123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108 |
- <?php
- define('ECS_ROLE_EXPIRE_TIME', 3600);
- class EcsRamRoleService
- {
-
- private $clientProfile;
-
- private $lastClearTime = null;
-
- private $sessionCredential = null;
-
- public function __construct($clientProfile)
- {
- $this->clientProfile = $clientProfile;
- }
-
- public function getSessionCredential()
- {
- if ($this->lastClearTime != null && $this->sessionCredential != null) {
- $now = time();
- $elapsedTime = $now - $this->lastClearTime;
- if ($elapsedTime <= ECS_ROLE_EXPIRE_TIME * 0.8) {
- return $this->sessionCredential;
- }
- }
- $credential = $this->assumeRole();
- if ($credential == null) {
- return null;
- }
- $this->sessionCredential = $credential;
- $this->lastClearTime = time();
- return $credential;
- }
-
- private function assumeRole()
- {
- $ecsRamRoleCredential = $this->clientProfile->getCredential();
- $requestUrl =
- 'http://100.100.100.200/latest/meta-data/ram/security-credentials/' . $ecsRamRoleCredential->getRoleName();
- $httpResponse = HttpHelper::curl($requestUrl, 'GET', null, null);
- if (!$httpResponse->isSuccess()) {
- return null;
- }
- $respObj = json_decode($httpResponse->getBody());
- $code = $respObj->Code;
- if ($code != 'Success') {
- return null;
- }
- $sessionAccessKeyId = $respObj->AccessKeyId;
- $sessionAccessKeySecret = $respObj->AccessKeySecret;
- $securityToken = $respObj->SecurityToken;
- return new Credential($sessionAccessKeyId, $sessionAccessKeySecret, $securityToken);
- }
- }
|