|
1024 | 1024 | "smithy.api#httpError": 400 |
1025 | 1025 | } |
1026 | 1026 | }, |
| 1027 | + "com.amazonaws.ssooidc#AwsAdditionalDetails": { |
| 1028 | + "type": "structure", |
| 1029 | + "members": { |
| 1030 | + "identityContext": { |
| 1031 | + "target": "com.amazonaws.ssooidc#IdentityContext", |
| 1032 | + "traits": { |
| 1033 | + "smithy.api#documentation": "<p>STS context assertion that carries a user identifier to the Amazon Web Services service that it calls\n and can be used to obtain an identity-enhanced IAM role session. This value corresponds to\n the <code>sts:identity_context</code> claim in the ID token.</p>" |
| 1034 | + } |
| 1035 | + } |
| 1036 | + }, |
| 1037 | + "traits": { |
| 1038 | + "smithy.api#documentation": "<p>This structure contains Amazon Web Services-specific parameter extensions for the token endpoint\n responses and includes the identity context.</p>" |
| 1039 | + } |
| 1040 | + }, |
1027 | 1041 | "com.amazonaws.ssooidc#ClientId": { |
1028 | 1042 | "type": "string" |
1029 | 1043 | }, |
|
1304 | 1318 | "refreshToken": "aorvJYubGpU6i91YnH7Mfo-AT2fIVa1zCfA_Rvq9yjVKIP3onFmmykuQ7E93y2I-9Nyj-A_sVvMufaLNL0bqnDRtgAkc0:MGUCMFrRsktMRVlWaOR70XGMFGLL0SlcCw4DiYveIiOVx1uK9BbD0gvAddsW3UTLozXKMgIxAJ3qxUvjpnlLIOaaKOoa/FuNgqJVvr9GMwDtnAtlh9iZzAkEXAMPLEREFRESHTOKEN", |
1305 | 1319 | "idToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhd3M6aWRlbnRpdHlfc3RvcmVfaWQiOiJkLTMzMzMzMzMzMzMiLCJzdWIiOiI3MzA0NDhmMi1lMGExLTcwYTctYzk1NC0wMDAwMDAwMDAwMDAiLCJhd3M6aW5zdGFuY2VfYWNjb3VudCI6IjExMTExMTExMTExMSIsInN0czppZGVudGl0eV9jb250ZXh0IjoiRVhBTVBMRUlERU5USVRZQ09OVEVYVCIsInN0czphdWRpdF9jb250ZXh0IjoiRVhBTVBMRUFVRElUQ09OVEVYVCIsImlzcyI6Imh0dHBzOi8vaWRlbnRpdHljZW50ZXIuYW1hem9uYXdzLmNvbS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmlkZW50aXR5X3N0b3JlX2FybiI6ImFybjphd3M6aWRlbnRpdHlzdG9yZTo6MTExMTExMTExMTExOmlkZW50aXR5c3RvcmUvZC0zMzMzMzMzMzMzIiwiYXVkIjoiYXJuOmF3czpzc286OjEyMzQ1Njc4OTAxMjphcHBsaWNhdGlvbi9zc29pbnMtMTExMTExMTExMTExL2FwbC0yMjIyMjIyMjIyMjIiLCJhd3M6aW5zdGFuY2VfYXJuIjoiYXJuOmF3czpzc286OjppbnN0YW5jZS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmNyZWRlbnRpYWxfaWQiOiJfWlIyTjZhVkJqMjdGUEtheWpfcEtwVjc3QVBERl80MXB4ZXRfWWpJdUpONlVJR2RBdkpFWEFNUExFQ1JFRElEIiwiYXV0aF90aW1lIjoiMjAyMC0wMS0yMlQxMjo0NToyOVoiLCJleHAiOjE1Nzk3Mjk1MjksImlhdCI6MTU3OTcyNTkyOX0.Xyah6qbk78qThzJ41iFU2yfGuRqqtKXHrJYwQ8L9Ip0", |
1306 | 1320 | "issuedTokenType": "urn:ietf:params:oauth:token-type:refresh_token", |
1307 | | - "scope": ["openid", "aws", "sts:identity_context"] |
| 1321 | + "scope": ["openid", "aws", "sts:identity_context"], |
| 1322 | + "awsAdditionalDetails": { |
| 1323 | + "identityContext": "EXAMPLEIDENTITYCONTEXT" |
| 1324 | + } |
1308 | 1325 | } |
1309 | 1326 | }, |
1310 | 1327 | { |
|
1322 | 1339 | "refreshToken": "aorvJYubGpU6i91YnH7Mfo-AT2fIVa1zCfA_Rvq9yjVKIP3onFmmykuQ7E93y2I-9Nyj-A_sVvMufaLNL0bqnDRtgAkc0:MGUCMFrRsktMRVlWaOR70XGMFGLL0SlcCw4DiYveIiOVx1uK9BbD0gvAddsW3UTLozXKMgIxAJ3qxUvjpnlLIOaaKOoa/FuNgqJVvr9GMwDtnAtlh9iZzAkEXAMPLEREFRESHTOKEN", |
1323 | 1340 | "idToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhd3M6aWRlbnRpdHlfc3RvcmVfaWQiOiJkLTMzMzMzMzMzMzMiLCJzdWIiOiI3MzA0NDhmMi1lMGExLTcwYTctYzk1NC0wMDAwMDAwMDAwMDAiLCJhd3M6aW5zdGFuY2VfYWNjb3VudCI6IjExMTExMTExMTExMSIsInN0czppZGVudGl0eV9jb250ZXh0IjoiRVhBTVBMRUlERU5USVRZQ09OVEVYVCIsInN0czphdWRpdF9jb250ZXh0IjoiRVhBTVBMRUFVRElUQ09OVEVYVCIsImlzcyI6Imh0dHBzOi8vaWRlbnRpdHljZW50ZXIuYW1hem9uYXdzLmNvbS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmlkZW50aXR5X3N0b3JlX2FybiI6ImFybjphd3M6aWRlbnRpdHlzdG9yZTo6MTExMTExMTExMTExOmlkZW50aXR5c3RvcmUvZC0zMzMzMzMzMzMzIiwiYXVkIjoiYXJuOmF3czpzc286OjEyMzQ1Njc4OTAxMjphcHBsaWNhdGlvbi9zc29pbnMtMTExMTExMTExMTExL2FwbC0yMjIyMjIyMjIyMjIiLCJhd3M6aW5zdGFuY2VfYXJuIjoiYXJuOmF3czpzc286OjppbnN0YW5jZS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmNyZWRlbnRpYWxfaWQiOiJfWlIyTjZhVkJqMjdGUEtheWpfcEtwVjc3QVBERl80MXB4ZXRfWWpJdUpONlVJR2RBdkpFWEFNUExFQ1JFRElEIiwiYXV0aF90aW1lIjoiMjAyMC0wMS0yMlQxMjo0NToyOVoiLCJleHAiOjE1Nzk3Mjk1MjksImlhdCI6MTU3OTcyNTkyOX0.Xyah6qbk78qThzJ41iFU2yfGuRqqtKXHrJYwQ8L9Ip0", |
1324 | 1341 | "issuedTokenType": "urn:ietf:params:oauth:token-type:refresh_token", |
1325 | | - "scope": ["openid", "aws", "sts:identity_context"] |
| 1342 | + "scope": ["openid", "aws", "sts:identity_context"], |
| 1343 | + "awsAdditionalDetails": { |
| 1344 | + "identityContext": "EXAMPLEIDENTITYCONTEXT" |
| 1345 | + } |
1326 | 1346 | } |
1327 | 1347 | }, |
1328 | 1348 | { |
|
1358 | 1378 | "expiresIn": 1579729529, |
1359 | 1379 | "idToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJhd3M6aWRlbnRpdHlfc3RvcmVfaWQiOiJkLTMzMzMzMzMzMzMiLCJzdWIiOiI3MzA0NDhmMi1lMGExLTcwYTctYzk1NC0wMDAwMDAwMDAwMDAiLCJhd3M6aW5zdGFuY2VfYWNjb3VudCI6IjExMTExMTExMTExMSIsInN0czppZGVudGl0eV9jb250ZXh0IjoiRVhBTVBMRUlERU5USVRZQ09OVEVYVCIsImlzcyI6Imh0dHBzOi8vaWRlbnRpdHljZW50ZXIuYW1hem9uYXdzLmNvbS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmlkZW50aXR5X3N0b3JlX2FybiI6ImFybjphd3M6aWRlbnRpdHlzdG9yZTo6MTExMTExMTExMTExOmlkZW50aXR5c3RvcmUvZC0zMzMzMzMzMzMzIiwiYXVkIjoiYXJuOmF3czpzc286OjEyMzQ1Njc4OTAxMjphcHBsaWNhdGlvbi9zc29pbnMtMTExMTExMTExMTExL2FwbC0yMjIyMjIyMjIyMjIiLCJhd3M6aW5zdGFuY2VfYXJuIjoiYXJuOmF3czpzc286OjppbnN0YW5jZS9zc29pbnMtMTExMTExMTExMTExIiwiYXdzOmNyZWRlbnRpYWxfaWQiOiJfWlIyTjZhVkJqMjdGUEtheWpfcEtwVjc3QVBERl80MXB4ZXRfWWpJdUpONlVJR2RBdkpFWEFNUExFQ1JFRElEIiwiYXV0aF90aW1lIjoiMjAyMC0wMS0yMlQxMjo0NToyOVoiLCJleHAiOjE1Nzk3Mjk1MjksImlhdCI6MTU3OTcyNTkyOX0.5SYiW1kMsuUr7nna-l5tlakM0GNbMHvIM2_n0QD23jM", |
1360 | 1380 | "issuedTokenType": "urn:ietf:params:oauth:token-type:access_token", |
1361 | | - "scope": ["openid", "aws", "sts:identity_context"] |
| 1381 | + "scope": ["openid", "aws", "sts:identity_context"], |
| 1382 | + "awsAdditionalDetails": { |
| 1383 | + "identityContext": "EXAMPLEIDENTITYCONTEXT" |
| 1384 | + } |
1362 | 1385 | } |
1363 | 1386 | } |
1364 | 1387 | ], |
|
1490 | 1513 | "traits": { |
1491 | 1514 | "smithy.api#documentation": "<p>The list of scopes for which authorization is granted. The access token that is issued is\n limited to the scopes that are granted.</p>" |
1492 | 1515 | } |
| 1516 | + }, |
| 1517 | + "awsAdditionalDetails": { |
| 1518 | + "target": "com.amazonaws.ssooidc#AwsAdditionalDetails", |
| 1519 | + "traits": { |
| 1520 | + "smithy.api#documentation": "<p>A structure containing information from the <code>idToken</code>. Only the\n <code>identityContext</code> is in it, which is a value extracted from the\n <code>idToken</code>. This provides direct access to identity information without requiring\n JWT parsing.</p>" |
| 1521 | + } |
1493 | 1522 | } |
1494 | 1523 | }, |
1495 | 1524 | "traits": { |
|
1548 | 1577 | "smithy.api#sensitive": {} |
1549 | 1578 | } |
1550 | 1579 | }, |
| 1580 | + "com.amazonaws.ssooidc#IdentityContext": { |
| 1581 | + "type": "string" |
| 1582 | + }, |
1551 | 1583 | "com.amazonaws.ssooidc#InternalServerException": { |
1552 | 1584 | "type": "structure", |
1553 | 1585 | "members": { |
|
1995 | 2027 | "output": { |
1996 | 2028 | "deviceCode": "yJraWQiOiJrZXktMTU2Njk2ODA4OCIsImFsZyI6IkhTMzIn0EXAMPLEDEVICECODE", |
1997 | 2029 | "userCode": "makdfsk83yJraWQiOiJrZXktMTU2Njk2sImFsZyI6IkhTMzIn0EXAMPLEUSERCODE", |
1998 | | - "verificationUri": "https://device.sso.us-west-2.amazonaws.com", |
1999 | | - "verificationUriComplete": "https://device.sso.us-west-2.amazonaws.com?user_code=makdfsk83yJraWQiOiJrZXktMTU2Njk2sImFsZyI6IkhTMzIn0EXAMPLEUSERCODE", |
| 2030 | + "verificationUri": "https://directory-alias-example.awsapps.com/start/#/device", |
| 2031 | + "verificationUriComplete": "https://directory-alias-example.awsapps.com/start/#/device?user_code=makdfsk83yJraWQiOiJrZXktMTU2Njk2sImFsZyI6IkhTMzIn0EXAMPLEUSERCODE", |
2000 | 2032 | "expiresIn": 1579729529, |
2001 | 2033 | "interval": 1 |
2002 | 2034 | } |
|
0 commit comments