|
1 | 1 | package io.github.easy4j.hermes; |
2 | 2 | import io.github.easy4j.hermes.api.HermesApiConstants; |
| 3 | +import io.github.easy4j.hermes.security.CredentialProvider; |
| 4 | +import io.github.easy4j.hermes.security.CredentialSnapshot; |
3 | 5 | import io.github.easy4j.hermes.security.EndpointPolicy; |
| 6 | +import io.github.easy4j.hermes.security.ProfileIdentity; |
4 | 7 | import lombok.Data; |
5 | 8 |
|
6 | 9 | import java.util.Objects; |
@@ -73,6 +76,12 @@ public HermesHttpClientConfig(HermesDebugConfig debug) { |
73 | 76 | */ |
74 | 77 | private String apiKey; |
75 | 78 |
|
| 79 | + /** 命名 Profile 的每请求凭据提供器;设置后优先于静态 apiKey。 */ |
| 80 | + private CredentialProvider credentialProvider; |
| 81 | + |
| 82 | + /** 当前命名 Profile 的非秘密身份。 */ |
| 83 | + private ProfileIdentity profileIdentity; |
| 84 | + |
76 | 85 | /** |
77 | 86 | * 建立连接的超时时间,单位为毫秒。 |
78 | 87 | */ |
@@ -236,6 +245,17 @@ public void markUnsafeBaseUrlOverriddenForTest(boolean value) { |
236 | 245 | } |
237 | 246 |
|
238 | 247 | public String resolveApiKey() { |
| 248 | + if (credentialProvider != null) { |
| 249 | + if (profileIdentity == null) { |
| 250 | + throw new IllegalStateException("Profile identity is required for dynamic credentials"); |
| 251 | + } |
| 252 | + CredentialSnapshot snapshot = credentialProvider.resolve(profileIdentity); |
| 253 | + if (snapshot == null) { |
| 254 | + throw new IllegalStateException("No credential is available for Hermes profile " |
| 255 | + + profileIdentity.getProfileId()); |
| 256 | + } |
| 257 | + return Objects.toString(snapshot.getToken(), ""); |
| 258 | + } |
239 | 259 | return Objects.toString(apiKey, ""); |
240 | 260 | } |
241 | 261 | } |
0 commit comments