fe9d87d6dc2f3e6194862799b0707f97844e83ac

Author
Mike Mattice <mmattice@users.noreply.github.com>
Committer
GitHub <noreply@github.com>
Date

Message

feat(aws): accept aws mfa tokencode on `acp` cli call (#10130)

Co-authored-by: Mike Mattice <mmattice@reliant.io>

Diff

 1diff --git a/plugins/aws/README.md b/plugins/aws/README.md
 2index 24c6429ddbe11644ebb047cbd9e52f7e1584a185..d6f4f4600a5c9c3f00b2db78cbfbb2253a158adf 100644
 3--- a/plugins/aws/README.md
 4+++ b/plugins/aws/README.md
 5@@ -16,10 +16,10 @@ plugins=(... aws)
 6   Run `asp` without arguments to clear the profile.
 7 * `asp [<profile>] login`: If AWS SSO has been configured in your aws profile, it will run the `aws sso login` command following profile selection. 
 8 
 9-* `acp [<profile>]`: in addition to `asp` functionality, it actually changes the profile by
10-   assuming the role specified in the `<profile>` configuration. It supports MFA and sets
11-   `$AWS_ACCESS_KEY_ID`, `$AWS_SECRET_ACCESS_KEY` and `$AWS_SESSION_TOKEN`, if obtained. It
12-   requires the roles to be configured as per the
13+* `acp [<profile>] [<mfa_token>]`: in addition to `asp` functionality, it actually changes
14+   the profile by assuming the role specified in the `<profile>` configuration. It supports
15+   MFA and sets `$AWS_ACCESS_KEY_ID`, `$AWS_SECRET_ACCESS_KEY` and `$AWS_SESSION_TOKEN`, if
16+   obtained. It requires the roles to be configured as per the
17    [official guide](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-role.html).
18    Run `acp` without arguments to clear the profile.
19 
20diff --git a/plugins/aws/aws.plugin.zsh b/plugins/aws/aws.plugin.zsh
21index c18bd634b8a516c2bf0a634487644546289d6154..920a7139df70b2a4315ed545aea1aec6e42d5805 100644
22--- a/plugins/aws/aws.plugin.zsh
23+++ b/plugins/aws/aws.plugin.zsh
24@@ -45,6 +45,7 @@ function acp() {
25   fi
26 
27   local profile="$1"
28+  local mfa_token="$2"
29 
30   # Get fallback credentials for if the aws command fails or no command is run
31   local aws_access_key_id="$(aws configure get aws_access_key_id --profile $profile)"
32@@ -58,9 +59,10 @@ function acp() {
33 
34   if [[ -n "$mfa_serial" ]]; then
35     local -a mfa_opt
36-    local mfa_token
37-    echo -n "Please enter your MFA token for $mfa_serial: "
38-    read -r mfa_token
39+    if [[ -z "$mfa_token" ]]; then
40+      echo -n "Please enter your MFA token for $mfa_serial: "
41+      read -r mfa_token
42+    fi
43     if [[ -z "$sess_duration" ]]; then
44       echo -n "Please enter the session duration in seconds (900-43200; default: 3600, which is the default maximum for a role): "
45       read -r sess_duration