roa_signature_composer.go 4.2 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138
  1. /*
  2. * Licensed under the Apache License, Version 2.0 (the "License");
  3. * you may not use this file except in compliance with the License.
  4. * You may obtain a copy of the License at
  5. *
  6. * http://www.apache.org/licenses/LICENSE-2.0
  7. *
  8. * Unless required by applicable law or agreed to in writing, software
  9. * distributed under the License is distributed on an "AS IS" BASIS,
  10. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  11. * See the License for the specific language governing permissions and
  12. * limitations under the License.
  13. */
  14. package auth
  15. import (
  16. "bytes"
  17. "sort"
  18. "strings"
  19. "github.com/aliyun/alibaba-cloud-sdk-go/sdk/requests"
  20. "github.com/aliyun/alibaba-cloud-sdk-go/sdk/utils"
  21. )
  22. var debug utils.Debug
  23. var hookGetDate = func(fn func() string) string {
  24. return fn()
  25. }
  26. func init() {
  27. debug = utils.Init("sdk")
  28. }
  29. func signRoaRequest(request requests.AcsRequest, signer Signer, regionId string) (err error) {
  30. completeROASignParams(request, signer, regionId)
  31. stringToSign := buildRoaStringToSign(request)
  32. request.SetStringToSign(stringToSign)
  33. accessKeyId, err := signer.GetAccessKeyId()
  34. if err != nil {
  35. return err
  36. }
  37. signature := signer.Sign(stringToSign, "")
  38. request.GetHeaders()["Authorization"] = "acs " + accessKeyId + ":" + signature
  39. return
  40. }
  41. func completeROASignParams(request requests.AcsRequest, signer Signer, regionId string) {
  42. headerParams := request.GetHeaders()
  43. // complete query params
  44. queryParams := request.GetQueryParams()
  45. //if _, ok := queryParams["RegionId"]; !ok {
  46. // queryParams["RegionId"] = regionId
  47. //}
  48. if extraParam := signer.GetExtraParam(); extraParam != nil {
  49. for key, value := range extraParam {
  50. if key == "SecurityToken" {
  51. headerParams["x-acs-security-token"] = value
  52. continue
  53. }
  54. if key == "BearerToken" {
  55. headerParams["x-acs-bearer-token"] = value
  56. continue
  57. }
  58. queryParams[key] = value
  59. }
  60. }
  61. // complete header params
  62. headerParams["Date"] = hookGetDate(utils.GetTimeInFormatRFC2616)
  63. headerParams["x-acs-signature-method"] = signer.GetName()
  64. headerParams["x-acs-signature-version"] = signer.GetVersion()
  65. if request.GetFormParams() != nil && len(request.GetFormParams()) > 0 {
  66. formString := utils.GetUrlFormedMap(request.GetFormParams())
  67. request.SetContent([]byte(formString))
  68. if headerParams["Content-Type"] == "" {
  69. headerParams["Content-Type"] = requests.Form
  70. }
  71. }
  72. contentMD5 := utils.GetMD5Base64(request.GetContent())
  73. headerParams["Content-MD5"] = contentMD5
  74. if _, contains := headerParams["Content-Type"]; !contains {
  75. headerParams["Content-Type"] = requests.Raw
  76. }
  77. switch format := request.GetAcceptFormat(); format {
  78. case "JSON":
  79. headerParams["Accept"] = requests.Json
  80. case "XML":
  81. headerParams["Accept"] = requests.Xml
  82. default:
  83. headerParams["Accept"] = requests.Raw
  84. }
  85. }
  86. func buildRoaStringToSign(request requests.AcsRequest) (stringToSign string) {
  87. headers := request.GetHeaders()
  88. stringToSignBuilder := bytes.Buffer{}
  89. stringToSignBuilder.WriteString(request.GetMethod())
  90. stringToSignBuilder.WriteString(requests.HeaderSeparator)
  91. // append header keys for sign
  92. appendIfContain(headers, &stringToSignBuilder, "Accept", requests.HeaderSeparator)
  93. appendIfContain(headers, &stringToSignBuilder, "Content-MD5", requests.HeaderSeparator)
  94. appendIfContain(headers, &stringToSignBuilder, "Content-Type", requests.HeaderSeparator)
  95. appendIfContain(headers, &stringToSignBuilder, "Date", requests.HeaderSeparator)
  96. // sort and append headers witch starts with 'x-acs-'
  97. var acsHeaders []string
  98. for key := range headers {
  99. if strings.HasPrefix(key, "x-acs-") {
  100. acsHeaders = append(acsHeaders, key)
  101. }
  102. }
  103. sort.Strings(acsHeaders)
  104. for _, key := range acsHeaders {
  105. stringToSignBuilder.WriteString(key + ":" + headers[key])
  106. stringToSignBuilder.WriteString(requests.HeaderSeparator)
  107. }
  108. // append query params
  109. stringToSignBuilder.WriteString(request.BuildQueries())
  110. stringToSign = stringToSignBuilder.String()
  111. debug("stringToSign: %s", stringToSign)
  112. return
  113. }
  114. func appendIfContain(sourceMap map[string]string, target *bytes.Buffer, key, separator string) {
  115. if value, contain := sourceMap[key]; contain && len(value) > 0 {
  116. target.WriteString(sourceMap[key])
  117. target.WriteString(separator)
  118. }
  119. }