Skip to main content

Aliyun OSS

Aliyun Object Storage Service requests signed with OSS signature V1, V2, or V4.

OSS signature V1OSS signature V2OSS signature V4✓ header signing✓ query / presign✓ WASMdocs.rs/reqsign-aliyun-oss ↗

expires_in selects query-string authentication for presigned OSS URLs.

Get started​

cargo add reqsign --features aliyun
use reqsign::aliyun;

// Env, config files, ECS RAM roles, OIDC — resolved by the default chain.
let signer = aliyun::default_signer("my-bucket");

let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://my-bucket.oss-cn-hangzhou.aliyuncs.com/my-object")
.body(())?
.into_parts()
.0;

// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;

Credentials

Default credential chain

The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:

  1. STS AssumeRole (when a role is configured)
  2. Environment variables
  3. OSS profile
  4. Credentials file
  5. CLI config file
  6. Credentials URI
  7. ECS RAM role metadata
  8. STS AssumeRole with OIDC

Credential providers

Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials: