mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-09-03 06:05:04 +09:00
feat: support custom STS endpoints (#1762)
Closes #1067. This is a advanced option and is not needed for most deployments.
This commit is contained in:
+49
-3
@@ -311,9 +311,7 @@ describe('Configure AWS Credentials', {}, () => {
|
||||
});
|
||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||
await run();
|
||||
expect(core.warning).toHaveBeenCalledWith(
|
||||
expect.stringContaining("'custom-tags' is set but will be ignored"),
|
||||
);
|
||||
expect(core.warning).toHaveBeenCalledWith(expect.stringContaining("'custom-tags' is set but will be ignored"));
|
||||
});
|
||||
});
|
||||
|
||||
@@ -801,6 +799,54 @@ describe('Configure AWS Credentials', {}, () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('Custom STS Endpoint', {}, () => {
|
||||
it('passes sts-endpoint to the STS client', async () => {
|
||||
const client = new CredentialsClient({
|
||||
region: 'us-east-1',
|
||||
stsEndpoint: 'https://sts.custom.example.com',
|
||||
roleChaining: false,
|
||||
});
|
||||
const endpoint = await client.stsClient.config.endpoint();
|
||||
expect(endpoint).toMatchObject({ hostname: 'sts.custom.example.com', protocol: 'https:' });
|
||||
});
|
||||
|
||||
it('does not override endpoint when sts-endpoint is not provided', () => {
|
||||
const client = new CredentialsClient({
|
||||
region: 'us-east-1',
|
||||
roleChaining: false,
|
||||
});
|
||||
expect(client.stsClient.config.endpoint).toBeUndefined();
|
||||
});
|
||||
|
||||
it('works with http endpoints for local services', async () => {
|
||||
const client = new CredentialsClient({
|
||||
region: 'us-east-1',
|
||||
stsEndpoint: 'http://localhost:9000',
|
||||
roleChaining: false,
|
||||
});
|
||||
const endpoint = await client.stsClient.config.endpoint();
|
||||
expect(endpoint).toMatchObject({ hostname: 'localhost', protocol: 'http:', port: 9000 });
|
||||
});
|
||||
|
||||
it('succeeds in a full action run with sts-endpoint input', async () => {
|
||||
vi.mocked(core.getInput).mockImplementation(
|
||||
mocks.getInput({
|
||||
...mocks.GH_OIDC_INPUTS,
|
||||
'sts-endpoint': 'https://sts.custom.example.com',
|
||||
}),
|
||||
);
|
||||
vi.mocked(core.getIDToken).mockResolvedValue('testoidctoken');
|
||||
mockedSTSClient.on(GetCallerIdentityCommand).resolvesOnce({ ...mocks.outputs.GET_CALLER_IDENTITY });
|
||||
mockedSTSClient.on(AssumeRoleWithWebIdentityCommand).resolvesOnce(mocks.outputs.STS_CREDENTIALS);
|
||||
process.env.ACTIONS_ID_TOKEN_REQUEST_TOKEN = 'fake-token';
|
||||
|
||||
await run();
|
||||
|
||||
expect(core.setFailed).not.toHaveBeenCalled();
|
||||
expect(core.info).toHaveBeenCalledWith('Authenticated as assumedRoleId AROAFAKEASSUMEDROLEID');
|
||||
});
|
||||
});
|
||||
|
||||
describe('HTTP Proxy Configuration', {}, () => {
|
||||
beforeEach(() => {
|
||||
vi.mocked(core.getInput).mockImplementation(mocks.getInput(mocks.GH_OIDC_INPUTS));
|
||||
|
||||
Reference in New Issue
Block a user