#gotham #aws #amazon #signing-key #signature-verification

gotham_middleware_aws_sig_verify

Gotham 中间件用于 AWS SigV4 验证

2 个不稳定版本

0.2.0 2020 年 5 月 26 日
0.1.0 2020 年 3 月 24 日

#9#gotham

Apache-2.0 协议

15KB
236 行代码(不含注释)

Gotham 中间件用于 AWS SigV4 验证

包: gotham_middleware_aws_sig_verify

gotham_middleware_aws_sig_verify 包将 AWS SigV4 验证(来自 aws_sig_verify)集成到 Gotham 网络框架中。

假设您有一个函数 get_signing_key,它可以返回 AWS 访问密钥(和可选令牌)对应的签名密钥,集成方法如下:

use gotham;
use gotham::pipeline::new_pipeline;
use gotham::pipeline::single::single_pipeline;
use gotham::router::builder::{build_router, DefineSingleRoute, DrawRoutes};
use gotham::router::Router;
use gotham::state::State;
use gotham_middleware_aws_sig_verify::{AWSSigV4Verifier, SigningKeyKind, SignatureError};
use http::status::StatusCode;
use hyper::{Body, Response};

const SERVICE: &str = "myservice";
const REGION: &str = "local";

fn router() -> Router {
    let verifier = AWSSigV4Verifier::new(get_signing_key, SERVICE, REGION);
    let (chain, pipelines) = single_pipeline(new_pipeline().add(verifier).build());
    build_router(chain, pipelines, |route| {
        route.get("/").to(my_handler);
    })
}

fn my_handler(state: State) -> (State, Response<Body>) {
    let response: Response<Body> = Response::builder()
        .header("Content-Type", "text/plain; charset=utf-8")
        .status(StatusCode::OK)
        .body(Body::from("OK"))
        .unwrap();

    (state, response)
}

fn get_signing_key(
    kind: SigningKeyKind,
    access_key_id: &str,
    session_token: Option<&str>,
    req_date_opt: Option<&str>,
    region_opt: Option<&str>,
    service_opt: Option<&str>
) -> Result<Vec<u8>, SignatureError> {
    ...
}

pub fn main() {
    gotham::start("127.0.0.1:8080", router())
}

依赖项

~27MB
~601K SLoC