From 6fda826deb2feca1c82819d6e5a5614841858d0a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E5=B1=88=E8=BD=A9?= Date: Fri, 8 Apr 2022 01:35:47 +0800 Subject: [PATCH] fix(region): qcloud client no need fetch bucket (#13880) --- pkg/multicloud/qcloud/qcloud.go | 39 ++++++++++++++++++------------ pkg/multicloud/qcloud/shell/sts.go | 33 +++++++++++++++++++++++++ pkg/multicloud/qcloud/sts.go | 36 +++++++++++++++++++++++++++ 3 files changed, 93 insertions(+), 15 deletions(-) create mode 100644 pkg/multicloud/qcloud/shell/sts.go create mode 100644 pkg/multicloud/qcloud/sts.go diff --git a/pkg/multicloud/qcloud/qcloud.go b/pkg/multicloud/qcloud/qcloud.go index bf95bc7712..22b8797310 100644 --- a/pkg/multicloud/qcloud/qcloud.go +++ b/pkg/multicloud/qcloud/qcloud.go @@ -70,6 +70,7 @@ const ( QCLOUD_KAFKA_API_VERSION = "2019-08-19" QCLOUD_TKE_API_VERSION = "2018-05-25" QCLOUD_DNS_API_VERSION = "2021-03-23" + QCLOUD_STS_API_VERSION = "2018-08-13" ) type QcloudClientConfig struct { @@ -107,7 +108,6 @@ func (cfg *QcloudClientConfig) Debug(debug bool) *QcloudClientConfig { type SQcloudClient struct { *QcloudClientConfig - uin string ownerId string ownerName string @@ -123,17 +123,6 @@ func NewQcloudClient(cfg *QcloudClientConfig) (*SQcloudClient, error) { if err != nil { return nil, errors.Wrap(err, "fetchRegions") } - // err = client.verifyAppId() - // if err != nil { - // return nil, errors.Wrap(err, "verifyAppId") - // } - err = client.fetchBuckets() - if err != nil { - return nil, errors.Wrap(err, "fetchBuckets") - } - if client.debug { - log.Debugf("ownerID: %s ownerName: %s", client.ownerId, client.ownerName) - } return &client, nil } @@ -301,6 +290,12 @@ func cdnRequest(client *common.Client, apiName string, params map[string]string, return _jsonRequest(client, domain, QCLOUD_CDN_API_VERSION, apiName, params, updateFunc, debug, true) } +func stsRequest(client *common.Client, apiName string, params map[string]string, updateFunc func(string, string), + debug bool) (jsonutils.JSONObject, error) { + domain := "sts.tencentcloudapi.com" + return _jsonRequest(client, domain, QCLOUD_STS_API_VERSION, apiName, params, updateFunc, debug, true) +} + // ============phpJsonRequest============ type qcloudResponse interface { tchttp.Response @@ -830,6 +825,14 @@ func (client *SQcloudClient) cdnRequest(apiName string, params map[string]string return cdnRequest(cli, apiName, params, client.cpcfg.UpdatePermission, client.debug) } +func (client *SQcloudClient) stsRequest(apiName string, params map[string]string) (jsonutils.JSONObject, error) { + cli, err := client.getDefaultClient() + if err != nil { + return nil, err + } + return stsRequest(cli, apiName, params, client.cpcfg.UpdatePermission, client.debug) +} + func (client *SQcloudClient) jsonRequest(apiName string, params map[string]string, retry bool) (jsonutils.JSONObject, error) { cli, err := client.getDefaultClient() if err != nil { @@ -1000,12 +1003,18 @@ func (client *SQcloudClient) GetSubAccounts() ([]cloudprovider.SSubAccount, erro return []cloudprovider.SSubAccount{subAccount}, nil } -func (client *SQcloudClient) GetAccountId() string { - return client.ownerName +func (self *SQcloudClient) GetAccountId() string { + if len(self.ownerId) == 0 { + caller, err := self.GetCallerIdentity() + if err == nil { + self.ownerId = caller.AccountId + } + } + return self.ownerId } func (client *SQcloudClient) GetIamLoginUrl() string { - return fmt.Sprintf("https://cloud.tencent.com/login/subAccount?account=%s", client.ownerName) + return fmt.Sprintf("https://cloud.tencent.com/login/subAccount") } func (client *SQcloudClient) GetIRegions() []cloudprovider.ICloudRegion { diff --git a/pkg/multicloud/qcloud/shell/sts.go b/pkg/multicloud/qcloud/shell/sts.go new file mode 100644 index 0000000000..6f2c2d2151 --- /dev/null +++ b/pkg/multicloud/qcloud/shell/sts.go @@ -0,0 +1,33 @@ +// Copyright 2019 Yunion +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package shell + +import ( + "yunion.io/x/onecloud/pkg/multicloud/qcloud" + "yunion.io/x/onecloud/pkg/util/shellutils" +) + +func init() { + type CallerShowOptions struct { + } + shellutils.R(&CallerShowOptions{}, "caller-show", "Show caller", func(cli *qcloud.SRegion, args *CallerShowOptions) error { + caller, err := cli.GetClient().GetCallerIdentity() + if err != nil { + return err + } + printObject(caller) + return nil + }) +} diff --git a/pkg/multicloud/qcloud/sts.go b/pkg/multicloud/qcloud/sts.go new file mode 100644 index 0000000000..da90164351 --- /dev/null +++ b/pkg/multicloud/qcloud/sts.go @@ -0,0 +1,36 @@ +// Copyright 2019 Yunion +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package qcloud + +type CallerIdentity struct { + AccountId string + Arn string + PrincipalId string + RequestId string + Type string + UserId string +} + +func (self *SQcloudClient) GetCallerIdentity() (*CallerIdentity, error) { + params := map[string]string{ + "Region": "ap-beijing", + } + resp, err := self.stsRequest("GetCallerIdentity", params) + if err != nil { + return nil, err + } + ret := &CallerIdentity{} + return ret, resp.Unmarshal(ret) +}