%% WARNING: DO NOT EDIT, AUTO-GENERATED CODE!
%% See https://github.com/aws-beam/aws-codegen for more details.
%% @doc SupportedLoginProviders are as follows:
%%
%%
graph.facebook.com
%%
%% accounts.google.com
%%
%% www.amazon.com
%%
%% api.twitter.com
%%
%% www.digits.com
%%
%% IdentityId and an
%% OpenID Connect token for a user authenticated by your backend
%% authentication process. Supplying multiple logins will create an implicit
%% linked account. You can only specify one developer provider as part of the
%% Logins map, which is linked to the identity pool. The
%% developer provider is the "domain" by which Cognito will refer to your
%% users.
%%
%% You can use GetOpenIdTokenForDeveloperIdentity to create a
%% new identity and to link new logins (that is, user credentials issued by a
%% public provider or developer provider) to an existing identity. When you
%% want to create a new identity, the IdentityId should be null.
%% When you want to associate a new login with an existing
%% authenticated/unauthenticated identity, you can do so by providing the
%% existing IdentityId. This API will create the identity in the
%% specified IdentityPoolId.
%%
%% You must use AWS Developer credentials to call this API.
get_open_id_token_for_developer_identity(Client, Input)
when is_map(Client), is_map(Input) ->
get_open_id_token_for_developer_identity(Client, Input, []).
get_open_id_token_for_developer_identity(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"GetOpenIdTokenForDeveloperIdentity">>, Input, Options).
%% @doc Lists the identities in an identity pool.
%%
%% You must use AWS Developer credentials to call this API.
list_identities(Client, Input)
when is_map(Client), is_map(Input) ->
list_identities(Client, Input, []).
list_identities(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ListIdentities">>, Input, Options).
%% @doc Lists all of the Cognito identity pools registered for your account.
%%
%% You must use AWS Developer credentials to call this API.
list_identity_pools(Client, Input)
when is_map(Client), is_map(Input) ->
list_identity_pools(Client, Input, []).
list_identity_pools(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ListIdentityPools">>, Input, Options).
%% @doc Lists the tags that are assigned to an Amazon Cognito identity pool.
%%
%% A tag is a label that you can apply to identity pools to categorize and
%% manage them in different ways, such as by purpose, owner, environment, or
%% other criteria.
%%
%% You can use this action up to 10 times per second, per account.
list_tags_for_resource(Client, Input)
when is_map(Client), is_map(Input) ->
list_tags_for_resource(Client, Input, []).
list_tags_for_resource(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"ListTagsForResource">>, Input, Options).
%% @doc Retrieves the IdentityID associated with a
%% DeveloperUserIdentifier or the list of
%% DeveloperUserIdentifier values associated with an
%% IdentityId for an existing identity. Either
%% IdentityID or DeveloperUserIdentifier must not
%% be null. If you supply only one of these values, the other value will be
%% searched in the database and returned as a part of the response. If you
%% supply both, DeveloperUserIdentifier will be matched against
%% IdentityID. If the values are verified against the database,
%% the response returns both values and is the same as the request. Otherwise
%% a ResourceConflictException is thrown.
%%
%% LookupDeveloperIdentity is intended for low-throughput
%% control plane operations: for example, to enable customer service to
%% locate an identity ID by username. If you are using it for higher-volume
%% operations such as user authentication, your requests are likely to be
%% throttled. GetOpenIdTokenForDeveloperIdentity is a better option
%% for higher-volume operations for user authentication.
%%
%% You must use AWS Developer credentials to call this API.
lookup_developer_identity(Client, Input)
when is_map(Client), is_map(Input) ->
lookup_developer_identity(Client, Input, []).
lookup_developer_identity(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"LookupDeveloperIdentity">>, Input, Options).
%% @doc Merges two users having different IdentityIds, existing
%% in the same identity pool, and identified by the same developer provider.
%% You can use this action to request that discrete users be merged and
%% identified as a single user in the Cognito environment. Cognito associates
%% the given source user (SourceUserIdentifier) with the
%% IdentityId of the DestinationUserIdentifier.
%% Only developer-authenticated users can be merged. If the users to be
%% merged are associated with the same public provider, but as two different
%% users, an exception will be thrown.
%%
%% The number of linked logins is limited to 20. So, the number of linked
%% logins for the source user, SourceUserIdentifier, and the
%% destination user, DestinationUserIdentifier, together should
%% not be larger than 20. Otherwise, an exception will be thrown.
%%
%% You must use AWS Developer credentials to call this API.
merge_developer_identities(Client, Input)
when is_map(Client), is_map(Input) ->
merge_developer_identities(Client, Input, []).
merge_developer_identities(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"MergeDeveloperIdentities">>, Input, Options).
%% @doc Sets the roles for an identity pool. These roles are used when making
%% calls to GetCredentialsForIdentity action.
%%
%% You must use AWS Developer credentials to call this API.
set_identity_pool_roles(Client, Input)
when is_map(Client), is_map(Input) ->
set_identity_pool_roles(Client, Input, []).
set_identity_pool_roles(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"SetIdentityPoolRoles">>, Input, Options).
%% @doc Assigns a set of tags to an Amazon Cognito identity pool. A tag is a
%% label that you can use to categorize and manage identity pools in
%% different ways, such as by purpose, owner, environment, or other criteria.
%%
%% Each tag consists of a key and value, both of which you define. A key is a
%% general category for more specific values. For example, if you have two
%% versions of an identity pool, one for testing and another for production,
%% you might assign an Environment tag key to both identity
%% pools. The value of this key might be Test for one identity
%% pool and Production for the other.
%%
%% Tags are useful for cost tracking and access control. You can activate
%% your tags so that they appear on the Billing and Cost Management console,
%% where you can track the costs associated with your identity pools. In an
%% IAM policy, you can constrain permissions for identity pools based on
%% specific tags or tag values.
%%
%% You can use this action up to 5 times per second, per account. An identity
%% pool can have as many as 50 tags.
tag_resource(Client, Input)
when is_map(Client), is_map(Input) ->
tag_resource(Client, Input, []).
tag_resource(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"TagResource">>, Input, Options).
%% @doc Unlinks a DeveloperUserIdentifier from an existing
%% identity. Unlinked developer users will be considered new identities next
%% time they are seen. If, for a given Cognito identity, you remove all
%% federated identities as well as the developer user identifier, the Cognito
%% identity becomes inaccessible.
%%
%% You must use AWS Developer credentials to call this API.
unlink_developer_identity(Client, Input)
when is_map(Client), is_map(Input) ->
unlink_developer_identity(Client, Input, []).
unlink_developer_identity(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UnlinkDeveloperIdentity">>, Input, Options).
%% @doc Unlinks a federated identity from an existing account. Unlinked
%% logins will be considered new identities next time they are seen. Removing
%% the last linked login will make this identity inaccessible.
%%
%% This is a public API. You do not need any credentials to call this API.
unlink_identity(Client, Input)
when is_map(Client), is_map(Input) ->
unlink_identity(Client, Input, []).
unlink_identity(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UnlinkIdentity">>, Input, Options).
%% @doc Removes the specified tags from an Amazon Cognito identity pool. You
%% can use this action up to 5 times per second, per account
untag_resource(Client, Input)
when is_map(Client), is_map(Input) ->
untag_resource(Client, Input, []).
untag_resource(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UntagResource">>, Input, Options).
%% @doc Updates an identity pool.
%%
%% You must use AWS Developer credentials to call this API.
update_identity_pool(Client, Input)
when is_map(Client), is_map(Input) ->
update_identity_pool(Client, Input, []).
update_identity_pool(Client, Input, Options)
when is_map(Client), is_map(Input), is_list(Options) ->
request(Client, <<"UpdateIdentityPool">>, Input, Options).
%%====================================================================
%% Internal functions
%%====================================================================
-spec request(aws_client:aws_client(), binary(), map(), list()) ->
{ok, Result, {integer(), list(), hackney:client()}} |
{error, Error, {integer(), list(), hackney:client()}} |
{error, term()} when
Result :: map() | undefined,
Error :: {binary(), binary()}.
request(Client, Action, Input, Options) ->
Client1 = Client#{service => <<"cognito-identity">>},
Host = get_host(<<"cognito-identity">>, Client1),
URL = get_url(Host, Client1),
Headers = [
{<<"Host">>, Host},
{<<"Content-Type">>, <<"application/x-amz-json-1.1">>},
{<<"X-Amz-Target">>, << <<"AWSCognitoIdentityService.">>/binary, Action/binary>>}
],
Payload = jsx:encode(Input),
SignedHeaders = aws_request:sign_request(Client1, <<"POST">>, URL, Headers, Payload),
Response = hackney:request(post, URL, SignedHeaders, Payload, Options),
handle_response(Response).
handle_response({ok, 200, ResponseHeaders, Client}) ->
case hackney:body(Client) of
{ok, <<>>} ->
{ok, undefined, {200, ResponseHeaders, Client}};
{ok, Body} ->
Result = jsx:decode(Body, [return_maps]),
{ok, Result, {200, ResponseHeaders, Client}}
end;
handle_response({ok, StatusCode, ResponseHeaders, Client}) ->
{ok, Body} = hackney:body(Client),
Error = jsx:decode(Body, [return_maps]),
Exception = maps:get(<<"__type">>, Error, undefined),
Reason = maps:get(<<"message">>, Error, undefined),
{error, {Exception, Reason}, {StatusCode, ResponseHeaders, Client}};
handle_response({error, Reason}) ->
{error, Reason}.
get_host(_EndpointPrefix, #{region := <<"local">>}) ->
<<"localhost">>;
get_host(EndpointPrefix, #{region := Region, endpoint := Endpoint}) ->
aws_util:binary_join([EndpointPrefix, <<".">>, Region, <<".">>, Endpoint], <<"">>).
get_url(Host, Client) ->
Proto = maps:get(proto, Client),
Port = maps:get(port, Client),
aws_util:binary_join([Proto, <<"://">>, Host, <<":">>, Port, <<"/">>], <<"">>).