Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add support for AWS_SESSION_TOKEN and AWS_SECURITY_TOKEN #283

Merged
merged 2 commits into from
Mar 31, 2017
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 15 additions & 7 deletions storages/backends/s3boto.py
Original file line number Diff line number Diff line change
Expand Up @@ -205,6 +205,7 @@ class S3BotoStorage(Storage):
# used for looking up the access and secret key from env vars
access_key_names = ['AWS_S3_ACCESS_KEY_ID', 'AWS_ACCESS_KEY_ID']
secret_key_names = ['AWS_S3_SECRET_ACCESS_KEY', 'AWS_SECRET_ACCESS_KEY']
security_token_names = ['AWS_SESSION_TOKEN', 'AWS_SECURITY_TOKEN']

access_key = setting('AWS_S3_ACCESS_KEY_ID', setting('AWS_ACCESS_KEY_ID'))
secret_key = setting('AWS_S3_SECRET_ACCESS_KEY', setting('AWS_SECRET_ACCESS_KEY'))
Expand Down Expand Up @@ -270,13 +271,15 @@ def __init__(self, acl=None, bucket=None, **settings):

if not self.access_key and not self.secret_key:
self.access_key, self.secret_key = self._get_access_keys()
self.security_token = self._get_security_token()

@property
def connection(self):
if self._connection is None:
self._connection = self.connection_class(
self.access_key,
self.secret_key,
security_token=self.security_token,
is_secure=self.use_ssl,
calling_format=self.calling_format,
host=self.host,
Expand Down Expand Up @@ -306,21 +309,26 @@ def entries(self):
for entry in self.bucket.list(prefix=self.location))
return self._entries

def _lookup_env(self, names):
for name in names:
value = os.environ.get(name)
if value:
return value

def _get_access_keys(self):
"""
Gets the access keys to use when accessing S3. If none
are provided to the class in the constructor or in the
settings then get them from the environment variables.
"""
def lookup_env(names):
for name in names:
value = os.environ.get(name)
if value:
return value
access_key = self.access_key or lookup_env(self.access_key_names)
secret_key = self.secret_key or lookup_env(self.secret_key_names)
access_key = self.access_key or self._lookup_env(self.access_key_names)
secret_key = self.secret_key or self._lookup_env(self.secret_key_names)
return access_key, secret_key

def _get_security_token(self):
security_token = self._lookup_env(self.security_token_names)
return security_token

def _get_or_create_bucket(self, name):
"""
Retrieves a bucket if it exists, otherwise creates it.
Expand Down
22 changes: 15 additions & 7 deletions storages/backends/s3boto3.py
Original file line number Diff line number Diff line change
Expand Up @@ -209,6 +209,7 @@ class S3Boto3Storage(Storage):
# used for looking up the access and secret key from env vars
access_key_names = ['AWS_S3_ACCESS_KEY_ID', 'AWS_ACCESS_KEY_ID']
secret_key_names = ['AWS_S3_SECRET_ACCESS_KEY', 'AWS_SECRET_ACCESS_KEY']
security_token_names = ['AWS_SESSION_TOKEN', 'AWS_SECURITY_TOKEN']

access_key = setting('AWS_S3_ACCESS_KEY_ID', setting('AWS_ACCESS_KEY_ID'))
secret_key = setting('AWS_S3_SECRET_ACCESS_KEY', setting('AWS_SECRET_ACCESS_KEY'))
Expand Down Expand Up @@ -272,6 +273,7 @@ def __init__(self, acl=None, bucket=None, **settings):

if not self.access_key and not self.secret_key:
self.access_key, self.secret_key = self._get_access_keys()
self.security_token = self._get_security_token()

if not self.config:
self.config = Config(s3={'addressing_style': self.addressing_style},
Expand All @@ -289,6 +291,7 @@ def connection(self):
self.connection_service_name,
aws_access_key_id=self.access_key,
aws_secret_access_key=self.secret_key,
aws_session_token=self.security_token,
region_name=self.region_name,
use_ssl=self.use_ssl,
endpoint_url=self.endpoint_url,
Expand Down Expand Up @@ -316,21 +319,26 @@ def entries(self):
for entry in self.bucket.objects.filter(Prefix=self.location))
return self._entries

def _lookup_env(self, names):
for name in names:
value = os.environ.get(name)
if value:
return value

def _get_access_keys(self):
"""
Gets the access keys to use when accessing S3. If none
are provided to the class in the constructor or in the
settings then get them from the environment variables.
"""
def lookup_env(names):
for name in names:
value = os.environ.get(name)
if value:
return value
access_key = self.access_key or lookup_env(self.access_key_names)
secret_key = self.secret_key or lookup_env(self.secret_key_names)
access_key = self.access_key or self._lookup_env(self.access_key_names)
secret_key = self.secret_key or self._lookup_env(self.secret_key_names)
return access_key, secret_key

def _get_security_token(self):
security_token = self._lookup_env(self.security_token_names)
return security_token

def _get_or_create_bucket(self, name):
"""
Retrieves a bucket if it exists, otherwise creates it.
Expand Down