Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 5 additions & 1 deletion samtranslator/model/eventsources/scheduler.py
Original file line number Diff line number Diff line change
Expand Up @@ -122,7 +122,11 @@ def to_cloudformation(self, **kwargs: dict[str, Any]) -> list[Resource]:
execution_role_arn: Union[str, dict[str, Any]] = self.RoleArn # type: ignore[assignment]
if not execution_role_arn:
execution_role = self._construct_execution_role(
target, target_type, passthrough_resource_attributes, dlq_queue_arn, self.PermissionsBoundary
cast(Resource, kwargs.get("state_machine", target)),
target_type,
passthrough_resource_attributes,
dlq_queue_arn,
self.PermissionsBoundary,
)
resources.append(execution_role)
execution_role_arn = execution_role.get_runtime_attr("arn")
Expand Down
6 changes: 3 additions & 3 deletions samtranslator/model/stepfunctions/events.py
Original file line number Diff line number Diff line change
Expand Up @@ -146,7 +146,7 @@ def to_cloudformation(self, resource, **kwargs): # type: ignore[no-untyped-def]

role: Union[IAMRole, str, dict[str, Any]]
if self.RoleArn is None:
role = self._construct_role(resource, permissions_boundary, prefix=None)
role = self._construct_role(kwargs.get("state_machine", resource), permissions_boundary, prefix=None)
resources.append(role)
else:
role = self.RoleArn
Expand Down Expand Up @@ -263,7 +263,7 @@ def to_cloudformation(self, resource, **kwargs): # type: ignore[no-untyped-def]
resources.append(events_rule)

role = self._construct_role(
resource,
kwargs.get("state_machine", resource),
permissions_boundary,
prefix=None,
)
Expand Down Expand Up @@ -375,7 +375,7 @@ def to_cloudformation(self, resource, **kwargs): # type: ignore[no-untyped-def]
# Convert to lower case so that user can specify either GET or get
self.Method = self.Method.lower()

role = self._construct_role(resource, permissions_boundary, prefix=None)
role = self._construct_role(kwargs.get("state_machine", resource), permissions_boundary, prefix=None)
resources.append(role)

explicit_api = kwargs["explicit_api"]
Expand Down
2 changes: 2 additions & 0 deletions samtranslator/model/stepfunctions/generators.py
Original file line number Diff line number Diff line change
Expand Up @@ -341,6 +341,8 @@ def _generate_event_resources(self) -> list[dict[str, Any]]:
kwargs = {
"intrinsics_resolver": self.intrinsics_resolver,
"permissions_boundary": self.permissions_boundary,
# Step Functions authorizes alias invocations against the underlying state machine.
"state_machine": self.state_machine,
}
try:
eventsource = self.event_resolver.resolve_resource_type(event_dict).from_dict(
Expand Down
10 changes: 10 additions & 0 deletions tests/model/eventsources/test_schedulev2_event_source.py
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
from samtranslator.model.exceptions import InvalidEventException
from samtranslator.model.lambda_ import LambdaFunction
from samtranslator.model.scheduler import SchedulerSchedule
from samtranslator.model.stepfunctions.resources import StepFunctionsStateMachine, StepFunctionsStateMachineAlias


class ScheduleV2EventSourceInSamFunction(TestCase):
Expand Down Expand Up @@ -169,6 +170,15 @@ def test_to_cloudformation_with_dlq_generated_with_intrinsic_function_custom_log


class ScheduleV2EventSourceInSamStateMachine(TestCase):
def test_alias_target_uses_state_machine_permissions(self) -> None:
state_machine = StepFunctionsStateMachine("Machine")
alias = StepFunctionsStateMachineAlias("MachineAliaslive")

resources = self.schedule_event_source.to_cloudformation(resource=alias, state_machine=state_machine)

self.assertEqual(resources[0].Target["Arn"], {"Ref": "MachineAliaslive"})
self.assertEqual(resources[1].Policies[0]["PolicyDocument"]["Statement"][0]["Resource"], {"Ref": "Machine"})

def setUp(self):
self.logical_id = "ScheduleEvent"

Expand Down
4 changes: 4 additions & 0 deletions tests/model/stepfunctions/test_state_machine_generator.py
Original file line number Diff line number Diff line change
Expand Up @@ -164,6 +164,10 @@ def test_state_machine_with_alias_as_event_source_target(self):
state_machine_generator._generate_managed_traffic_shifting_resources()
generated_event_resources = state_machine_generator._generate_event_resources()
self.assertEqual(generated_event_resources[0].Targets[0]["Arn"], {"Ref": "StateMachineIdAliaslive"})
self.assertEqual(
generated_event_resources[1].Policies[0]["PolicyDocument"]["Statement"][0]["Resource"],
{"Ref": "StateMachineId"},
)

def test_state_machine_with_alias_as_event_source_target_requires_alias(self):
self.kwargs["definition_uri"] = "s3://mybucket/myASLfile"
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -133,7 +133,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -193,7 +193,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -254,7 +254,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -312,7 +312,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -133,7 +133,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -193,7 +193,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -254,7 +254,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -312,7 +312,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -70,7 +70,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -133,7 +133,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -193,7 +193,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -254,7 +254,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down Expand Up @@ -312,7 +312,7 @@
"Action": "states:StartExecution",
"Effect": "Allow",
"Resource": {
"Ref": "MyStateMachineAliastest"
"Ref": "MyStateMachine"
}
}
]
Expand Down