config";
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME = "AWS_S3_DISABLE_MULTIREGION_ACCESS_POINTS";
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME = "s3_disable_multiregion_access_points";
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS = {
environmentVariableSelector: (env) => booleanSelector(env, NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME, SelectorType.ENV),
configFileSelector: (profile) => booleanSelector(profile, NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME, SelectorType.CONFIG),
default: false,
};
@@ -0,0 +1,8 @@
import { booleanSelector, SelectorType } from "@smithy/core/config";
export const NODE_USE_ARN_REGION_ENV_NAME = "AWS_S3_USE_ARN_REGION";
export const NODE_USE_ARN_REGION_INI_NAME = "s3_use_arn_region";
export const NODE_USE_ARN_REGION_CONFIG_OPTIONS = {
environmentVariableSelector: (env) => booleanSelector(env, NODE_USE_ARN_REGION_ENV_NAME, SelectorType.ENV),
configFileSelector: (profile) => booleanSelector(profile, NODE_USE_ARN_REGION_INI_NAME, SelectorType.CONFIG),
default: undefined,
};
@@ -0,0 +1,30 @@
const no = Symbol.for("node-only");
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, } from "./middleware-check-content-length-header/check-content-length-header";
export { regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, } from "./middleware-region-redirect/region-redirect-endpoint-middleware";
export { regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, } from "./middleware-region-redirect/region-redirect-middleware";
export { resolveS3Config } from "./middleware-s3-configuration/s3Configuration";
export { s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, } from "./middleware-s3-expires/s3-expires-middleware";
export { S3ExpressIdentityCache } from "./middleware-s3-express/classes/S3ExpressIdentityCache";
export { S3ExpressIdentityCacheEntry } from "./middleware-s3-express/classes/S3ExpressIdentityCacheEntry";
export { S3ExpressIdentityProviderImpl } from "./middleware-s3-express/classes/S3ExpressIdentityProviderImpl";
export { SignatureV4S3Express } from "./middleware-s3-express/classes/SignatureV4S3Express";
export const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS = no;
export { getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressMiddleware";
export { getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressHttpSigningMiddleware";
export { throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, } from "./middleware-throw-200-exceptions/throw-200-exceptions";
export { validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, } from "./middleware-validate-bucket-name/validate-bucket-name";
export { S3RestXmlProtocol } from "./protocol/S3RestXmlProtocol";
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS = no;
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME = no;
export const NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME = no;
export const NODE_USE_ARN_REGION_CONFIG_OPTIONS = no;
export const NODE_USE_ARN_REGION_ENV_NAME = no;
export const NODE_USE_ARN_REGION_INI_NAME = no;
export { bucketEndpointMiddleware, bucketEndpointMiddlewareOptions, getBucketEndpointPlugin, } from "./middleware-bucket-endpoint/bucketEndpointMiddleware";
export { bucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export { resolveBucketEndpointConfig } from "./middleware-bucket-endpoint/configurations";
export { getArnResources, getSuffixForArnEndpoint, validateOutpostService, validatePartition, validateAccountId, validateRegion, validateDNSHostLabel, validateNoDualstack, validateNoFIPS, } from "./middleware-bucket-endpoint/bucketHostnameUtils";
export { addExpectContinueMiddleware, addExpectContinueMiddlewareOptions, getAddExpectContinuePlugin, } from "./middleware-expect-continue/middleware-expect-continue";
export { locationConstraintMiddleware, locationConstraintMiddlewareOptions, getLocationConstraintPlugin, } from "./middleware-location-constraint/middleware-location-constraint";
export { resolveLocationConstraintConfig } from "./middleware-location-constraint/configuration";
export { ssecMiddleware, ssecMiddlewareOptions, getSsecPlugin, isValidBase64EncodedSSECustomerKey, } from "./middleware-ssec/middleware-ssec";
+25
View File
@@ -0,0 +1,25 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, } from "./middleware-check-content-length-header/check-content-length-header";
export { regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, } from "./middleware-region-redirect/region-redirect-endpoint-middleware";
export { regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, } from "./middleware-region-redirect/region-redirect-middleware";
export { resolveS3Config } from "./middleware-s3-configuration/s3Configuration";
export { s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, } from "./middleware-s3-expires/s3-expires-middleware";
export { S3ExpressIdentityCache } from "./middleware-s3-express/classes/S3ExpressIdentityCache";
export { S3ExpressIdentityCacheEntry } from "./middleware-s3-express/classes/S3ExpressIdentityCacheEntry";
export { S3ExpressIdentityProviderImpl } from "./middleware-s3-express/classes/S3ExpressIdentityProviderImpl";
export { SignatureV4S3Express } from "./middleware-s3-express/classes/SignatureV4S3Express";
export { NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS } from "./middleware-s3-express/constants";
export { getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressMiddleware";
export { getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressHttpSigningMiddleware";
export { throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, } from "./middleware-throw-200-exceptions/throw-200-exceptions";
export { validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, } from "./middleware-validate-bucket-name/validate-bucket-name";
export { S3RestXmlProtocol } from "./protocol/S3RestXmlProtocol";
export { NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS, NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME, NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME, } from "./NodeDisableMultiregionAccessPointConfigOptions";
export { NODE_USE_ARN_REGION_CONFIG_OPTIONS, NODE_USE_ARN_REGION_ENV_NAME, NODE_USE_ARN_REGION_INI_NAME, } from "./NodeUseArnRegionConfigOptions";
export { bucketEndpointMiddleware, bucketEndpointMiddlewareOptions, getBucketEndpointPlugin, } from "./middleware-bucket-endpoint/bucketEndpointMiddleware";
export { bucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export { resolveBucketEndpointConfig } from "./middleware-bucket-endpoint/configurations";
export { getArnResources, getSuffixForArnEndpoint, validateOutpostService, validatePartition, validateAccountId, validateRegion, validateDNSHostLabel, validateNoDualstack, validateNoFIPS, } from "./middleware-bucket-endpoint/bucketHostnameUtils";
export { addExpectContinueMiddleware, addExpectContinueMiddlewareOptions, getAddExpectContinuePlugin, } from "./middleware-expect-continue/middleware-expect-continue";
export { locationConstraintMiddleware, locationConstraintMiddlewareOptions, getLocationConstraintPlugin, } from "./middleware-location-constraint/middleware-location-constraint";
export { resolveLocationConstraintConfig } from "./middleware-location-constraint/configuration";
export { ssecMiddleware, ssecMiddlewareOptions, getSsecPlugin, isValidBase64EncodedSSECustomerKey, } from "./middleware-ssec/middleware-ssec";
@@ -0,0 +1,81 @@
import { parse as parseArn, validate as validateArn } from "@aws-sdk/core/util";
import { HttpRequest } from "@smithy/core/protocols";
import { bucketHostname } from "./bucketHostname";
export const bucketEndpointMiddleware = (options) => (next, context) => async (args) => {
const { Bucket: bucketName } = args.input;
let replaceBucketInPath = options.bucketEndpoint;
const request = args.request;
if (HttpRequest.isInstance(request)) {
if (options.bucketEndpoint) {
request.hostname = bucketName;
}
else if (validateArn(bucketName)) {
const bucketArn = parseArn(bucketName);
const clientRegion = await options.region();
const useDualstackEndpoint = await options.useDualstackEndpoint();
const useFipsEndpoint = await options.useFipsEndpoint();
const { partition, signingRegion = clientRegion } = (await options.regionInfoProvider(clientRegion, { useDualstackEndpoint, useFipsEndpoint })) || {};
const useArnRegion = await options.useArnRegion();
const { hostname, bucketEndpoint, signingRegion: modifiedSigningRegion, signingService, } = bucketHostname({
bucketName: bucketArn,
baseHostname: request.hostname,
accelerateEndpoint: options.useAccelerateEndpoint,
dualstackEndpoint: useDualstackEndpoint,
fipsEndpoint: useFipsEndpoint,
pathStyleEndpoint: options.forcePathStyle,
tlsCompatible: request.protocol === "https:",
useArnRegion,
clientPartition: partition,
clientSigningRegion: signingRegion,
clientRegion: clientRegion,
isCustomEndpoint: options.isCustomEndpoint,
disableMultiregionAccessPoints: await options.disableMultiregionAccessPoints(),
});
if (modifiedSigningRegion && modifiedSigningRegion !== signingRegion) {
context["signing_region"] = modifiedSigningRegion;
}
if (signingService && signingService !== "s3") {
context["signing_service"] = signingService;
}
request.hostname = hostname;
replaceBucketInPath = bucketEndpoint;
}
else {
const clientRegion = await options.region();
const dualstackEndpoint = await options.useDualstackEndpoint();
const fipsEndpoint = await options.useFipsEndpoint();
const { hostname, bucketEndpoint } = bucketHostname({
bucketName,
clientRegion,
baseHostname: request.hostname,
accelerateEndpoint: options.useAccelerateEndpoint,
dualstackEndpoint,
fipsEndpoint,
pathStyleEndpoint: options.forcePathStyle,
tlsCompatible: request.protocol === "https:",
isCustomEndpoint: options.isCustomEndpoint,
});
request.hostname = hostname;
replaceBucketInPath = bucketEndpoint;
}
if (replaceBucketInPath) {
request.path = request.path.replace(/^(\/)?[^\/]+/, "");
if (request.path === "") {
request.path = "/";
}
}
}
return next({ ...args, request });
};
export const bucketEndpointMiddlewareOptions = {
tags: ["BUCKET_ENDPOINT"],
name: "bucketEndpointMiddleware",
relation: "before",
toMiddleware: "hostHeaderMiddleware",
override: true,
};
export const getBucketEndpointPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(bucketEndpointMiddleware(options), bucketEndpointMiddlewareOptions);
},
});
@@ -0,0 +1,106 @@
import { DOT_PATTERN, getArnResources, getSuffix, getSuffixForArnEndpoint, isBucketNameOptions, isDnsCompatibleBucketName, validateAccountId, validateArnEndpointOptions, validateCustomEndpoint, validateDNSHostLabel, validateMrapAlias, validateNoFIPS, validateOutpostService, validatePartition, validateRegionalClient, validateS3Service, validateService, } from "./bucketHostnameUtils";
export const bucketHostname = (options) => {
validateCustomEndpoint(options);
return isBucketNameOptions(options)
?
getEndpointFromBucketName(options)
:
getEndpointFromArn(options);
};
const getEndpointFromBucketName = ({ accelerateEndpoint = false, clientRegion: region, baseHostname, bucketName, dualstackEndpoint = false, fipsEndpoint = false, pathStyleEndpoint = false, tlsCompatible = true, isCustomEndpoint = false, }) => {
const [clientRegion, hostnameSuffix] = isCustomEndpoint ? [region, baseHostname] : getSuffix(baseHostname);
if (pathStyleEndpoint || !isDnsCompatibleBucketName(bucketName) || (tlsCompatible && DOT_PATTERN.test(bucketName))) {
return {
bucketEndpoint: false,
hostname: dualstackEndpoint ? `s3.dualstack.${clientRegion}.${hostnameSuffix}` : baseHostname,
};
}
if (accelerateEndpoint) {
baseHostname = `s3-accelerate${dualstackEndpoint ? ".dualstack" : ""}.${hostnameSuffix}`;
}
else if (dualstackEndpoint) {
baseHostname = `s3.dualstack.${clientRegion}.${hostnameSuffix}`;
}
return {
bucketEndpoint: true,
hostname: `${bucketName}.${baseHostname}`,
};
};
const getEndpointFromArn = (options) => {
const { isCustomEndpoint, baseHostname, clientRegion } = options;
const hostnameSuffix = isCustomEndpoint ? baseHostname : getSuffixForArnEndpoint(baseHostname)[1];
const { pathStyleEndpoint, accelerateEndpoint = false, fipsEndpoint = false, tlsCompatible = true, bucketName, clientPartition = "aws", } = options;
validateArnEndpointOptions({ pathStyleEndpoint, accelerateEndpoint, tlsCompatible });
const { service, partition, accountId, region, resource } = bucketName;
validateService(service);
validatePartition(partition, { clientPartition });
validateAccountId(accountId);
const { accesspointName, outpostId } = getArnResources(resource);
if (service === "s3-object-lambda") {
return getEndpointFromObjectLambdaArn({ ...options, tlsCompatible, bucketName, accesspointName, hostnameSuffix });
}
if (region === "") {
return getEndpointFromMRAPArn({ ...options, clientRegion, mrapAlias: accesspointName, hostnameSuffix });
}
if (outpostId) {
return getEndpointFromOutpostArn({ ...options, clientRegion, outpostId, accesspointName, hostnameSuffix });
}
return getEndpointFromAccessPointArn({ ...options, clientRegion, accesspointName, hostnameSuffix });
};
const getEndpointFromObjectLambdaArn = ({ dualstackEndpoint = false, fipsEndpoint = false, tlsCompatible = true, useArnRegion, clientRegion, clientSigningRegion = clientRegion, accesspointName, bucketName, hostnameSuffix, }) => {
const { accountId, region, service } = bucketName;
validateRegionalClient(clientRegion);
const DNSHostLabel = `${accesspointName}-${accountId}`;
validateDNSHostLabel(DNSHostLabel, { tlsCompatible });
const endpointRegion = useArnRegion ? region : clientRegion;
const signingRegion = useArnRegion ? region : clientSigningRegion;
return {
bucketEndpoint: true,
hostname: `${DNSHostLabel}.${service}${fipsEndpoint ? "-fips" : ""}.${endpointRegion}.${hostnameSuffix}`,
signingRegion,
signingService: service,
};
};
const getEndpointFromMRAPArn = ({ disableMultiregionAccessPoints, dualstackEndpoint = false, isCustomEndpoint, mrapAlias, hostnameSuffix, }) => {
if (disableMultiregionAccessPoints === true) {
throw new Error("SDK is attempting to use a MRAP ARN. Please enable to feature.");
}
validateMrapAlias(mrapAlias);
return {
bucketEndpoint: true,
hostname: `${mrapAlias}${isCustomEndpoint ? "" : `.accesspoint.s3-global`}.${hostnameSuffix}`,
signingRegion: "*",
};
};
const getEndpointFromOutpostArn = ({ useArnRegion, clientRegion, clientSigningRegion = clientRegion, bucketName, outpostId, dualstackEndpoint = false, fipsEndpoint = false, tlsCompatible = true, accesspointName, isCustomEndpoint, hostnameSuffix, }) => {
validateRegionalClient(clientRegion);
const DNSHostLabel = `${accesspointName}-${bucketName.accountId}`;
validateDNSHostLabel(DNSHostLabel, { tlsCompatible });
const endpointRegion = useArnRegion ? bucketName.region : clientRegion;
const signingRegion = useArnRegion ? bucketName.region : clientSigningRegion;
validateOutpostService(bucketName.service);
validateDNSHostLabel(outpostId, { tlsCompatible });
validateNoFIPS(fipsEndpoint);
const hostnamePrefix = `${DNSHostLabel}.${outpostId}`;
return {
bucketEndpoint: true,
hostname: `${hostnamePrefix}${isCustomEndpoint ? "" : `.s3-outposts.${endpointRegion}`}.${hostnameSuffix}`,
signingRegion,
signingService: "s3-outposts",
};
};
const getEndpointFromAccessPointArn = ({ useArnRegion, clientRegion, clientSigningRegion = clientRegion, bucketName, dualstackEndpoint = false, fipsEndpoint = false, tlsCompatible = true, accesspointName, isCustomEndpoint, hostnameSuffix, }) => {
validateRegionalClient(clientRegion);
const hostnamePrefix = `${accesspointName}-${bucketName.accountId}`;
validateDNSHostLabel(hostnamePrefix, { tlsCompatible });
const endpointRegion = useArnRegion ? bucketName.region : clientRegion;
const signingRegion = useArnRegion ? bucketName.region : clientSigningRegion;
validateS3Service(bucketName.service);
return {
bucketEndpoint: true,
hostname: `${hostnamePrefix}${isCustomEndpoint
? ""
: `.s3-accesspoint${fipsEndpoint ? "-fips" : ""}${dualstackEndpoint ? ".dualstack" : ""}.${endpointRegion}`}.${hostnameSuffix}`,
signingRegion,
};
};
@@ -0,0 +1,111 @@
const DOMAIN_PATTERN = /^[a-z0-9][a-z0-9\.\-]{1,61}[a-z0-9]$/;
const IP_ADDRESS_PATTERN = /(\d+\.){3}\d+/;
const DOTS_PATTERN = /\.\./;
export const DOT_PATTERN = /\./;
export const S3_HOSTNAME_PATTERN = /^(.+\.)?s3(-fips)?(\.dualstack)?[.-]([a-z0-9-]+)\./;
const S3_US_EAST_1_ALTNAME_PATTERN = /^s3(-external-1)?\.amazonaws\.com$/;
const AWS_PARTITION_SUFFIX = "amazonaws.com";
export const isBucketNameOptions = (options) => typeof options.bucketName === "string";
export const isDnsCompatibleBucketName = (bucketName) => DOMAIN_PATTERN.test(bucketName) && !IP_ADDRESS_PATTERN.test(bucketName) && !DOTS_PATTERN.test(bucketName);
const getRegionalSuffix = (hostname) => {
const parts = hostname.match(S3_HOSTNAME_PATTERN);
return [parts[4], hostname.replace(new RegExp(`^${parts[0]}`), "")];
};
export const getSuffix = (hostname) => S3_US_EAST_1_ALTNAME_PATTERN.test(hostname) ? ["us-east-1", AWS_PARTITION_SUFFIX] : getRegionalSuffix(hostname);
export const getSuffixForArnEndpoint = (hostname) => S3_US_EAST_1_ALTNAME_PATTERN.test(hostname)
? [hostname.replace(`.${AWS_PARTITION_SUFFIX}`, ""), AWS_PARTITION_SUFFIX]
: getRegionalSuffix(hostname);
export const validateArnEndpointOptions = (options) => {
if (options.pathStyleEndpoint) {
throw new Error("Path-style S3 endpoint is not supported when bucket is an ARN");
}
if (options.accelerateEndpoint) {
throw new Error("Accelerate endpoint is not supported when bucket is an ARN");
}
if (!options.tlsCompatible) {
throw new Error("HTTPS is required when bucket is an ARN");
}
};
export const validateService = (service) => {
if (service !== "s3" && service !== "s3-outposts" && service !== "s3-object-lambda") {
throw new Error("Expect 's3' or 's3-outposts' or 's3-object-lambda' in ARN service component");
}
};
export const validateS3Service = (service) => {
if (service !== "s3") {
throw new Error("Expect 's3' in Accesspoint ARN service component");
}
};
export const validateOutpostService = (service) => {
if (service !== "s3-outposts") {
throw new Error("Expect 's3-posts' in Outpost ARN service component");
}
};
export const validatePartition = (partition, options) => {
if (partition !== options.clientPartition) {
throw new Error(`Partition in ARN is incompatible, got "${partition}" but expected "${options.clientPartition}"`);
}
};
export const validateRegion = (region, options) => { };
export const validateRegionalClient = (region) => {
if (["s3-external-1", "aws-global"].includes(region)) {
throw new Error(`Client region ${region} is not regional`);
}
};
export const validateAccountId = (accountId) => {
if (!/[0-9]{12}/.exec(accountId)) {
throw new Error("Access point ARN accountID does not match regex '[0-9]{12}'");
}
};
export const validateDNSHostLabel = (label, options = { tlsCompatible: true }) => {
if (label.length >= 64 ||
!/^[a-z0-9][a-z0-9.-]*[a-z0-9]$/.test(label) ||
/(\d+\.){3}\d+/.test(label) ||
/[.-]{2}/.test(label) ||
(options?.tlsCompatible && DOT_PATTERN.test(label))) {
throw new Error(`Invalid DNS label ${label}`);
}
};
export const validateCustomEndpoint = (options) => {
if (options.isCustomEndpoint) {
if (options.dualstackEndpoint)
throw new Error("Dualstack endpoint is not supported with custom endpoint");
if (options.accelerateEndpoint)
throw new Error("Accelerate endpoint is not supported with custom endpoint");
}
};
export const getArnResources = (resource) => {
const delimiter = resource.includes(":") ? ":" : "/";
const [resourceType, ...rest] = resource.split(delimiter);
if (resourceType === "accesspoint") {
if (rest.length !== 1 || rest[0] === "") {
throw new Error(`Access Point ARN should have one resource accesspoint${delimiter}{accesspointname}`);
}
return { accesspointName: rest[0] };
}
else if (resourceType === "outpost") {
if (!rest[0] || rest[1] !== "accesspoint" || !rest[2] || rest.length !== 3) {
throw new Error(`Outpost ARN should have resource outpost${delimiter}{outpostId}${delimiter}accesspoint${delimiter}{accesspointName}`);
}
const [outpostId, _, accesspointName] = rest;
return { outpostId, accesspointName };
}
else {
throw new Error(`ARN resource should begin with 'accesspoint${delimiter}' or 'outpost${delimiter}'`);
}
};
export const validateNoDualstack = (dualstackEndpoint) => { };
export const validateNoFIPS = (useFipsEndpoint) => {
if (useFipsEndpoint)
throw new Error(`FIPS region is not supported with Outpost.`);
};
export const validateMrapAlias = (name) => {
try {
name.split(".").forEach((label) => {
validateDNSHostLabel(label);
});
}
catch (e) {
throw new Error(`"${name}" is not a DNS compatible name.`);
}
};
@@ -0,0 +1,12 @@
export function resolveBucketEndpointConfig(input) {
const { bucketEndpoint = false, forcePathStyle = false, useAccelerateEndpoint = false, useArnRegion, disableMultiregionAccessPoints = false, } = input;
return Object.assign(input, {
bucketEndpoint,
forcePathStyle,
useAccelerateEndpoint,
useArnRegion: typeof useArnRegion === "function" ? useArnRegion : () => Promise.resolve(useArnRegion),
disableMultiregionAccessPoints: typeof disableMultiregionAccessPoints === "function"
? disableMultiregionAccessPoints
: () => Promise.resolve(disableMultiregionAccessPoints),
});
}
@@ -0,0 +1,32 @@
import { NoOpLogger } from "@smithy/core/client";
import { HttpRequest } from "@smithy/core/protocols";
const CONTENT_LENGTH_HEADER = "content-length";
const DECODED_CONTENT_LENGTH_HEADER = "x-amz-decoded-content-length";
export function checkContentLengthHeader() {
return (next, context) => async (args) => {
const { request } = args;
if (HttpRequest.isInstance(request)) {
if (!(CONTENT_LENGTH_HEADER in request.headers) && !(DECODED_CONTENT_LENGTH_HEADER in request.headers)) {
const message = `Are you using a Stream of unknown length as the Body of a PutObject request? Consider using Upload instead from @aws-sdk/lib-storage.`;
if (typeof context?.logger?.warn === "function" && !(context.logger instanceof NoOpLogger)) {
context.logger.warn(message);
}
else {
console.warn(message);
}
}
}
return next({ ...args });
};
}
export const checkContentLengthHeaderMiddlewareOptions = {
step: "finalizeRequest",
tags: ["CHECK_CONTENT_LENGTH_HEADER"],
name: "getCheckContentLengthHeaderPlugin",
override: true,
};
export const getCheckContentLengthHeaderPlugin = (unused) => ({
applyToStack: (clientStack) => {
clientStack.add(checkContentLengthHeader(), checkContentLengthHeaderMiddlewareOptions);
},
});
@@ -0,0 +1,41 @@
import { HttpRequest } from "@smithy/core/protocols";
export function addExpectContinueMiddleware(options) {
return (next) => async (args) => {
const { request } = args;
if (options.expectContinueHeader !== false &&
HttpRequest.isInstance(request) &&
request.body &&
options.runtime === "node" &&
options.requestHandler?.constructor?.name !== "FetchHttpHandler") {
let sendHeader = true;
if (typeof options.expectContinueHeader === "number") {
try {
const bodyLength = Number(request.headers?.["content-length"]) ?? options.bodyLengthChecker?.(request.body) ?? Infinity;
sendHeader = bodyLength >= options.expectContinueHeader;
}
catch (e) { }
}
else {
sendHeader = !!options.expectContinueHeader;
}
if (sendHeader) {
request.headers.Expect = "100-continue";
}
}
return next({
...args,
request,
});
};
}
export const addExpectContinueMiddlewareOptions = {
step: "build",
tags: ["SET_EXPECT_HEADER", "EXPECT_HEADER"],
name: "addExpectContinueMiddleware",
override: true,
};
export const getAddExpectContinuePlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(addExpectContinueMiddleware(options), addExpectContinueMiddlewareOptions);
},
});
@@ -0,0 +1,3 @@
export function resolveLocationConstraintConfig(input) {
return input;
}
@@ -0,0 +1,24 @@
export function locationConstraintMiddleware(options) {
return (next) => async (args) => {
const { CreateBucketConfiguration } = args.input;
const region = await options.region();
if (!CreateBucketConfiguration?.LocationConstraint && !CreateBucketConfiguration?.Location) {
if (region !== "us-east-1") {
args.input.CreateBucketConfiguration = args.input.CreateBucketConfiguration ?? {};
args.input.CreateBucketConfiguration.LocationConstraint = region;
}
}
return next(args);
};
}
export const locationConstraintMiddlewareOptions = {
step: "initialize",
tags: ["LOCATION_CONSTRAINT", "CREATE_BUCKET_CONFIGURATION"],
name: "locationConstraintMiddleware",
override: true,
};
export const getLocationConstraintPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.add(locationConstraintMiddleware(config), locationConstraintMiddlewareOptions);
},
});
@@ -0,0 +1,36 @@
export function bucketEndpointMiddleware(options) {
return (next, context) => async (args) => {
if (options.bucketEndpoint) {
const endpoint = context.endpointV2;
if (endpoint) {
const bucket = args.input.Bucket;
if (typeof bucket === "string") {
try {
const bucketEndpointUrl = new URL(bucket);
context.endpointV2 = {
...endpoint,
url: bucketEndpointUrl,
};
}
catch (e) {
const warning = `@aws-sdk/middleware-sdk-s3: bucketEndpoint=true was set but Bucket=${bucket} could not be parsed as URL.`;
if (context.logger?.constructor?.name === "NoOpLogger") {
console.warn(warning);
}
else {
context.logger?.warn?.(warning);
}
throw e;
}
}
}
}
return next(args);
};
}
export const bucketEndpointMiddlewareOptions = {
name: "bucketEndpointMiddleware",
override: true,
relation: "after",
toMiddleware: "endpointV2Middleware",
};
@@ -0,0 +1,41 @@
export const regionRedirectEndpointMiddleware = (config) => {
return (next, context) => async (args) => {
const originalRegion = await config.region();
const regionProviderRef = config.region;
let unlock = () => { };
if (context.__s3RegionRedirect) {
Object.defineProperty(config, "region", {
writable: false,
value: async () => {
return context.__s3RegionRedirect;
},
});
unlock = () => Object.defineProperty(config, "region", {
writable: true,
value: regionProviderRef,
});
}
try {
const result = await next(args);
if (context.__s3RegionRedirect) {
unlock();
const region = await config.region();
if (originalRegion !== region) {
throw new Error("Region was not restored following S3 region redirect.");
}
}
return result;
}
catch (e) {
unlock();
throw e;
}
};
};
export const regionRedirectEndpointMiddlewareOptions = {
tags: ["REGION_REDIRECT", "S3"],
name: "regionRedirectEndpointMiddleware",
override: true,
relation: "before",
toMiddleware: "endpointV2Middleware",
};
@@ -0,0 +1,42 @@
import { regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, } from "./region-redirect-endpoint-middleware";
export function regionRedirectMiddleware(clientConfig) {
return (next, context) => async (args) => {
try {
return await next(args);
}
catch (err) {
if (clientConfig.followRegionRedirects) {
const statusCode = err?.$metadata?.httpStatusCode;
const isHeadBucket = context.commandName === "HeadBucketCommand";
const bucketRegionHeader = err?.$response?.headers?.["x-amz-bucket-region"];
if (bucketRegionHeader) {
if (statusCode === 301 ||
(statusCode === 400 && (err?.name === "IllegalLocationConstraintException" || isHeadBucket))) {
try {
const actualRegion = bucketRegionHeader;
context.logger?.debug(`Redirecting from ${await clientConfig.region()} to ${actualRegion}`);
context.__s3RegionRedirect = actualRegion;
}
catch (e) {
throw new Error("Region redirect failed: " + e);
}
return next(args);
}
}
}
throw err;
}
};
}
export const regionRedirectMiddlewareOptions = {
step: "initialize",
tags: ["REGION_REDIRECT", "S3"],
name: "regionRedirectMiddleware",
override: true,
};
export const getRegionRedirectMiddlewarePlugin = (clientConfig) => ({
applyToStack: (clientStack) => {
clientStack.add(regionRedirectMiddleware(clientConfig), regionRedirectMiddlewareOptions);
clientStack.addRelativeTo(regionRedirectEndpointMiddleware(clientConfig), regionRedirectEndpointMiddlewareOptions);
},
});
@@ -0,0 +1,17 @@
import { S3ExpressIdentityProviderImpl } from "../middleware-s3-express/classes/S3ExpressIdentityProviderImpl";
export const resolveS3Config = (input, { session, }) => {
const [s3ClientProvider, CreateSessionCommandCtor] = session;
const { forcePathStyle, useAccelerateEndpoint, disableMultiregionAccessPoints, followRegionRedirects, s3ExpressIdentityProvider, bucketEndpoint, expectContinueHeader, } = input;
return Object.assign(input, {
forcePathStyle: forcePathStyle ?? false,
useAccelerateEndpoint: useAccelerateEndpoint ?? false,
disableMultiregionAccessPoints: disableMultiregionAccessPoints ?? false,
followRegionRedirects: followRegionRedirects ?? false,
s3ExpressIdentityProvider: s3ExpressIdentityProvider ??
new S3ExpressIdentityProviderImpl(async (key) => s3ClientProvider().send(new CreateSessionCommandCtor({
Bucket: key,
}))),
bucketEndpoint: bucketEndpoint ?? false,
expectContinueHeader: expectContinueHeader ?? 2_097_152,
});
};
@@ -0,0 +1,33 @@
import { HttpResponse } from "@smithy/core/protocols";
import { parseRfc7231DateTime } from "@smithy/core/serde";
export const s3ExpiresMiddleware = (config) => {
return (next, context) => async (args) => {
const result = await next(args);
const { response } = result;
if (HttpResponse.isInstance(response)) {
if (response.headers.expires) {
response.headers.expiresstring = response.headers.expires;
try {
parseRfc7231DateTime(response.headers.expires);
}
catch (e) {
context.logger?.warn(`AWS SDK Warning for ${context.clientName}::${context.commandName} response parsing (${response.headers.expires}): ${e}`);
delete response.headers.expires;
}
}
}
return result;
};
};
export const s3ExpiresMiddlewareOptions = {
tags: ["S3"],
name: "s3ExpiresMiddleware",
override: true,
relation: "after",
toMiddleware: "deserializerMiddleware",
};
export const getS3ExpiresMiddlewarePlugin = (clientConfig) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(s3ExpiresMiddleware(clientConfig), s3ExpiresMiddlewareOptions);
},
});
@@ -0,0 +1,39 @@
export class S3ExpressIdentityCache {
data;
lastPurgeTime = Date.now();
static EXPIRED_CREDENTIAL_PURGE_INTERVAL_MS = 30_000;
constructor(data = {}) {
this.data = data;
}
get(key) {
const entry = this.data[key];
if (!entry) {
return;
}
return entry;
}
set(key, entry) {
this.data[key] = entry;
return entry;
}
delete(key) {
delete this.data[key];
}
async purgeExpired() {
const now = Date.now();
if (this.lastPurgeTime + S3ExpressIdentityCache.EXPIRED_CREDENTIAL_PURGE_INTERVAL_MS > now) {
return;
}
for (const key in this.data) {
const entry = this.data[key];
if (!entry.isRefreshing) {
const credential = await entry.identity;
if (credential.expiration) {
if (credential.expiration.getTime() < now) {
delete this.data[key];
}
}
}
}
}
}
@@ -0,0 +1,14 @@
export class S3ExpressIdentityCacheEntry {
_identity;
isRefreshing;
accessed;
constructor(_identity, isRefreshing = false, accessed = Date.now()) {
this._identity = _identity;
this.isRefreshing = isRefreshing;
this.accessed = accessed;
}
get identity() {
this.accessed = Date.now();
return this._identity;
}
}
@@ -0,0 +1,49 @@
import { S3ExpressIdentityCache } from "./S3ExpressIdentityCache";
import { S3ExpressIdentityCacheEntry } from "./S3ExpressIdentityCacheEntry";
export class S3ExpressIdentityProviderImpl {
createSessionFn;
cache;
static REFRESH_WINDOW_MS = 60_000;
constructor(createSessionFn, cache = new S3ExpressIdentityCache()) {
this.createSessionFn = createSessionFn;
this.cache = cache;
}
async getS3ExpressIdentity(awsIdentity, identityProperties) {
const key = identityProperties.Bucket;
const { cache } = this;
const entry = cache.get(key);
if (entry) {
return entry.identity.then((identity) => {
const isExpired = (identity.expiration?.getTime() ?? 0) < Date.now();
if (isExpired) {
return cache.set(key, new S3ExpressIdentityCacheEntry(this.getIdentity(key))).identity;
}
const isExpiringSoon = (identity.expiration?.getTime() ?? 0) < Date.now() + S3ExpressIdentityProviderImpl.REFRESH_WINDOW_MS;
if (isExpiringSoon && !entry.isRefreshing) {
entry.isRefreshing = true;
this.getIdentity(key).then((id) => {
cache.set(key, new S3ExpressIdentityCacheEntry(Promise.resolve(id)));
});
}
return identity;
});
}
return cache.set(key, new S3ExpressIdentityCacheEntry(this.getIdentity(key))).identity;
}
async getIdentity(key) {
await this.cache.purgeExpired().catch((error) => {
console.warn("Error while clearing expired entries in S3ExpressIdentityCache: \n" + error);
});
const session = await this.createSessionFn(key);
if (!session.Credentials?.AccessKeyId || !session.Credentials?.SecretAccessKey) {
throw new Error("s3#createSession response credential missing AccessKeyId or SecretAccessKey.");
}
const identity = {
accessKeyId: session.Credentials.AccessKeyId,
secretAccessKey: session.Credentials.SecretAccessKey,
sessionToken: session.Credentials.SessionToken,
expiration: session.Credentials.Expiration ? new Date(session.Credentials.Expiration) : undefined,
};
return identity;
}
}
@@ -0,0 +1,3 @@
import { SignatureV4SignWithCredentials } from "@aws-sdk/signature-v4-multi-region";
export class SignatureV4S3Express extends SignatureV4SignWithCredentials {
}
@@ -0,0 +1,13 @@
import { booleanSelector, SelectorType } from "@smithy/core/config";
export const S3_EXPRESS_BUCKET_TYPE = "Directory";
export const S3_EXPRESS_BACKEND = "S3Express";
export const S3_EXPRESS_AUTH_SCHEME = "sigv4-s3express";
export const SESSION_TOKEN_QUERY_PARAM = "X-Amz-S3session-Token";
export const SESSION_TOKEN_HEADER = SESSION_TOKEN_QUERY_PARAM.toLowerCase();
export const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_ENV_NAME = "AWS_S3_DISABLE_EXPRESS_SESSION_AUTH";
export const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_INI_NAME = "s3_disable_express_session_auth";
export const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS = {
environmentVariableSelector: (env) => booleanSelector(env, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_ENV_NAME, SelectorType.ENV),
configFileSelector: (profile) => booleanSelector(profile, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_INI_NAME, SelectorType.CONFIG),
default: false,
};
@@ -0,0 +1,38 @@
import { httpSigningMiddlewareOptions } from "@smithy/core";
import { getSmithyContext } from "@smithy/core/client";
import { HttpRequest } from "@smithy/core/protocols";
import { signS3Express } from "./signS3Express";
const defaultErrorHandler = (signingProperties) => (error) => {
throw error;
};
const defaultSuccessHandler = (httpResponse, signingProperties) => { };
export const s3ExpressHttpSigningMiddlewareOptions = httpSigningMiddlewareOptions;
export const s3ExpressHttpSigningMiddleware = (config) => (next, context) => async (args) => {
if (!HttpRequest.isInstance(args.request)) {
return next(args);
}
const smithyContext = getSmithyContext(context);
const scheme = smithyContext.selectedHttpAuthScheme;
if (!scheme) {
throw new Error(`No HttpAuthScheme was selected: unable to sign request`);
}
const { httpAuthOption: { signingProperties = {} }, identity, signer, } = scheme;
let request;
if (context.s3ExpressIdentity) {
request = await signS3Express(context.s3ExpressIdentity, signingProperties, args.request, await config.signer());
}
else {
request = await signer.sign(args.request, identity, signingProperties);
}
const output = await next({
...args,
request,
}).catch((signer.errorHandler || defaultErrorHandler)(signingProperties));
(signer.successHandler || defaultSuccessHandler)(output.response, signingProperties);
return output;
};
export const getS3ExpressHttpSigningPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(s3ExpressHttpSigningMiddleware(config), httpSigningMiddlewareOptions);
},
});
@@ -0,0 +1,41 @@
import { setFeature } from "@aws-sdk/core/client";
import { HttpRequest } from "@smithy/core/protocols";
import { S3_EXPRESS_AUTH_SCHEME, S3_EXPRESS_BACKEND, S3_EXPRESS_BUCKET_TYPE, SESSION_TOKEN_HEADER } from "../constants";
export const s3ExpressMiddleware = (options) => {
return (next, context) => async (args) => {
if (context.endpointV2) {
const endpoint = context.endpointV2;
const isS3ExpressAuth = endpoint.properties?.authSchemes?.[0]?.name === S3_EXPRESS_AUTH_SCHEME;
const isS3ExpressBucket = endpoint.properties?.backend === S3_EXPRESS_BACKEND ||
endpoint.properties?.bucketType === S3_EXPRESS_BUCKET_TYPE;
if (isS3ExpressBucket) {
setFeature(context, "S3_EXPRESS_BUCKET", "J");
context.isS3ExpressBucket = true;
}
if (isS3ExpressAuth) {
const requestBucket = args.input.Bucket;
if (requestBucket) {
const s3ExpressIdentity = await options.s3ExpressIdentityProvider.getS3ExpressIdentity(await options.credentials(), {
Bucket: requestBucket,
});
context.s3ExpressIdentity = s3ExpressIdentity;
if (HttpRequest.isInstance(args.request) && s3ExpressIdentity.sessionToken) {
args.request.headers[SESSION_TOKEN_HEADER] = s3ExpressIdentity.sessionToken;
}
}
}
}
return next(args);
};
};
export const s3ExpressMiddlewareOptions = {
name: "s3ExpressMiddleware",
step: "build",
tags: ["S3", "S3_EXPRESS"],
override: true,
};
export const getS3ExpressPlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(s3ExpressMiddleware(options), s3ExpressMiddlewareOptions);
},
});
@@ -0,0 +1,7 @@
export const signS3Express = async (s3ExpressIdentity, signingOptions, request, sigV4MultiRegionSigner) => {
const signedRequest = await sigV4MultiRegionSigner.signWithCredentials(request, s3ExpressIdentity, {});
if (signedRequest.headers["X-Amz-Security-Token"] || signedRequest.headers["x-amz-security-token"]) {
throw new Error("X-Amz-Security-Token must not be set for s3-express requests.");
}
return signedRequest;
};
@@ -0,0 +1,66 @@
export function ssecMiddleware(options) {
return (next) => async (args) => {
const input = { ...args.input };
const properties = [
{
target: "SSECustomerKey",
hash: "SSECustomerKeyMD5",
},
{
target: "CopySourceSSECustomerKey",
hash: "CopySourceSSECustomerKeyMD5",
},
];
for (const prop of properties) {
const value = input[prop.target];
if (value) {
let valueForHash;
if (typeof value === "string") {
if (isValidBase64EncodedSSECustomerKey(value, options)) {
valueForHash = options.base64Decoder(value);
}
else {
valueForHash = options.utf8Decoder(value);
input[prop.target] = options.base64Encoder(valueForHash);
}
}
else {
valueForHash = ArrayBuffer.isView(value)
? new Uint8Array(value.buffer, value.byteOffset, value.byteLength)
: new Uint8Array(value);
input[prop.target] = options.base64Encoder(valueForHash);
}
const hash = new options.md5();
hash.update(valueForHash);
input[prop.hash] = options.base64Encoder(await hash.digest());
}
}
return next({
...args,
input,
});
};
}
export const ssecMiddlewareOptions = {
name: "ssecMiddleware",
step: "initialize",
tags: ["SSE"],
override: true,
};
export const getSsecPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.add(ssecMiddleware(config), ssecMiddlewareOptions);
},
});
export function isValidBase64EncodedSSECustomerKey(str, options) {
const base64Regex = /^(?:[A-Za-z0-9+/]{4})*([A-Za-z0-9+/]{2}==|[A-Za-z0-9+/]{3}=)?$/;
if (!base64Regex.test(str))
return false;
try {
const decodedBytes = options.base64Decoder(str);
return decodedBytes.length === 32;
}
catch {
return false;
}
}
@@ -0,0 +1,51 @@
import { HttpResponse } from "@smithy/core/protocols";
import { toStream } from "../to-stream/toStream";
const THROW_IF_EMPTY_BODY = {
CopyObjectCommand: true,
UploadPartCopyCommand: true,
CompleteMultipartUploadCommand: true,
};
export const throw200ExceptionsMiddleware = (config) => (next, context) => async (args) => {
const result = await next(args);
const { response } = result;
if (!HttpResponse.isInstance(response)) {
return result;
}
const { statusCode, body } = response;
if (statusCode < 200 || statusCode >= 300) {
return result;
}
const bodyBytes = await collectBody(body, config);
response.body = toStream(bodyBytes);
if (bodyBytes.length === 0 && THROW_IF_EMPTY_BODY[context.commandName]) {
const err = new Error("S3 aborted request");
err.$metadata = {
httpStatusCode: 503,
};
err.name = "InternalError";
throw err;
}
const bodyStringTail = config.utf8Encoder(bodyBytes.subarray(bodyBytes.length - 16));
if (bodyStringTail && bodyStringTail.endsWith("</Error>")) {
response.statusCode = 503;
}
return result;
};
const collectBody = (streamBody = new Uint8Array(), context) => {
if (streamBody instanceof Uint8Array) {
return Promise.resolve(streamBody);
}
return context.streamCollector(streamBody) || Promise.resolve(new Uint8Array());
};
export const throw200ExceptionsMiddlewareOptions = {
relation: "after",
toMiddleware: "deserializerMiddleware",
tags: ["THROW_200_EXCEPTIONS", "S3"],
name: "throw200ExceptionsMiddleware",
override: true,
};
export const getThrow200ExceptionsPlugin = (config) => ({
applyToStack: (clientStack) => {
clientStack.addRelativeTo(throw200ExceptionsMiddleware(config), throw200ExceptionsMiddlewareOptions);
},
});
@@ -0,0 +1,25 @@
import { validate as validateArn } from "@aws-sdk/core/util";
import { bucketEndpointMiddleware, bucketEndpointMiddlewareOptions, } from "../middleware-region-redirect/bucket-endpoint-middleware";
export function validateBucketNameMiddleware({ bucketEndpoint }) {
return (next) => async (args) => {
const { input: { Bucket }, } = args;
if (!bucketEndpoint && typeof Bucket === "string" && !validateArn(Bucket) && Bucket.indexOf("/") >= 0) {
const err = new Error(`Bucket name shouldn't contain '/', received '${Bucket}'`);
err.name = "InvalidBucketName";
throw err;
}
return next({ ...args });
};
}
export const validateBucketNameMiddlewareOptions = {
step: "initialize",
tags: ["VALIDATE_BUCKET_NAME"],
name: "validateBucketNameMiddleware",
override: true,
};
export const getValidateBucketNamePlugin = (options) => ({
applyToStack: (clientStack) => {
clientStack.add(validateBucketNameMiddleware(options), validateBucketNameMiddlewareOptions);
clientStack.addRelativeTo(bucketEndpointMiddleware(options), bucketEndpointMiddlewareOptions);
},
});
@@ -0,0 +1,25 @@
import { AwsRestXmlProtocol } from "@aws-sdk/core/protocols";
import { NormalizedSchema } from "@smithy/core/schema";
export class S3RestXmlProtocol extends AwsRestXmlProtocol {
async serializeRequest(operationSchema, input, context) {
const request = await super.serializeRequest(operationSchema, input, context);
const ns = NormalizedSchema.of(operationSchema.input);
const staticStructureSchema = ns.getSchema();
let bucketMemberIndex = 0;
const requiredMemberCount = staticStructureSchema[6] ?? 0;
if (input && typeof input === "object") {
for (const [memberName, memberNs] of ns.structIterator()) {
if (++bucketMemberIndex > requiredMemberCount) {
break;
}
if (memberName === "Bucket") {
if (!input.Bucket && memberNs.getMergedTraits().httpLabel) {
throw new Error(`No value provided for input HTTP label: Bucket.`);
}
break;
}
}
}
return request;
}
}
@@ -0,0 +1,8 @@
export function toStream(bytes) {
return new ReadableStream({
start(controller) {
controller.enqueue(bytes);
controller.close();
},
});
}
@@ -0,0 +1,4 @@
import { Readable } from "node:stream";
export function toStream(bytes) {
return Readable.from(Buffer.from(bytes));
}
@@ -0,0 +1,2 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, resolveS3Config, s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, S3ExpressIdentityCache, S3ExpressIdentityCacheEntry, S3ExpressIdentityProviderImpl, SignatureV4S3Express, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS, getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, S3RestXmlProtocol, } from "./submodules/s3/index.browser";
export type { PreviouslyResolved, S3InputConfig, S3ResolvedConfig, S3ExpressIdentity, S3ExpressIdentityProvider, } from "./submodules/s3/index.browser";
+2
View File
@@ -0,0 +1,2 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, resolveS3Config, s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, S3ExpressIdentityCache, S3ExpressIdentityCacheEntry, S3ExpressIdentityProviderImpl, SignatureV4S3Express, NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS, getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, S3RestXmlProtocol, } from "./submodules/s3/index";
export type { PreviouslyResolved, S3InputConfig, S3ResolvedConfig, S3ExpressIdentity, S3ExpressIdentityProvider, } from "./submodules/s3/index";
@@ -0,0 +1,47 @@
import type { Provider, RegionInfoProvider } from "@smithy/types";
export { NODE_USE_ARN_REGION_CONFIG_OPTIONS } from "@aws-sdk/middleware-sdk-s3/s3";
/**
* @public
*/
export interface S3ControlInputConfig {
/**
* Whether to override the request region with the region inferred from requested resource's ARN. Defaults to false
*/
useArnRegion?: boolean | undefined | Provider<boolean | undefined>;
}
interface PreviouslyResolved {
isCustomEndpoint?: boolean;
region: Provider<string>;
regionInfoProvider?: RegionInfoProvider;
useFipsEndpoint: Provider<boolean>;
useDualstackEndpoint: Provider<boolean>;
}
export interface S3ControlResolvedConfig {
/**
* Whether the endpoint is specified by caller.
* @internal
*/
isCustomEndpoint?: boolean;
/**
* Enables FIPS compatible endpoints.
*/
useFipsEndpoint: Provider<boolean>;
/**
* Enables IPv6/IPv4 dualstack endpoint.
*/
useDualstackEndpoint: Provider<boolean>;
/**
* Resolved value for input config {@link S3ControlInputConfig.useArnRegion}
*/
useArnRegion: Provider<boolean | undefined>;
/**
* Resolved value for input config {@link RegionInputConfig.region}
*/
region: Provider<string>;
/**
* Fetch related hostname, signing name or signing region with given region.
* @internal
*/
regionInfoProvider?: RegionInfoProvider;
}
export declare function resolveS3ControlConfig<T>(input: T & PreviouslyResolved & S3ControlInputConfig): T & S3ControlResolvedConfig;
@@ -0,0 +1,5 @@
export declare const CONTEXT_OUTPOST_ID = "outpost_id";
export declare const CONTEXT_ACCOUNT_ID = "account_id";
export declare const CONTEXT_ARN_REGION = "outpost_arn_region";
export declare const CONTEXT_SIGNING_SERVICE = "signing_service";
export declare const CONTEXT_SIGNING_REGION = "signing_region";
@@ -0,0 +1,9 @@
export type { S3ControlInputConfig, S3ControlResolvedConfig } from "./configurations";
export { resolveS3ControlConfig } from "./configurations";
export { getProcessArnablesPlugin } from "./middleware-process-arnables/getProcessArnablesPlugin";
export { parseOutpostArnablesMiddleaware, parseOutpostArnablesMiddleawareOptions, } from "./middleware-process-arnables/parse-outpost-arnables";
export { updateArnablesRequestMiddleware, updateArnablesRequestMiddlewareOptions, } from "./middleware-process-arnables/update-arnables-request";
export { getOutpostEndpoint } from "./middleware-process-arnables/getOutpostEndpoint";
export { hostPrefixDeduplicationMiddleware, hostPrefixDeduplicationMiddlewareOptions, getHostPrefixDeduplicationPlugin, } from "./middleware-host-prefix-deduplication/hostPrefixDeduplicationMiddleware";
export type { RedirectFromPostIdMiddlewareConfig } from "./middleware-redirect-from-postid/redirect-from-postid";
export { redirectFromPostIdMiddleware, redirectFromPostIdMiddlewareOptions, getRedirectFromPostIdPlugin, } from "./middleware-redirect-from-postid/redirect-from-postid";
@@ -0,0 +1,17 @@
import type { Pluggable, RelativeMiddlewareOptions, SerializeMiddleware } from "@smithy/types";
/**
* @internal
* @deprecated - the middleware is no longer necessary since hostPrefix was
* removed by S3Control codegen customization's model preprocessing.
*/
export declare const hostPrefixDeduplicationMiddleware: () => SerializeMiddleware<any, any>;
/**
* @internal
* @deprecated
*/
export declare const hostPrefixDeduplicationMiddlewareOptions: RelativeMiddlewareOptions;
/**
* @internal
* @deprecated
*/
export declare const getHostPrefixDeduplicationPlugin: <T>(config: T) => Pluggable<any, any>;
@@ -0,0 +1,6 @@
export interface GetOutpostEndpointOptions {
isCustomEndpoint?: boolean;
regionOverride?: string;
useFipsEndpoint: boolean;
}
export declare const getOutpostEndpoint: (hostname: string, { isCustomEndpoint, regionOverride, useFipsEndpoint }: GetOutpostEndpointOptions) => string;
@@ -0,0 +1,3 @@
import type { Pluggable } from "@smithy/types";
import type { S3ControlResolvedConfig } from "../configurations";
export declare const getProcessArnablesPlugin: (options: S3ControlResolvedConfig) => Pluggable<any, any>;
@@ -0,0 +1,27 @@
import type { RelativeMiddlewareOptions, SerializeMiddleware } from "@smithy/types";
import type { S3ControlResolvedConfig } from "../configurations";
/**
* @internal
*/
type ArnableInput = {
Name?: string;
Bucket?: string;
AccountId?: string;
};
/**
* Validate input `Name` or `Bucket` parameter is acceptable ARN format. If so, modify the input ARN to inferred
* resource identifier, notify later middleware to redirect request to Outpost endpoint, signing service and signing
* region.
* @internal
*/
export declare const parseOutpostArnablesMiddleaware: (options: S3ControlResolvedConfig) => SerializeMiddleware<ArnableInput, any>;
/**
* This middleware must go after endpoint resolution and before serialization.
* The transform applied to the input.Bucket or input.Name ARN must not have occurred
* by the time endpoint resolution happens, but must have completed by the time serialization
* happens.
*
* @internal
*/
export declare const parseOutpostArnablesMiddleawareOptions: RelativeMiddlewareOptions;
export {};
@@ -0,0 +1,19 @@
import type { Provider, RelativeMiddlewareOptions, SerializeMiddleware } from "@smithy/types";
/**
* @internal
*/
export interface UpdateArnablesRequestMiddlewareConfig {
isCustomEndpoint?: boolean;
useFipsEndpoint: Provider<boolean>;
}
/**
* After outpost request is constructed, redirect request to outpost endpoint and set `x-amz-account-id` and
* `x-amz-outpost-id` headers.
*
* @internal
*/
export declare const updateArnablesRequestMiddleware: (config: UpdateArnablesRequestMiddlewareConfig) => SerializeMiddleware<any, any>;
/**
* @internal
*/
export declare const updateArnablesRequestMiddlewareOptions: RelativeMiddlewareOptions;
@@ -0,0 +1,17 @@
import type { BuildHandlerOptions, BuildMiddleware, Pluggable, Provider } from "@smithy/types";
import type { S3ControlResolvedConfig } from "../configurations";
type InputType = {
OutpostId?: string;
};
export interface RedirectFromPostIdMiddlewareConfig {
isCustomEndpoint?: boolean;
useFipsEndpoint: Provider<boolean>;
}
/**
* If OutpostId is set, redirect hostname to Outpost one, and change signing service to `s3-outposts`.
* Applied to S3Control.CreateBucket and S3Control.ListRegionalBuckets
*/
export declare const redirectFromPostIdMiddleware: (config: RedirectFromPostIdMiddlewareConfig) => BuildMiddleware<InputType, any>;
export declare const redirectFromPostIdMiddlewareOptions: BuildHandlerOptions;
export declare const getRedirectFromPostIdPlugin: (options: S3ControlResolvedConfig) => Pluggable<any, any>;
export {};
@@ -0,0 +1,4 @@
import type { LoadedConfigSelectors } from "@smithy/core/config";
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME = "AWS_S3_DISABLE_MULTIREGION_ACCESS_POINTS";
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME = "s3_disable_multiregion_access_points";
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS: LoadedConfigSelectors<boolean>;
@@ -0,0 +1,9 @@
import type { LoadedConfigSelectors } from "@smithy/core/config";
export declare const NODE_USE_ARN_REGION_ENV_NAME = "AWS_S3_USE_ARN_REGION";
export declare const NODE_USE_ARN_REGION_INI_NAME = "s3_use_arn_region";
/**
* Config to load useArnRegion from environment variables and shared INI files
*
* @internal
*/
export declare const NODE_USE_ARN_REGION_CONFIG_OPTIONS: LoadedConfigSelectors<boolean | undefined>;
@@ -0,0 +1,36 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, } from "./middleware-check-content-length-header/check-content-length-header";
export { regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, } from "./middleware-region-redirect/region-redirect-endpoint-middleware";
export { regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, } from "./middleware-region-redirect/region-redirect-middleware";
export type { PreviouslyResolved } from "./middleware-region-redirect/region-redirect-middleware";
export type { S3InputConfig, S3ResolvedConfig } from "./middleware-s3-configuration/s3Configuration";
export { resolveS3Config } from "./middleware-s3-configuration/s3Configuration";
export { s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, } from "./middleware-s3-expires/s3-expires-middleware";
export { S3ExpressIdentityCache } from "./middleware-s3-express/classes/S3ExpressIdentityCache";
export { S3ExpressIdentityCacheEntry } from "./middleware-s3-express/classes/S3ExpressIdentityCacheEntry";
export { S3ExpressIdentityProviderImpl } from "./middleware-s3-express/classes/S3ExpressIdentityProviderImpl";
export { SignatureV4S3Express } from "./middleware-s3-express/classes/SignatureV4S3Express";
export declare const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS: symbol;
export { getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressMiddleware";
export { getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressHttpSigningMiddleware";
export type { S3ExpressIdentity } from "./middleware-s3-express/interfaces/S3ExpressIdentity";
export type { S3ExpressIdentityProvider } from "./middleware-s3-express/interfaces/S3ExpressIdentityProvider";
export { throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, } from "./middleware-throw-200-exceptions/throw-200-exceptions";
export { validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, } from "./middleware-validate-bucket-name/validate-bucket-name";
export { S3RestXmlProtocol } from "./protocol/S3RestXmlProtocol";
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS: symbol;
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME: symbol;
export declare const NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME: symbol;
export declare const NODE_USE_ARN_REGION_CONFIG_OPTIONS: symbol;
export declare const NODE_USE_ARN_REGION_ENV_NAME: symbol;
export declare const NODE_USE_ARN_REGION_INI_NAME: symbol;
export { bucketEndpointMiddleware, bucketEndpointMiddlewareOptions, getBucketEndpointPlugin, } from "./middleware-bucket-endpoint/bucketEndpointMiddleware";
export type { BucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export { bucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export type { BucketEndpointInputConfig, BucketEndpointResolvedConfig, } from "./middleware-bucket-endpoint/configurations";
export { resolveBucketEndpointConfig } from "./middleware-bucket-endpoint/configurations";
export { getArnResources, getSuffixForArnEndpoint, validateOutpostService, validatePartition, validateAccountId, validateRegion, validateDNSHostLabel, validateNoDualstack, validateNoFIPS, } from "./middleware-bucket-endpoint/bucketHostnameUtils";
export { addExpectContinueMiddleware, addExpectContinueMiddlewareOptions, getAddExpectContinuePlugin, } from "./middleware-expect-continue/middleware-expect-continue";
export { locationConstraintMiddleware, locationConstraintMiddlewareOptions, getLocationConstraintPlugin, } from "./middleware-location-constraint/middleware-location-constraint";
export type { LocationConstraintInputConfig, LocationConstraintResolvedConfig, } from "./middleware-location-constraint/configuration";
export { resolveLocationConstraintConfig } from "./middleware-location-constraint/configuration";
export { ssecMiddleware, ssecMiddlewareOptions, getSsecPlugin, isValidBase64EncodedSSECustomerKey, } from "./middleware-ssec/middleware-ssec";
@@ -0,0 +1,32 @@
export { checkContentLengthHeader, checkContentLengthHeaderMiddlewareOptions, getCheckContentLengthHeaderPlugin, } from "./middleware-check-content-length-header/check-content-length-header";
export { regionRedirectEndpointMiddleware, regionRedirectEndpointMiddlewareOptions, } from "./middleware-region-redirect/region-redirect-endpoint-middleware";
export { regionRedirectMiddleware, regionRedirectMiddlewareOptions, getRegionRedirectMiddlewarePlugin, } from "./middleware-region-redirect/region-redirect-middleware";
export type { PreviouslyResolved } from "./middleware-region-redirect/region-redirect-middleware";
export type { S3InputConfig, S3ResolvedConfig } from "./middleware-s3-configuration/s3Configuration";
export { resolveS3Config } from "./middleware-s3-configuration/s3Configuration";
export { s3ExpiresMiddleware, s3ExpiresMiddlewareOptions, getS3ExpiresMiddlewarePlugin, } from "./middleware-s3-expires/s3-expires-middleware";
export { S3ExpressIdentityCache } from "./middleware-s3-express/classes/S3ExpressIdentityCache";
export { S3ExpressIdentityCacheEntry } from "./middleware-s3-express/classes/S3ExpressIdentityCacheEntry";
export { S3ExpressIdentityProviderImpl } from "./middleware-s3-express/classes/S3ExpressIdentityProviderImpl";
export { SignatureV4S3Express } from "./middleware-s3-express/classes/SignatureV4S3Express";
export { NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS } from "./middleware-s3-express/constants";
export { getS3ExpressPlugin, s3ExpressMiddleware, s3ExpressMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressMiddleware";
export { getS3ExpressHttpSigningPlugin, s3ExpressHttpSigningMiddleware, s3ExpressHttpSigningMiddlewareOptions, } from "./middleware-s3-express/functions/s3ExpressHttpSigningMiddleware";
export type { S3ExpressIdentity } from "./middleware-s3-express/interfaces/S3ExpressIdentity";
export type { S3ExpressIdentityProvider } from "./middleware-s3-express/interfaces/S3ExpressIdentityProvider";
export { throw200ExceptionsMiddleware, throw200ExceptionsMiddlewareOptions, getThrow200ExceptionsPlugin, } from "./middleware-throw-200-exceptions/throw-200-exceptions";
export { validateBucketNameMiddleware, validateBucketNameMiddlewareOptions, getValidateBucketNamePlugin, } from "./middleware-validate-bucket-name/validate-bucket-name";
export { S3RestXmlProtocol } from "./protocol/S3RestXmlProtocol";
export { NODE_DISABLE_MULTIREGION_ACCESS_POINT_CONFIG_OPTIONS, NODE_DISABLE_MULTIREGION_ACCESS_POINT_ENV_NAME, NODE_DISABLE_MULTIREGION_ACCESS_POINT_INI_NAME, } from "./NodeDisableMultiregionAccessPointConfigOptions";
export { NODE_USE_ARN_REGION_CONFIG_OPTIONS, NODE_USE_ARN_REGION_ENV_NAME, NODE_USE_ARN_REGION_INI_NAME, } from "./NodeUseArnRegionConfigOptions";
export { bucketEndpointMiddleware, bucketEndpointMiddlewareOptions, getBucketEndpointPlugin, } from "./middleware-bucket-endpoint/bucketEndpointMiddleware";
export type { BucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export { bucketHostname } from "./middleware-bucket-endpoint/bucketHostname";
export type { BucketEndpointInputConfig, BucketEndpointResolvedConfig, } from "./middleware-bucket-endpoint/configurations";
export { resolveBucketEndpointConfig } from "./middleware-bucket-endpoint/configurations";
export { getArnResources, getSuffixForArnEndpoint, validateOutpostService, validatePartition, validateAccountId, validateRegion, validateDNSHostLabel, validateNoDualstack, validateNoFIPS, } from "./middleware-bucket-endpoint/bucketHostnameUtils";
export { addExpectContinueMiddleware, addExpectContinueMiddlewareOptions, getAddExpectContinuePlugin, } from "./middleware-expect-continue/middleware-expect-continue";
export { locationConstraintMiddleware, locationConstraintMiddlewareOptions, getLocationConstraintPlugin, } from "./middleware-location-constraint/middleware-location-constraint";
export type { LocationConstraintInputConfig, LocationConstraintResolvedConfig, } from "./middleware-location-constraint/configuration";
export { resolveLocationConstraintConfig } from "./middleware-location-constraint/configuration";
export { ssecMiddleware, ssecMiddlewareOptions, getSsecPlugin, isValidBase64EncodedSSECustomerKey, } from "./middleware-ssec/middleware-ssec";
@@ -0,0 +1,17 @@
import type { BuildMiddleware, Pluggable, RelativeMiddlewareOptions } from "@smithy/types";
import type { BucketEndpointResolvedConfig } from "./configurations";
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const bucketEndpointMiddleware: (options: BucketEndpointResolvedConfig) => BuildMiddleware<any, any>;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const bucketEndpointMiddlewareOptions: RelativeMiddlewareOptions;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const getBucketEndpointPlugin: (options: BucketEndpointResolvedConfig) => Pluggable<any, any>;
@@ -0,0 +1,16 @@
import type { ArnHostnameParams, BucketHostnameParams } from "./bucketHostnameUtils";
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export interface BucketHostname {
hostname: string;
bucketEndpoint: boolean;
signingRegion?: string;
signingService?: string;
}
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const bucketHostname: (options: BucketHostnameParams | ArnHostnameParams) => BucketHostname;
@@ -0,0 +1,174 @@
import type { ARN } from "@aws-sdk/core/util";
/**
* @deprecated unused as of EndpointsV2.
*/
export declare const DOT_PATTERN: RegExp;
/**
* @deprecated unused as of EndpointsV2.
*/
export declare const S3_HOSTNAME_PATTERN: RegExp;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export interface AccessPointArn extends ARN {
accessPointName: string;
}
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export interface BucketHostnameParams {
isCustomEndpoint?: boolean;
baseHostname: string;
bucketName: string;
clientRegion: string;
accelerateEndpoint?: boolean;
dualstackEndpoint?: boolean;
fipsEndpoint?: boolean;
pathStyleEndpoint?: boolean;
tlsCompatible?: boolean;
}
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export interface ArnHostnameParams extends Omit<BucketHostnameParams, "bucketName"> {
bucketName: ARN;
clientSigningRegion?: string;
clientPartition?: string;
useArnRegion?: boolean;
disableMultiregionAccessPoints?: boolean;
}
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const isBucketNameOptions: (options: BucketHostnameParams | ArnHostnameParams) => options is BucketHostnameParams;
/**
* Determines whether a given string is DNS compliant per the rules outlined by
* S3. Length, capitaization, and leading dot restrictions are enforced by the
* DOMAIN_PATTERN regular expression.
* @internal
*
* @see https://docs.aws.amazon.com/AmazonS3/latest/dev/BucketRestrictions.html
*
* @deprecated unused as of EndpointsV2.
*/
export declare const isDnsCompatibleBucketName: (bucketName: string) => boolean;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const getSuffix: (hostname: string) => [string, string];
/**
* Infer region and hostname suffix from a complete hostname
* @internal
* @param hostname - Hostname
* @returns [Region, Hostname suffix]
*
* @deprecated unused as of EndpointsV2.
*/
export declare const getSuffixForArnEndpoint: (hostname: string) => [string, string];
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const validateArnEndpointOptions: (options: {
accelerateEndpoint?: boolean;
tlsCompatible?: boolean;
pathStyleEndpoint?: boolean;
}) => void;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const validateService: (service: string) => void;
/**
* @deprecated unused as of EndpointsV2.
* @internal
*/
export declare const validateS3Service: (service: string) => void;
/**
* @internal
*/
export declare const validateOutpostService: (service: string) => void;
/**
* Validate partition inferred from ARN is the same to `options.clientPartition`.
* @internal
*/
export declare const validatePartition: (partition: string, options: {
clientPartition: string;
}) => void;
/**
* (Previous to deprecation)
* validate region value inferred from ARN. If `options.useArnRegion` is set, it validates the region is not a FIPS
* region. If `options.useArnRegion` is unset, it validates the region is equal to `options.clientRegion` or
* `options.clientSigningRegion`.
*
* @internal
*
* @deprecated validation is deferred to the endpoint ruleset.
*/
export declare const validateRegion: (region: string, options: {
useArnRegion?: boolean;
allowFipsRegion?: boolean;
clientRegion: string;
clientSigningRegion: string;
useFipsEndpoint: boolean;
}) => void;
/**
* @deprecated unused as of EndpointsV2.
*/
export declare const validateRegionalClient: (region: string) => void;
/**
* Validate an account ID
* @internal
*/
export declare const validateAccountId: (accountId: string) => void;
/**
* Validate a host label according to https://tools.ietf.org/html/rfc3986#section-3.2.2
* @internal
* @deprecated unused as of EndpointsV2.
*/
export declare const validateDNSHostLabel: (label: string, options?: {
tlsCompatible?: boolean;
}) => void;
/**
* @deprecated unused as of EndpointsV2.
*/
export declare const validateCustomEndpoint: (options: {
isCustomEndpoint?: boolean;
dualstackEndpoint?: boolean;
accelerateEndpoint?: boolean;
}) => void;
/**
* Validate and parse an Access Point ARN or Outposts ARN
* @internal
*
* @param resource - The resource section of an ARN
* @returns Access Point Name and optional Outpost ID.
*/
export declare const getArnResources: (resource: string) => {
accesspointName: string;
outpostId?: string;
};
/**
* (Prior to deprecation) Throw if dual stack configuration is set to true.
* @internal
*
* @deprecated validation deferred to endpoints ruleset.
*/
export declare const validateNoDualstack: (dualstackEndpoint?: boolean) => void;
/**
* Validate fips endpoint is not set up.
* @internal
* @deprecated unused as of EndpointsV2.
*/
export declare const validateNoFIPS: (useFipsEndpoint?: boolean) => void;
/**
* Validate the multi-region access point alias.
* @internal
* @deprecated unused as of EndpointsV2.
*/
export declare const validateMrapAlias: (name: string) => void;
@@ -0,0 +1,95 @@
import type { Provider, RegionInfoProvider } from "@smithy/types";
/**
* @deprecated unused as of EndpointsV2.
*/
export interface BucketEndpointInputConfig {
/**
* Whether to use the bucket name as the endpoint for this request. The bucket
* name must be a domain name with a CNAME record alias to an appropriate virtual
* hosted-style S3 hostname, e.g. a bucket of `images.johnsmith.net` and a DNS
* record of:
*
* ```
* images.johnsmith.net CNAME images.johnsmith.net.s3.amazonaws.com.
* ```
*
* @see https://docs.aws.amazon.com/AmazonS3/latest/userguide/VirtualHosting.html#VirtualHostingCustomURLs
*/
bucketEndpoint?: boolean;
/**
* Whether to force path style URLs for S3 objects (e.g., https://s3.amazonaws.com/<bucketName>/<key> instead of https://<bucketName>.s3.amazonaws.com/<key>
*/
forcePathStyle?: boolean;
/**
* Whether to use the S3 Transfer Acceleration endpoint by default
*/
useAccelerateEndpoint?: boolean;
/**
* Whether to override the request region with the region inferred from requested resource's ARN. Defaults to false
*/
useArnRegion?: boolean | Provider<boolean>;
/**
* Whether to prevent SDK from making cross-region request when supplied bucket is a multi-region access point ARN.
* Defaults to false
*/
disableMultiregionAccessPoints?: boolean | Provider<boolean>;
}
/**
* @deprecated unused as of EndpointsV2.
*/
interface PreviouslyResolved {
isCustomEndpoint?: boolean;
region: Provider<string>;
regionInfoProvider: RegionInfoProvider;
useFipsEndpoint: Provider<boolean>;
useDualstackEndpoint: Provider<boolean>;
}
/**
* @deprecated unused as of EndpointsV2.
*/
export interface BucketEndpointResolvedConfig {
/**
* Whether the endpoint is specified by caller.
* @internal
*/
isCustomEndpoint?: boolean;
/**
* Resolved value for input config {@link BucketEndpointInputConfig.bucketEndpoint}
*/
bucketEndpoint: boolean;
/**
* Resolved value for input config {@link BucketEndpointInputConfig.forcePathStyle}
*/
forcePathStyle: boolean;
/**
* Resolved value for input config {@link BucketEndpointInputConfig.useAccelerateEndpoint}
*/
useAccelerateEndpoint: boolean;
/**
* Enables FIPS compatible endpoints.
*/
useFipsEndpoint: Provider<boolean>;
/**
* Enables IPv6/IPv4 dualstack endpoint.
*/
useDualstackEndpoint: Provider<boolean>;
/**
* Resolved value for input config {@link BucketEndpointInputConfig.useArnRegion}
*/
useArnRegion: Provider<boolean | undefined>;
/**
* Resolved value for input config {@link RegionInputConfig.region}
*/
region: Provider<string>;
/**
* Fetch related hostname, signing name or signing region with given region.
* @internal
*/
regionInfoProvider: RegionInfoProvider;
disableMultiregionAccessPoints: Provider<boolean>;
}
/**
* @deprecated unused as of EndpointsV2.
*/
export declare function resolveBucketEndpointConfig<T>(input: T & PreviouslyResolved & BucketEndpointInputConfig): T & BucketEndpointResolvedConfig;
export {};
@@ -0,0 +1,16 @@
import type { FinalizeRequestHandlerOptions, FinalizeRequestMiddleware, Pluggable } from "@smithy/types";
/**
* @internal
*
* Log a warning if the input to PutObject is detected to be a Stream of unknown ContentLength and
* recommend the usage of the @aws-sdk/lib-storage Upload class.
*/
export declare function checkContentLengthHeader(): FinalizeRequestMiddleware<any, any>;
/**
* @internal
*/
export declare const checkContentLengthHeaderMiddlewareOptions: FinalizeRequestHandlerOptions;
/**
* @internal
*/
export declare const getCheckContentLengthHeaderPlugin: (unused: any) => Pluggable<any, any>;
@@ -0,0 +1,12 @@
import type { HttpHandler } from "@smithy/core/protocols";
import type { BodyLengthCalculator, BuildHandlerOptions, BuildMiddleware, Pluggable, RequestHandler } from "@smithy/types";
interface PreviouslyResolved {
runtime: string;
requestHandler?: RequestHandler<any, any, any> | HttpHandler<any>;
bodyLengthChecker?: BodyLengthCalculator;
expectContinueHeader?: boolean | number;
}
export declare function addExpectContinueMiddleware(options: PreviouslyResolved): BuildMiddleware<any, any>;
export declare const addExpectContinueMiddlewareOptions: BuildHandlerOptions;
export declare const getAddExpectContinuePlugin: (options: PreviouslyResolved) => Pluggable<any, any>;
export {};
@@ -0,0 +1,17 @@
import type { Provider } from "@smithy/types";
/**
* @public
*/
export interface LocationConstraintInputConfig {
}
interface PreviouslyResolved {
region: Provider<string>;
}
export interface LocationConstraintResolvedConfig {
/**
* Resolved value for input config {@link RegionInputConfig.region}
*/
region: Provider<string>;
}
export declare function resolveLocationConstraintConfig<T>(input: T & LocationConstraintInputConfig & PreviouslyResolved): T & LocationConstraintResolvedConfig;
export {};
@@ -0,0 +1,10 @@
import type { InitializeHandlerOptions, InitializeMiddleware, Pluggable } from "@smithy/types";
import type { LocationConstraintResolvedConfig } from "./configuration";
/**
* This middleware modifies the input on S3 CreateBucket requests. If the LocationConstraint has not been set, this
* middleware will set a LocationConstraint to match the configured region. The CreateBucketConfiguration will be
* removed entirely on requests to the us-east-1 region.
*/
export declare function locationConstraintMiddleware(options: LocationConstraintResolvedConfig): InitializeMiddleware<any, any>;
export declare const locationConstraintMiddlewareOptions: InitializeHandlerOptions;
export declare const getLocationConstraintPlugin: (config: LocationConstraintResolvedConfig) => Pluggable<any, any>;
@@ -0,0 +1,13 @@
import type { RelativeMiddlewareOptions, SerializeMiddleware } from "@smithy/types";
interface PreviouslyResolved {
bucketEndpoint?: boolean;
}
/**
* @internal
*/
export declare function bucketEndpointMiddleware(options: PreviouslyResolved): SerializeMiddleware<any, any>;
/**
* @internal
*/
export declare const bucketEndpointMiddlewareOptions: RelativeMiddlewareOptions;
export {};
@@ -0,0 +1,10 @@
import type { RelativeMiddlewareOptions, SerializeMiddleware } from "@smithy/types";
import type { PreviouslyResolved } from "./region-redirect-middleware";
/**
* @internal
*/
export declare const regionRedirectEndpointMiddleware: (config: PreviouslyResolved) => SerializeMiddleware<any, any>;
/**
* @internal
*/
export declare const regionRedirectEndpointMiddlewareOptions: RelativeMiddlewareOptions;
@@ -0,0 +1,20 @@
import type { InitializeHandlerOptions, InitializeMiddleware, Pluggable, Provider } from "@smithy/types";
/**
* @internal
*/
export interface PreviouslyResolved {
region: Provider<string>;
followRegionRedirects: boolean;
}
/**
* @internal
*/
export declare function regionRedirectMiddleware(clientConfig: PreviouslyResolved): InitializeMiddleware<any, any>;
/**
* @internal
*/
export declare const regionRedirectMiddlewareOptions: InitializeHandlerOptions;
/**
* @internal
*/
export declare const getRegionRedirectMiddlewarePlugin: (clientConfig: PreviouslyResolved) => Pluggable<any, any>;
@@ -0,0 +1,79 @@
import type { Client, Command } from "@smithy/types";
import type { S3ExpressIdentityProvider } from "../middleware-s3-express/interfaces/S3ExpressIdentityProvider";
/**
* All endpoint parameters with built-in bindings of AWS::S3::*
* @public
*/
export interface S3InputConfig {
/**
* Whether to force path style URLs for S3 objects
* (e.g., https://s3.amazonaws.com/<bucketName>/<key> instead of https://<bucketName>.s3.amazonaws.com/<key>
*/
forcePathStyle?: boolean;
/**
* Whether to use the S3 Transfer Acceleration endpoint by default
*/
useAccelerateEndpoint?: boolean;
/**
* Whether multi-region access points (MRAP) should be disabled.
*/
disableMultiregionAccessPoints?: boolean;
/**
* This feature was previously called the S3 Global Client.
* This can result in additional latency as failed requests are retried
* with a corrected region when receiving a permanent redirect error with status 301.
* This feature should only be used as a last resort if you do not know the region of your bucket(s) ahead of time.
*/
followRegionRedirects?: boolean;
/**
* Identity provider for an S3 feature.
*/
s3ExpressIdentityProvider?: S3ExpressIdentityProvider;
/**
* Whether to use the bucket name as the endpoint for this client.
*/
bucketEndpoint?: boolean;
/**
* This field configures the SDK's behavior around setting the `expect: 100-continue` header.
*
* Default: 2_097_152 (2 MB)
*
* When given as a boolean - always send or omit the header.
* When given as a number - minimum byte threshold of the payload before setting the header.
* Unmeasurable payload sizes (streams) will set the header too.
*
* The `expect: 100-continue` header is used to allow the server a chance to validate the PUT request
* headers before the client begins to send the object payload. This avoids wasteful data transmission for a
* request that is rejected.
*
* However, there is a trade-off where the request will take longer to complete.
*/
expectContinueHeader?: boolean | number;
}
/**
* This is a placeholder for the actual
* S3Client type from \@aws-sdk/client-s3. It is not explicitly
* imported to avoid a circular dependency.
* @internal
*/
type PlaceholderS3Client = Client<any, any, any> & any;
/**
* Placeholder for the constructor for CreateSessionCommand.
* @internal
*/
type PlaceholderCreateSessionCommandCtor = {
new (args: any): Command<any, any, any, any, any>;
};
export interface S3ResolvedConfig {
forcePathStyle: boolean;
useAccelerateEndpoint: boolean;
disableMultiregionAccessPoints: boolean;
followRegionRedirects: boolean;
s3ExpressIdentityProvider: S3ExpressIdentityProvider;
bucketEndpoint: boolean;
expectContinueHeader: boolean | number;
}
export declare const resolveS3Config: <T>(input: T & S3InputConfig, { session, }: {
session: [() => PlaceholderS3Client, PlaceholderCreateSessionCommandCtor];
}) => T & S3ResolvedConfig;
export {};
@@ -0,0 +1,26 @@
import type { DeserializeMiddleware, Pluggable, RelativeMiddlewareOptions } from "@smithy/types";
/**
* @internal
*/
interface PreviouslyResolved {
}
/**
* @internal
*
* From the S3 Expires compatibility spec.
* A model transform will ensure S3#Expires remains a timestamp shape, though
* it is deprecated.
* If a particular object has a non-date string set as the Expires value,
* the SDK will have the raw string as "ExpiresString" on the response.
*
*/
export declare const s3ExpiresMiddleware: (config: PreviouslyResolved) => DeserializeMiddleware<any, any>;
/**
* @internal
*/
export declare const s3ExpiresMiddlewareOptions: RelativeMiddlewareOptions;
/**
* @internal
*/
export declare const getS3ExpiresMiddlewarePlugin: (clientConfig: PreviouslyResolved) => Pluggable<any, any>;
export {};
@@ -0,0 +1,16 @@
import type { S3ExpressIdentityCacheEntry } from "./S3ExpressIdentityCacheEntry";
/**
* @internal
*
* Stores identities by key.
*/
export declare class S3ExpressIdentityCache {
private data;
private lastPurgeTime;
static EXPIRED_CREDENTIAL_PURGE_INTERVAL_MS: number;
constructor(data?: Record<string, S3ExpressIdentityCacheEntry>);
get(key: string): undefined | S3ExpressIdentityCacheEntry;
set(key: string, entry: S3ExpressIdentityCacheEntry): S3ExpressIdentityCacheEntry;
delete(key: string): void;
purgeExpired(): Promise<void>;
}
@@ -0,0 +1,16 @@
import type { S3ExpressIdentity } from "../interfaces/S3ExpressIdentity";
/**
* @internal
*/
export declare class S3ExpressIdentityCacheEntry {
private _identity;
isRefreshing: boolean;
accessed: number;
/**
* @param identity - stored identity.
* @param accessed - timestamp of last access in epoch ms.
* @param isRefreshing - this key is currently in the process of being refreshed (background).
*/
constructor(_identity: Promise<S3ExpressIdentity>, isRefreshing?: boolean, accessed?: number);
get identity(): Promise<S3ExpressIdentity>;
}
@@ -0,0 +1,32 @@
import type { AwsCredentialIdentity } from "@aws-sdk/types";
import type { S3ExpressIdentity } from "../interfaces/S3ExpressIdentity";
import type { S3ExpressIdentityProvider } from "../interfaces/S3ExpressIdentityProvider";
import { S3ExpressIdentityCache } from "./S3ExpressIdentityCache";
/**
* @internal
*
* This should match S3::CreateSessionCommandOutput::SessionCredentials
* but it is not imported since that would create a circular dependency.
*/
type Credentials = {
AccessKeyId: string | undefined;
SecretAccessKey: string | undefined;
SessionToken: string | undefined;
Expiration: Date | undefined;
};
/**
* @internal
*/
export declare class S3ExpressIdentityProviderImpl implements S3ExpressIdentityProvider {
private createSessionFn;
private cache;
static REFRESH_WINDOW_MS: number;
constructor(createSessionFn: (key: string) => Promise<{
Credentials: Credentials;
}>, cache?: S3ExpressIdentityCache);
getS3ExpressIdentity(awsIdentity: AwsCredentialIdentity, identityProperties: {
Bucket: string;
} & Record<string, string>): Promise<S3ExpressIdentity>;
private getIdentity;
}
export {};
@@ -0,0 +1,6 @@
import { SignatureV4SignWithCredentials } from "@aws-sdk/signature-v4-multi-region";
/**
* @internal
*/
export declare class SignatureV4S3Express extends SignatureV4SignWithCredentials {
}
@@ -0,0 +1,37 @@
import type { LoadedConfigSelectors } from "@smithy/core/config";
/**
* @internal
*
* @deprecated will be replaced by backend.
*
* TODO(s3-express): non-beta value, backend == S3Express.
*/
export declare const S3_EXPRESS_BUCKET_TYPE = "Directory";
/**
* @internal
*/
export declare const S3_EXPRESS_BACKEND = "S3Express";
/**
* @internal
*/
export declare const S3_EXPRESS_AUTH_SCHEME = "sigv4-s3express";
/**
* @internal
*/
export declare const SESSION_TOKEN_QUERY_PARAM = "X-Amz-S3session-Token";
/**
* @internal
*/
export declare const SESSION_TOKEN_HEADER: string;
/**
* @internal
*/
export declare const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_ENV_NAME = "AWS_S3_DISABLE_EXPRESS_SESSION_AUTH";
/**
* @internal
*/
export declare const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_INI_NAME = "s3_disable_express_session_auth";
/**
* @internal
*/
export declare const NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS: LoadedConfigSelectors<boolean>;
@@ -0,0 +1,27 @@
import type { IHttpRequest } from "@smithy/core/protocols";
import type { AuthScheme, AwsCredentialIdentity, FinalizeRequestMiddleware, Pluggable, RequestSigner } from "@smithy/types";
interface SigningProperties {
signingRegion: string;
signingDate: Date;
signingService: string;
}
interface PreviouslyResolved {
signer: (authScheme?: AuthScheme | undefined) => Promise<RequestSigner & {
signWithCredentials(req: IHttpRequest, identity: AwsCredentialIdentity, opts?: Partial<SigningProperties>): Promise<IHttpRequest>;
}>;
}
/**
* @internal
*/
export declare const s3ExpressHttpSigningMiddlewareOptions: import("@smithy/types").FinalizeRequestHandlerOptions & import("@smithy/types").RelativeLocation & Omit<import("@smithy/types").HandlerOptions, "step">;
/**
* @internal
*/
export declare const s3ExpressHttpSigningMiddleware: <Input extends object, Output extends object>(config: PreviouslyResolved) => FinalizeRequestMiddleware<any, any>;
/**
* @internal
*/
export declare const getS3ExpressHttpSigningPlugin: (config: {
signer: (authScheme?: AuthScheme | undefined) => Promise<RequestSigner>;
}) => Pluggable<any, any>;
export {};
@@ -0,0 +1,32 @@
import type { AwsCredentialIdentity } from "@aws-sdk/types";
import type { BuildHandlerOptions, BuildMiddleware, Logger, MemoizedProvider, Pluggable } from "@smithy/types";
import type { S3ExpressIdentity } from "../interfaces/S3ExpressIdentity";
import type { S3ExpressIdentityProvider } from "../interfaces/S3ExpressIdentityProvider";
declare module "@smithy/types" {
interface HandlerExecutionContext {
/**
* Reserved key, only when using S3.
*/
s3ExpressIdentity?: S3ExpressIdentity;
}
}
/**
* @internal
*/
export interface S3ExpressResolvedConfig {
logger?: Logger;
s3ExpressIdentityProvider: S3ExpressIdentityProvider;
credentials: MemoizedProvider<AwsCredentialIdentity>;
}
/**
* @internal
*/
export declare const s3ExpressMiddleware: (options: S3ExpressResolvedConfig) => BuildMiddleware<any, any>;
/**
* @internal
*/
export declare const s3ExpressMiddlewareOptions: BuildHandlerOptions;
/**
* @internal
*/
export declare const getS3ExpressPlugin: (options: S3ExpressResolvedConfig) => Pluggable<any, any>;
@@ -0,0 +1,9 @@
import type { AwsCredentialIdentity, HttpRequest as IHttpRequest } from "@smithy/types";
import type { S3ExpressIdentity } from "../interfaces/S3ExpressIdentity";
export declare const signS3Express: (s3ExpressIdentity: S3ExpressIdentity, signingOptions: {
signingDate: Date;
signingRegion: string;
signingService: string;
}, request: IHttpRequest, sigV4MultiRegionSigner: {
signWithCredentials(req: IHttpRequest, identity: AwsCredentialIdentity, opts?: Partial<typeof signingOptions>): Promise<IHttpRequest>;
}) => Promise<IHttpRequest>;
@@ -0,0 +1,6 @@
import type { AwsCredentialIdentity } from "@aws-sdk/types";
/**
* @public
*/
export interface S3ExpressIdentity extends AwsCredentialIdentity {
}
@@ -0,0 +1,12 @@
import type { AwsCredentialIdentity } from "@aws-sdk/types";
import type { S3ExpressIdentity } from "./S3ExpressIdentity";
/**
* @public
*/
export interface S3ExpressIdentityProvider {
/**
* @param awsIdentity - pre-existing credentials.
* @param identityProperties - unknown.
*/
getS3ExpressIdentity(awsIdentity: AwsCredentialIdentity, identityProperties: Record<string, string>): Promise<S3ExpressIdentity>;
}
@@ -0,0 +1,12 @@
import type { ChecksumConstructor, Decoder, Encoder, HashConstructor, InitializeHandlerOptions, InitializeMiddleware, Pluggable } from "@smithy/types";
interface PreviouslyResolved {
base64Encoder: Encoder;
md5: ChecksumConstructor | HashConstructor;
utf8Decoder: Decoder;
base64Decoder: Decoder;
}
export declare function ssecMiddleware(options: PreviouslyResolved): InitializeMiddleware<any, any>;
export declare const ssecMiddlewareOptions: InitializeHandlerOptions;
export declare const getSsecPlugin: (config: PreviouslyResolved) => Pluggable<any, any>;
export declare function isValidBase64EncodedSSECustomerKey(str: string, options: PreviouslyResolved): boolean;
export {};
@@ -0,0 +1,21 @@
import type { DeserializeMiddleware, Encoder, Pluggable, RelativeMiddlewareOptions, StreamCollector } from "@smithy/types";
type PreviouslyResolved = {
streamCollector: StreamCollector;
utf8Encoder: Encoder;
};
/**
* In case of an internal error/terminated connection, S3 operations may return 200 errors. CopyObject, UploadPartCopy,
* CompleteMultipartUpload may return empty payload or payload with only xml Preamble.
* @internal
*/
export declare const throw200ExceptionsMiddleware: (config: PreviouslyResolved) => DeserializeMiddleware<any, any>;
/**
* @internal
*/
export declare const throw200ExceptionsMiddlewareOptions: RelativeMiddlewareOptions;
/**
*
* @internal
*/
export declare const getThrow200ExceptionsPlugin: (config: PreviouslyResolved) => Pluggable<any, any>;
export {};
@@ -0,0 +1,14 @@
import type { InitializeHandlerOptions, InitializeMiddleware, Pluggable } from "@smithy/types";
import type { S3ResolvedConfig } from "../middleware-s3-configuration/s3Configuration";
/**
* @internal
*/
export declare function validateBucketNameMiddleware({ bucketEndpoint }: S3ResolvedConfig): InitializeMiddleware<any, any>;
/**
* @internal
*/
export declare const validateBucketNameMiddlewareOptions: InitializeHandlerOptions;
/**
* @internal
*/
export declare const getValidateBucketNamePlugin: (options: S3ResolvedConfig) => Pluggable<any, any>;
@@ -0,0 +1,20 @@
import { AwsRestXmlProtocol } from "@aws-sdk/core/protocols";
import type { EndpointBearer, HandlerExecutionContext, HttpRequest, OperationSchema, SerdeFunctions } from "@smithy/types";
/**
* Customization for S3 backwards compatibility.
*
* In the S3 model, Bucket is considered an HTTP label, and we normally perform http label client
* side validation. However, the standard validation is that the http label appears in
* the request path. Bucket is unique in that it is an endpoint context param. It appears
* where the endpoint resolver decides, rather than in the URL path (although sometimes it does appear there).
*
* For consistency with older code generated clients, we throw the HTTP label validation
* error when the Bucket input is missing, if-and-only-if it is an httpLabel and is a required top level member.
*
* This does not apply to S3 Control.
*
* @internal
*/
export declare class S3RestXmlProtocol extends AwsRestXmlProtocol {
serializeRequest<Input extends object>(operationSchema: OperationSchema, input: Input, context: HandlerExecutionContext & SerdeFunctions & EndpointBearer): Promise<HttpRequest>;
}
@@ -0,0 +1,4 @@
/**
* @internal
*/
export declare function toStream(bytes: Uint8Array): ReadableStream;
@@ -0,0 +1,5 @@
import { Readable } from "node:stream";
/**
* @internal
*/
export declare function toStream(bytes: Uint8Array): Readable;
@@ -0,0 +1,39 @@
export {
checkContentLengthHeader,
checkContentLengthHeaderMiddlewareOptions,
getCheckContentLengthHeaderPlugin,
regionRedirectEndpointMiddleware,
regionRedirectEndpointMiddlewareOptions,
regionRedirectMiddleware,
regionRedirectMiddlewareOptions,
getRegionRedirectMiddlewarePlugin,
resolveS3Config,
s3ExpiresMiddleware,
s3ExpiresMiddlewareOptions,
getS3ExpiresMiddlewarePlugin,
S3ExpressIdentityCache,
S3ExpressIdentityCacheEntry,
S3ExpressIdentityProviderImpl,
SignatureV4S3Express,
NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS,
getS3ExpressPlugin,
s3ExpressMiddleware,
s3ExpressMiddlewareOptions,
getS3ExpressHttpSigningPlugin,
s3ExpressHttpSigningMiddleware,
s3ExpressHttpSigningMiddlewareOptions,
throw200ExceptionsMiddleware,
throw200ExceptionsMiddlewareOptions,
getThrow200ExceptionsPlugin,
validateBucketNameMiddleware,
validateBucketNameMiddlewareOptions,
getValidateBucketNamePlugin,
S3RestXmlProtocol,
} from "./submodules/s3/index.browser";
export {
PreviouslyResolved,
S3InputConfig,
S3ResolvedConfig,
S3ExpressIdentity,
S3ExpressIdentityProvider,
} from "./submodules/s3/index.browser";
+39
View File
@@ -0,0 +1,39 @@
export {
checkContentLengthHeader,
checkContentLengthHeaderMiddlewareOptions,
getCheckContentLengthHeaderPlugin,
regionRedirectEndpointMiddleware,
regionRedirectEndpointMiddlewareOptions,
regionRedirectMiddleware,
regionRedirectMiddlewareOptions,
getRegionRedirectMiddlewarePlugin,
resolveS3Config,
s3ExpiresMiddleware,
s3ExpiresMiddlewareOptions,
getS3ExpiresMiddlewarePlugin,
S3ExpressIdentityCache,
S3ExpressIdentityCacheEntry,
S3ExpressIdentityProviderImpl,
SignatureV4S3Express,
NODE_DISABLE_S3_EXPRESS_SESSION_AUTH_OPTIONS,
getS3ExpressPlugin,
s3ExpressMiddleware,
s3ExpressMiddlewareOptions,
getS3ExpressHttpSigningPlugin,
s3ExpressHttpSigningMiddleware,
s3ExpressHttpSigningMiddlewareOptions,
throw200ExceptionsMiddleware,
throw200ExceptionsMiddlewareOptions,
getThrow200ExceptionsPlugin,
validateBucketNameMiddleware,
validateBucketNameMiddlewareOptions,
getValidateBucketNamePlugin,
S3RestXmlProtocol,
} from "./submodules/s3/index";
export {
PreviouslyResolved,
S3InputConfig,
S3ResolvedConfig,
S3ExpressIdentity,
S3ExpressIdentityProvider,
} from "./submodules/s3/index";
@@ -0,0 +1,23 @@
import { Provider, RegionInfoProvider } from "@smithy/types";
export { NODE_USE_ARN_REGION_CONFIG_OPTIONS } from "@aws-sdk/middleware-sdk-s3/s3";
export interface S3ControlInputConfig {
useArnRegion?: boolean | undefined | Provider<boolean | undefined>;
}
interface PreviouslyResolved {
isCustomEndpoint?: boolean;
region: Provider<string>;
regionInfoProvider?: RegionInfoProvider;
useFipsEndpoint: Provider<boolean>;
useDualstackEndpoint: Provider<boolean>;
}
export interface S3ControlResolvedConfig {
isCustomEndpoint?: boolean;
useFipsEndpoint: Provider<boolean>;
useDualstackEndpoint: Provider<boolean>;
useArnRegion: Provider<boolean | undefined>;
region: Provider<string>;
regionInfoProvider?: RegionInfoProvider;
}
export declare function resolveS3ControlConfig<T>(
input: T & PreviouslyResolved & S3ControlInputConfig
): T & S3ControlResolvedConfig;
@@ -0,0 +1,5 @@
export declare const CONTEXT_OUTPOST_ID = "outpost_id";
export declare const CONTEXT_ACCOUNT_ID = "account_id";
export declare const CONTEXT_ARN_REGION = "outpost_arn_region";
export declare const CONTEXT_SIGNING_SERVICE = "signing_service";
export declare const CONTEXT_SIGNING_REGION = "signing_region";
@@ -0,0 +1,26 @@
export {
S3ControlInputConfig,
S3ControlResolvedConfig,
} from "./configurations";
export { resolveS3ControlConfig } from "./configurations";
export { getProcessArnablesPlugin } from "./middleware-process-arnables/getProcessArnablesPlugin";
export {
parseOutpostArnablesMiddleaware,
parseOutpostArnablesMiddleawareOptions,
} from "./middleware-process-arnables/parse-outpost-arnables";
export {
updateArnablesRequestMiddleware,
updateArnablesRequestMiddlewareOptions,
} from "./middleware-process-arnables/update-arnables-request";
export { getOutpostEndpoint } from "./middleware-process-arnables/getOutpostEndpoint";
export {
hostPrefixDeduplicationMiddleware,
hostPrefixDeduplicationMiddlewareOptions,
getHostPrefixDeduplicationPlugin,
} from "./middleware-host-prefix-deduplication/hostPrefixDeduplicationMiddleware";
export { RedirectFromPostIdMiddlewareConfig } from "./middleware-redirect-from-postid/redirect-from-postid";
export {
redirectFromPostIdMiddleware,
redirectFromPostIdMiddlewareOptions,
getRedirectFromPostIdPlugin,
} from "./middleware-redirect-from-postid/redirect-from-postid";

Some files were not shown because too many files have changed in this diff Show More