Aliyun OSS
Aliyun Object Storage Service requests signed with OSS signature V1, V2, or V4.
OSS signature V1OSS signature V2OSS signature V4✓ header signing✓ query / presign✓ WASMdocs.rs/reqsign-aliyun-oss ↗
expires_in selects query-string authentication for presigned OSS URLs.
Get started
cargo add reqsign --features aliyun
use reqsign::aliyun;
// Env, config files, ECS RAM roles, OIDC — resolved by the default chain.
let signer = aliyun::default_signer("my-bucket");
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://my-bucket.oss-cn-hangzhou.aliyuncs.com/my-object")
.body(())?
.into_parts()
.0;
// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;
Credentials
Default credential chain
The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:
- STS AssumeRole (when a role is configured)
- Environment variables
- OSS profile
- Credentials file
- CLI config file
- Credentials URI
- ECS RAM role metadata
- STS AssumeRole with OIDC
Credential providers
Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:
AssumeRoleCredentialProvider— STS AssumeRole (when a role is configured)EnvCredentialProvider— Environment variablesOssProfileCredentialProvider— OSS profileCredentialsFileCredentialProvider— Credentials fileConfigFileCredentialProvider— CLI config fileCredentialsUriCredentialProvider— Credentials URIEcsRamRoleCredentialProvider— ECS RAM role metadataAssumeRoleWithOidcCredentialProvider— STS AssumeRole with OIDCStaticCredentialProvider— Static access keys