Compare commits

..
13 Commits
Author SHA1 Message Date
Dave Horton 8511e762c8 version update 2024-07-30 07:29:25 -04:00
Dave Horton b75d3068c9 Merge pull request #81 from jambonz/feat/gh_fs_832
allow configure STS session expiry
2024-07-30 07:14:06 -04:00
Quan HL 7fd1e1a3c3 allow configure STS session expiry 2024-07-29 18:18:37 +07:00
Dave Horton 7f6a3d349c 0.1.11 2024-06-14 07:37:19 -04:00
Dave Horton 50429ff535 bump version 2024-06-14 07:36:53 -04:00
Dave Horton 3bf0ef8ea3 Merge pull request #80 from jambonz/fix/aws_arnrole
fix aws arnrole
2024-06-14 07:34:22 -04:00
Quan HL e9a5e83e36 wip 2024-06-14 15:04:19 +07:00
Quan HL 86a64ac091 wip 2024-06-14 15:00:56 +07:00
Quan HL 97e06b3ab3 wip 2024-06-14 10:23:22 +07:00
Quan HL 09e833d910 wip 2024-06-14 10:19:55 +07:00
Quan HL 8c4e12e54f wip 2024-06-14 10:18:41 +07:00
Quan HL 2642bd71a4 wip 2024-06-14 10:16:57 +07:00
Quan HL c4feac916f fix aws arnrole 2024-06-14 10:15:23 +07:00
7 changed files with 1600 additions and 1407 deletions
+1 -1
View File
@@ -1,3 +1,3 @@
npm audit #npm audit
npm run jslint:fix || true npm run jslint:fix || true
npm test npm test
+10 -9
View File
@@ -1,20 +1,22 @@
const { STSClient, GetSessionTokenCommand, AssumeRoleCommand } = require('@aws-sdk/client-sts'); const { STSClient, GetSessionTokenCommand, AssumeRoleCommand } = require('@aws-sdk/client-sts');
const {makeAwsKey, noopLogger} = require('./utils'); const {makeAwsKey, noopLogger} = require('./utils');
const debug = require('debug')('jambonz:speech-utils'); const debug = require('debug')('jambonz:speech-utils');
const EXPIRY = 3600; const EXPIRY = process.env.AWS_STS_SESSION_DURATION || 3600;
// by default reset aws session before expiry time 10 mins
const CACHE_EXPIRY = process.env.AWS_STS_SESSION_RESET_EXPIRY || (EXPIRY - 600);
async function getAwsAuthToken( async function getAwsAuthToken(
logger, createHash, retrieveHash, logger, createHash, retrieveHash,
awsAccessKeyId, awsSecretAccessKey, awsRegion, roleArn = null) { {accessKeyId, secretAccessKey, region, roleArn}) {
logger = logger || noopLogger; logger = logger || noopLogger;
try { try {
const key = makeAwsKey(roleArn || awsAccessKeyId); const key = makeAwsKey(roleArn || accessKeyId);
const obj = await retrieveHash(key); const obj = await retrieveHash(key);
if (obj) return {...obj, servedFromCache: true}; if (obj) return {...obj, servedFromCache: true};
let data; let data;
if (roleArn) { if (roleArn) {
const stsClient = new STSClient({ region: awsRegion}); const stsClient = new STSClient({ region });
const roleToAssume = { RoleArn: roleArn, RoleSessionName: 'Jambonz_Speech', DurationSeconds: EXPIRY}; const roleToAssume = { RoleArn: roleArn, RoleSessionName: 'Jambonz_Speech', DurationSeconds: EXPIRY};
const command = new AssumeRoleCommand(roleToAssume); const command = new AssumeRoleCommand(roleToAssume);
@@ -22,10 +24,10 @@ async function getAwsAuthToken(
} else { } else {
/* access token not found in cache, so generate it using STS */ /* access token not found in cache, so generate it using STS */
const stsClient = new STSClient({ const stsClient = new STSClient({
region: awsRegion, region,
credentials: { credentials: {
accessKeyId: awsAccessKeyId, accessKeyId,
secretAccessKey: awsSecretAccessKey, secretAccessKey,
} }
}); });
const command = new GetSessionTokenCommand({DurationSeconds: EXPIRY}); const command = new GetSessionTokenCommand({DurationSeconds: EXPIRY});
@@ -39,8 +41,7 @@ async function getAwsAuthToken(
securityToken: data.Credentials.SessionToken securityToken: data.Credentials.SessionToken
}; };
/* expire 10 minutes before the hour, so we don't lose the use of it during a call */ createHash(key, credentials, CACHE_EXPIRY)
createHash(key, credentials, EXPIRY - 600)
.catch((err) => logger.error(err, `Error saving hash for key ${key}`)); .catch((err) => logger.error(err, `Error saving hash for key ${key}`));
return {...credentials, servedFromCache: false}; return {...credentials, servedFromCache: false};
+6 -1
View File
@@ -107,7 +107,12 @@ const getAwsVoices = async(_client, createHash, retrieveHash, logger, credential
} else if (roleArn) { } else if (roleArn) {
client = new PollyClient({ client = new PollyClient({
region, region,
credentials: await getAwsAuthToken(logger, createHash, retrieveHash, null, null, region, roleArn), credentials: await getAwsAuthToken(
logger, createHash, retrieveHash,
{
region,
roleArn
}),
}); });
} else { } else {
client = new PollyClient({region}); client = new PollyClient({region});
+6 -1
View File
@@ -281,7 +281,12 @@ const synthPolly = async(createHash, retrieveHash, logger,
} else if (roleArn) { } else if (roleArn) {
polly = new PollyClient({ polly = new PollyClient({
region, region,
credentials: await getAwsAuthToken(logger, createHash, retrieveHash, null, null, region, roleArn), credentials: await getAwsAuthToken(
logger, createHash, retrieveHash,
{
region,
roleArn
}),
}); });
} else { } else {
// AWS RoleArn assigned to Instance profile // AWS RoleArn assigned to Instance profile
+1565 -1391
View File
File diff suppressed because it is too large Load Diff
+2 -2
View File
@@ -1,6 +1,6 @@
{ {
"name": "@jambonz/speech-utils", "name": "@jambonz/speech-utils",
"version": "0.1.9", "version": "0.1.12",
"description": "TTS-related speech utilities for jambonz", "description": "TTS-related speech utilities for jambonz",
"main": "index.js", "main": "index.js",
"author": "Dave Horton", "author": "Dave Horton",
@@ -36,7 +36,7 @@
"form-urlencoded": "^6.1.4", "form-urlencoded": "^6.1.4",
"google-protobuf": "^3.21.2", "google-protobuf": "^3.21.2",
"ibm-watson": "^8.0.0", "ibm-watson": "^8.0.0",
"microsoft-cognitiveservices-speech-sdk": "1.36.0", "microsoft-cognitiveservices-speech-sdk": "1.38.0",
"openai": "^4.25.0", "openai": "^4.25.0",
"undici": "^6.4.0" "undici": "^6.4.0"
}, },
+10 -2
View File
@@ -19,12 +19,20 @@ test('AWS - create and cache auth token', async(t) => {
return; return;
} }
try { try {
let obj = await getAwsAuthToken(process.env.AWS_ACCESS_KEY_ID, process.env.AWS_SECRET_ACCESS_KEY, process.env.AWS_REGION); let obj = await getAwsAuthToken({
accessKeyId: process.env.AWS_ACCESS_KEY_ID,
secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY,
region: process.env.AWS_REGION
});
//console.log({obj}, 'received auth token from AWS'); //console.log({obj}, 'received auth token from AWS');
t.ok(obj.securityToken && !obj.servedFromCache, 'successfullY generated auth token from AWS'); t.ok(obj.securityToken && !obj.servedFromCache, 'successfullY generated auth token from AWS');
await sleep(250); await sleep(250);
obj = await getAwsAuthToken(process.env.AWS_ACCESS_KEY_ID, process.env.AWS_SECRET_ACCESS_KEY, process.env.AWS_REGION); obj = await getAwsAuthToken({
accessKeyId: process.env.AWS_ACCESS_KEY_ID,
secretAccessKey: process.env.AWS_SECRET_ACCESS_KEY,
region: process.env.AWS_REGION
});
//console.log({obj}, 'received auth token from AWS - second request'); //console.log({obj}, 'received auth token from AWS - second request');
t.ok(obj.securityToken && obj.servedFromCache, 'successfully received access token from cache'); t.ok(obj.securityToken && obj.servedFromCache, 'successfully received access token from cache');