aws-sts-connector
Service icon

AWS STS Connector

Stable version 1.0.0 (Compatible with OutSystems 11)
Uploaded
 on 2 Oct (4 days ago)
 by 
0.0
 (0 ratings)
aws-sts-connector

AWS STS Connector

Documentation
1.0.0

1. Setup

  1. Install the component and its dependencies (AWSSigV4_Lib and the Xml extension).
  2. In your module, add a dependency to AWSSTS_IS and pick the actions and structures you need.
  3. Have AWS credentials available: an access key ID and a secret access key of an IAM user or role, with permission for the STS actions you intend to call. Keep them somewhere safe (for example, encrypted configuration). Do not hard-code them in logic.

Site property

  • STSGlobalRegion (default us-east-1): the region used to sign requests sent to the global endpoint. AWS recommends us-east-1; you normally don't change it.

2. Concepts shared by all actions

Credentials. Signed actions take:

  • AccessKeyId (mandatory) and SecretAccessKey (mandatory): the keys used to sign the request.
  • SessionToken (optional): fill it only when the keys are temporary credentials. Leave it empty for long-term keys.

AssumeRoleWithSAML and AssumeRoleWithWebIdentity take no credentials: AWS does not require them, and the request is sent unsigned.

Endpoint and region. Requests go to the global endpoint, https://sts.amazonaws.com. AssumeRoot and GetWebIdentityToken are not available there, so they have a mandatory Region input (for example eu-west-1) and go to https://sts.{region}.amazonaws.com.

Optional numbers. An optional Integer input left at 0 (such as DurationSeconds) is not sent, so AWS applies its own default.

Lists. PolicyArns and TransitiveTagKeys are Text lists. Tags is a list of AWSSTS_KeyValuePair.

Request ID. Every action returns RequestId, the identifier AWS assigned to the request. Log it: AWS Support asks for it.

Errors. When AWS answers with an error, the action raises a Validation user exception whose message is [ErrorCode] Message, for example [AccessDenied] User ... is not authorized to perform: sts:AssumeRole .... Passing only one of the two keys also raises it. Handle it with an exception handler in your flow.

3. Quick start

Check which identity your credentials belong to

  1. Call AWSSTSConnector_GetCallerIdentity with AccessKeyId and SecretAccessKey.
  2. Read Arn, UserId and Account from the outputs.

Assume a role and use its credentials

  1. Call AWSSTSConnector_AssumeRole with your keys, the RoleArn of the role and a RoleSessionName.
  2. Take Credentials.AccessKeyId, Credentials.SecretAccessKey and Credentials.SessionToken from the output.
  3. Pass the three values to any other AWS connector, or back to this one (the token goes in SessionToken).
  4. Request new credentials before Credentials.Expiration (UTC).

4. Action reference

Mandatory inputs are marked with . All signed actions also take AccessKeyId, SecretAccessKey* and SessionToken; all actions return RequestId.

AWSSTSConnector_AssumeRole
Returns temporary credentials for a role.

  • Inputs: RoleArn, RoleSessionName, DurationSeconds, Policy, PolicyArns, Tags, TransitiveTagKeys, ExternalId, SerialNumber, TokenCode, RequestSourceIdentity, ProvidedContexts, MinimumSessionTokenSize
  • Outputs: Credentials, AssumedRoleUser, SourceIdentity, PackedPolicySize, SessionTokenSize, SessionTokenUtilization
  • RequestSourceIdentity is sent to AWS as SourceIdentity.

AWSSTSConnector_AssumeRoleWithSAML (no credentials)
Returns temporary credentials for a user authenticated through a SAML response.

  • Inputs: RoleArn, PrincipalArn, SAMLAssertion* (Base64), DurationSeconds, Policy, PolicyArns, MinimumSessionTokenSize
  • Outputs: Credentials, AssumedRoleUser, Subject, SubjectType, Issuer, Audience, NameQualifier, SourceIdentity, PackedPolicySize, SessionTokenSize, SessionTokenUtilization

AWSSTSConnector_AssumeRoleWithWebIdentity (no credentials)
Returns temporary credentials for a user authenticated by a web identity or OpenID Connect provider.

  • Inputs: RoleArn, RoleSessionName, WebIdentityToken*, ProviderId, DurationSeconds, Policy, PolicyArns, MinimumSessionTokenSize
  • Outputs: Credentials, AssumedRoleUser, SubjectFromWebIdentityToken, Provider, Audience, SourceIdentity, PackedPolicySize, SessionTokenSize, SessionTokenUtilization

AWSSTSConnector_AssumeRoot (regional)
Returns short-term credentials for privileged tasks on a member account. Must be called from the organization's management account or a delegated administrator for IAM.

  • Inputs: Region, TargetPrincipal, TaskPolicyArn*, DurationSeconds (up to 900), MinimumSessionTokenSize
  • Outputs: Credentials, SourceIdentity, SessionTokenSize, SessionTokenUtilization

AWSSTSConnector_DecodeAuthorizationMessage
Decodes the encoded message some AWS operations return when a request is not authorized.

  • Inputs: EncodedMessage*
  • Outputs: DecodedMessage (a JSON document)

AWSSTSConnector_GetAccessKeyInfo
Returns the account an access key belongs to.

  • Inputs: RequestAccessKeyId* (the key to look up, sent to AWS as AccessKeyId)
  • Outputs: Account

AWSSTSConnector_GetCallerIdentity
Returns the identity behind the credentials used in the call. Needs no IAM permission.

  • Inputs: credentials only
  • Outputs: Arn, UserId, Account

AWSSTSConnector_GetDelegatedAccessToken
Exchanges a trade-in token for temporary credentials.

  • Inputs: TradeInToken*
  • Outputs: Credentials, AssumedPrincipal

AWSSTSConnector_GetFederationToken
Returns temporary credentials for a federated user. Must be called with the long-term credentials of an IAM user; without a session policy the session has no permissions.

  • Inputs: Name*, DurationSeconds, Policy, PolicyArns, Tags, MinimumSessionTokenSize
  • Outputs: Credentials, FederatedUser, PackedPolicySize, SessionTokenSize, SessionTokenUtilization

AWSSTSConnector_GetSessionToken
Returns temporary credentials for an IAM user, typically to enforce MFA. Must be called with long-term credentials.

  • Inputs: DurationSeconds, SerialNumber, TokenCode, MinimumSessionTokenSize
  • Outputs: Credentials, SessionTokenSize, SessionTokenUtilization

AWSSTSConnector_GetWebIdentityToken (regional)
Returns a signed JWT that represents the calling AWS identity.

  • Inputs: Region, Audience (Text list, 1 to 10), SigningAlgorithm* (RS256 or ES384), DurationSeconds, Tags
  • Outputs: WebIdentityToken, Expiration

5. Structures

  • AWSSTS_Credentials: AccessKeyId, SecretAccessKey, SessionToken, Expiration (Date Time, UTC).
  • AWSSTS_AssumedRoleUser: AssumedRoleId, Arn.
  • AWSSTS_FederatedUser: FederatedUserId, Arn.
  • AWSSTS_ProvidedContext: ProviderArn, ContextAssertion.
  • AWSSTS_KeyValuePair: Key, Value. Used for session tags.

6. Notes and limits

  • Tokens from the global endpoint are, by default, valid only in the AWS regions that are enabled by default. To use them in opt-in regions, change the account's STS setting in IAM so the global endpoint issues tokens valid in all regions.
  • Server clock. Requests are signed with the server's current time, which the signing library treats as UTC. AWS rejects requests whose timestamp is more than a few minutes off.
  • Role chaining. A role assumed with temporary credentials is limited to a one-hour session.
  • PackedPolicySize is deprecated by AWS in favour of SessionTokenUtilization.
  • For the meaning and limits of each parameter, see the AWS STS API Reference: https://docs.aws.amazon.com/STS/latest/APIReference/welcome.html