Tencent COS
Tencent Cloud Object Storage requests signed with the COS signature.
expires_in selects q-sign query authentication for presigned COS URLs.
Get started
cargo add reqsign --features tencent
use reqsign::tencent;
// Env, config, OIDC federation — resolved by the default chain.
let signer = tencent::default_signer();
let mut req = http::Request::builder()
.method(http::Method::GET)
.uri("https://my-bucket-1250000000.cos.ap-guangzhou.myqcloud.com/my-object")
.body(())?
.into_parts()
.0;
// Sign in place, then send with the HTTP client you already use.
signer.sign(&mut req, None).await?;
Credentials
Default credential chain
The default signer tries these sources in order and uses the first one that yields a credential — no configuration needed when any of them is present:
- Environment variables
- STS AssumeRoleWithWebIdentity (OIDC)
Credential providers
Available ProvideCredential implementations. Construct any of them directly, reorder them, or compose them into your own chain — see Loading credentials:
EnvCredentialProvider— Environment variablesAssumeRoleWithWebIdentityCredentialProvider— STS AssumeRoleWithWebIdentity (OIDC)StaticCredentialProvider— Static access keysConfigCredentialProvider— Config-based credentials