Skip to content

Unattended refresh: exchange an API key without a browser and keep the token file fresh #17

Description

@alukach

Phase 5 — API keys.

Today
The CLI caches credentials and checks their expiry — and when they have expired it stops: Cached credentials have expired. Run 'source-coop login' to refresh. (src/main.rs). That is interactive, so nothing keeps a token file fresh for a daemon.

The CLI also sends the token as a URL query parameter (src/sts.rs, append_pair("WebIdentityToken", …)), so bearer tokens land in access logs.

Do

  • Add a mode that reads an API key, exchanges it at /.sts without a browser, and keeps AWS_WEB_IDENTITY_TOKEN_FILE fresh.
  • Send the token in the request body. The proxy already accepts form-encoded bodies, so this is CLI-only.

Done when
A daemon holding a key and no browser runs across a credential expiry, and the token never appears in a request URL.

Depends on source-cooperative/source.coop#548.


Part of source-cooperative/source.coop#491.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions