pub enum InternalCaller {
Service {
service: String,
source_arn: String,
source_account: String,
},
ServiceOwned {
arn: String,
canonical_user_id: Option<String>,
acting_account: String,
},
}Expand description
The AWS-owned principal a request is made as when fakecloud itself issues it on a customer’s behalf through its own front door – CloudFront fetching from an S3 origin through an origin access control, for example.
It travels as an http::Request extension set by in-process code and
is never parsed from the wire, so a client cannot claim it. Dispatch
honors it only on a request that carries no credentials of its own, and
authorizes it against the resource policy alone (see
IamPolicyEvaluator::evaluate_resource_policy_only): neither kind of
principal belongs to an account with identity policies.
Variants§
Service
An AWS service principal (cloudfront.amazonaws.com) acting for one
of its resources. source_arn / source_account are that resource
and its owner – the aws:SourceArn / aws:SourceAccount values a
confused-deputy condition compares against.
ServiceOwned
An IAM identity an AWS service owns outside every customer account,
such as a CloudFront origin access identity
(arn:aws:iam::cloudfront:user/CloudFront Origin Access Identity <id>).
A resource policy names it by arn or, in S3, by its
canonical_user_id. acting_account is the customer account whose
resource made the request.
Implementations§
Source§impl InternalCaller
impl InternalCaller
Sourcepub fn principal(&self) -> Principal
pub fn principal(&self) -> Principal
The principal the request is evaluated as. Neither kind carries an
account id: a service principal belongs to no account and a
service-owned identity to AWS’s, so an account-root grant
(arn:aws:iam::<acct>:root) never matches either, as in AWS. A
service-owned identity’s canonical user id is its user_id.
Sourcepub fn acting_account(&self) -> &str
pub fn acting_account(&self) -> &str
The customer account the request is made for: the owner of the resource on whose behalf the service acts.
Sourcepub fn condition_keys(&self) -> BTreeMap<String, Vec<String>>
pub fn condition_keys(&self) -> BTreeMap<String, Vec<String>>
The request-context keys this caller contributes: for a service
principal aws:SourceArn, aws:SourceAccount,
aws:PrincipalServiceName and aws:PrincipalIsAWSService; for a
service-owned identity nothing beyond its principal ARN (set on the
typed context by dispatch).
Trait Implementations§
Source§impl Clone for InternalCaller
impl Clone for InternalCaller
Source§impl Debug for InternalCaller
impl Debug for InternalCaller
impl Eq for InternalCaller
Source§impl PartialEq for InternalCaller
impl PartialEq for InternalCaller
impl StructuralPartialEq for InternalCaller
Auto Trait Implementations§
impl Freeze for InternalCaller
impl RefUnwindSafe for InternalCaller
impl Send for InternalCaller
impl Sync for InternalCaller
impl Unpin for InternalCaller
impl UnsafeUnpin for InternalCaller
impl UnwindSafe for InternalCaller
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> CloneToUninit for Twhere
T: Clone,
impl<T> CloneToUninit for Twhere
T: Clone,
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§impl<Q, K> Equivalent<K> for Q
impl<Q, K> Equivalent<K> for Q
Source§fn equivalent(&self, key: &K) -> bool
fn equivalent(&self, key: &K) -> bool
key and return true if they are equal.