說明
STS Token方式調用可以保護帳號AccessKey資訊,相比AccessKey方式更具有隱私性。
使用限制
只支援使用RAM使用者(子帳號)或RAM角色調用,不支援使用阿里雲帳號(主帳號)調用。
前提條件
已為RAM使用者或RAM角色授予STS的系統管理權限(AliyunSTSAssumeRoleAccess)。具體操作,請參見為RAM使用者授權、為RAM角色授權。
步驟一:擷取STS Token
關於如何擷取STS Token,請參見AssumeRole - 擷取扮演角色的臨時身份憑證。
擷取STS Token程式碼範例
from aliyunsdkcore.client import AcsClient
from aliyunsdkcore.request import CommonRequest
client = AcsClient("建議從環境變數中擷取RAM使用者AccessKey ID", "建議從環境變數中擷取RAM使用者AccessKey Secret", "cn-shanghai")
request = CommonRequest()
request.set_accept_format('json')
request.set_domain('sts.aliyuncs.com')
request.set_method('POST')
request.set_protocol_type('https')
request.set_version('2015-04-01')
request.set_action_name('AssumeRole')
request.add_query_param("RoleArn", "acs:ram::174*************:role/ali**")
request.add_query_param("RoleSessionName", "alink")
response = client.do_action_with_exception(request)
print(str(response, encoding='utf-8'))
正常返回樣本
{
"RequestId": "1*******-1111-5548-1111-6011111111D0",
"AssumedRoleUser":
{
"Arn": "acs:ram::17****************:role/alink/alink",
"AssumedRoleId": "3***************3:alink"
},
"Credentials":
{
"SecurityToken": "CAIS6Q******************wFnzm6aq/om6e49",
"AccessKeyId": "STS.NTu***************hh",
"AccessKeySecret": "FNQXp********************KCaZmpnA8fuyL",
"Expiration": "2022-12-13T04:43:09Z"
}
}
說明
上面返回樣本中Credentials欄位包含了調用Alibaba Content Security ServiceAPI所需的參數,其中Expiration為Token到期失效時間(UTC時間),需要在有效期間內使用。
步驟二:通過STS Token調用Alibaba Content Security ServiceAPI
以下以文本審核1.0版、增強版為例,為您展示通過STS Token調用Alibaba Content Security ServiceAPI的程式碼範例。
文本審核1.0版介面樣本
from aliyunsdkcore.client import AcsClient
from aliyunsdkcore.profile import region_provider
from aliyunsdkcore.auth.credentials import StsTokenCredential// 該方法的入參為STS Token擷取的參數。
from aliyunsdkgreen.request.v20180509 import TextScanRequest
import uuid
import json
sts_token_credential = StsTokenCredential("Credentials_AccessKeyId", "Credentials_AccessKeySecret", "Credentials_SecurityToken")
acs_client = AcsClient(region_id='cn-shanghai', credential=sts_token_credential)
region_provider.modify_point('Green', 'cn-shanghai', 'green.cn-shanghai.aliyuncs.com')
request = TextScanRequest.TextScanRequest()
request.set_accept_format('JSON')
task1 = {"dataId": str(uuid.uuid1()),
"content": "textContentToBeModerated",
}
request.set_content(bytearray(json.dumps({"tasks": [task1], "scenes": ["antispam"]}), "utf-8"))
response = acs_client.do_action_with_exception(request)
print(response)
result = json.loads(response)
if 200 == result["code"]:
taskResults = result["data"]
for taskResult in taskResults:
if (200 == taskResult["code"]):
sceneResults = taskResult["results"]
for sceneResult in sceneResults:
scene = sceneResult["scene"]
suggestion = sceneResult["suggestion"]
文本審核增強版介面樣本
from aliyunsdkcore.client import AcsClient
from aliyunsdkcore.auth.credentials import StsTokenCredential
from aliyunsdkcore.request import CommonRequest
sts_token_credential = StsTokenCredential("Credentials_AccessKeyId", "Credentials_AccessKeySecret", "Credentials_SecurityToken")
client = AcsClient(region_id='cn-shanghai', credential=sts_token_credential)
request = CommonRequest()
request.set_accept_format('json')
request.set_method('POST')
request.set_protocol_type('https')
request.set_domain('green-cip.cn-shanghai.aliyuncs.com')
request.set_version('2022-03-02')
request.set_action_name('TextModeration')
request.add_query_param("Service", "nickname_detection")
request.add_query_param("ServiceParameters", {'content': '測試文本', 'accountId': "user123"})
response = client.do_action_with_exception(request)
print(str(response, encoding='utf-8'))
如何解決報錯:You are not authorized to do this action. You should be authorized by RAM?
未對RAM使用者或RAM角色授予STS的系統管理權限,會顯示該錯誤資訊。造成該問題的原因和解決方案如下: