keystone.auth.plugins.ec2credential module¶
EC2 credential marker auth plugin.
This is a deliberately non-functional auth plugin. EC2 and S3 credentials
are validated and exchanged for tokens exclusively by the /v3/ec2tokens
and /v3/s3tokens endpoints, which never invoke this plugin. Its sole
purpose is to give the ec2credential auth method – the marker those
endpoints have recorded on the tokens they mint since the method was
introduced – a registered identity, so that the marker survives the token
payload round-trip (the fernet provider encodes methods as a bitmask of
the configured auth methods, so an unregistered method is silently
dropped).
Preserving the method name is what allows the guards that reject delegated-credential tokens (authorization in Keystone, token re-scoping, trust / application credential / OAuth1 management) to recognize a token that was minted from an EC2 or S3 credential (LP#2153453).
- class keystone.auth.plugins.ec2credential.Plugin[source]¶
Bases:
AuthMethodHandler- authenticate(auth_payload)[source]¶
Authenticate user and return an authentication context.
- Parameters:
auth_payload (dict) – the payload content of the authentication request for a given method
If successful, plugin must set
user_idinresponse_data.method_nameis used to convey any additional authentication methods in case authentication is for re-scoping. For example, if the authentication is for re-scoping, plugin must append the previous method names intomethod_names; NOTE: This behavior is exclusive to the re-scope type action. Here’s an example ofresponse_dataon successful authentication:{"methods": ["password", "token"], "user_id": "abc123"}
Plugins are invoked in the order in which they are specified in the
methodsattribute of theidentityobject. For example,custom-pluginis invoked beforepassword, which is invoked beforetokenin the following authentication request:{ "auth": { "identity": { "custom-plugin": {"custom-data": "sdfdfsfsfsdfsf"}, "methods": ["custom-plugin", "password", "token"], "password": { "user": {"id": "s23sfad1", "password": "secret"} }, "token": {"id": "sdfafasdfsfasfasdfds"}, } } }
- Returns:
AuthHandlerResponse with status set to
Trueif auth was successful. If status isFalseand this is a multi-step auth, theresponse_bodycan be in a form of a dict for the next step in authentication.- Raises:
keystone.exception.Unauthorized – for authentication failure