Phase 5 — API keys.
Today
The CLI caches credentials and checks their expiry — and when they have expired it stops: Cached credentials have expired. Run 'source-coop login' to refresh. (src/main.rs). That is interactive, so nothing keeps a token file fresh for a daemon.
The CLI also sends the token as a URL query parameter (src/sts.rs, append_pair("WebIdentityToken", …)), so bearer tokens land in access logs.
Do
- Add a mode that reads an API key, exchanges it at
/.sts without a browser, and keeps AWS_WEB_IDENTITY_TOKEN_FILE fresh.
- Send the token in the request body. The proxy already accepts form-encoded bodies, so this is CLI-only.
Done when
A daemon holding a key and no browser runs across a credential expiry, and the token never appears in a request URL.
Depends on source-cooperative/source.coop#548.
Part of source-cooperative/source.coop#491.
Phase 5 — API keys.
Today
The CLI caches credentials and checks their expiry — and when they have expired it stops:
Cached credentials have expired. Run 'source-coop login' to refresh.(src/main.rs). That is interactive, so nothing keeps a token file fresh for a daemon.The CLI also sends the token as a URL query parameter (
src/sts.rs,append_pair("WebIdentityToken", …)), so bearer tokens land in access logs.Do
/.stswithout a browser, and keepsAWS_WEB_IDENTITY_TOKEN_FILEfresh.Done when
A daemon holding a key and no browser runs across a credential expiry, and the token never appears in a request URL.
Depends on source-cooperative/source.coop#548.
Part of source-cooperative/source.coop#491.