fix: always read fresh credentials from disk on every request#294
Open
anasstahr wants to merge 2 commits into
Open
fix: always read fresh credentials from disk on every request#294anasstahr wants to merge 2 commits into
anasstahr wants to merge 2 commits into
Conversation
arnewouters
reviewed
May 27, 2026
| @@ -112,34 +112,20 @@ def create_aws_session(profile: Optional[str] = None) -> boto3.Session: | |||
|
|
|||
|
|
|||
| class SessionHolder: | |||
Contributor
There was a problem hiding this comment.
Does this class still make sense?
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Changes
Remove credential session caching from
SessionHolderso that every request reads fresh credentials from disk. Previously, the proxy cached aboto3.Sessionand only refreshed it reactively after receiving a 401/403 error. Now,SessionHolder.get_session()always creates a new session, ensuring account switches and credential refreshes on disk take effect immediately.mark_needs_refresh()/refresh_if_needed()with a singleget_session()method that always returns a fresh session_handle_error_response(no longer needed)create_transport_with_sigv4— no longer creates an initial session at startupUser experience
Before: If you switched AWS accounts or refreshed credentials on disk while the proxy was running, the proxy continued using the old cached credentials until they expired and triggered a 401/403. This could result in requests being signed with the wrong account's credentials.
After: Every request reads the current credentials from disk. Switching accounts or refreshing credentials takes effect on the very next request — no 401 roundtrip needed.
Checklist
Is this a breaking change? (Y/N)
Please add details about how this change was tested.
Acknowledgment
By submitting this pull request, I confirm that you can use, modify, copy, and redistribute this contribution, under the terms of your choice.