{"record":{"id":"2e9277646f7ade71","repo":"JuliusBrussee/caveman","slug":"awscreds-build-sts-request-w","errorCode":null,"errorMessage":"awscreds: build sts request: %w","messagePattern":"awscreds: build sts request: %w","errorType":"exception","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/awscreds/awscreds.go","lineNumber":332,"sourceCode":"\ttoken := strings.TrimSpace(string(raw))\n\tif token == \"\" {\n\t\treturn nil, errors.New(\"awscreds: web identity token file is empty\")\n\t}\n\tsessionName := p.env(\"AWS_ROLE_SESSION_NAME\")\n\tif sessionName == \"\" {\n\t\tsessionName = fmt.Sprintf(\"caveman-proxy-%d\", p.now().Unix())\n\t}\n\tform := url.Values{\n\t\t\"Action\":           {\"AssumeRoleWithWebIdentity\"},\n\t\t\"Version\":          {\"2011-06-15\"},\n\t\t\"RoleArn\":          {roleARN},\n\t\t\"RoleSessionName\":  {sessionName},\n\t\t\"WebIdentityToken\": {token},\n\t\t\"DurationSeconds\":  {\"3600\"},\n\t}\n\treq, err := http.NewRequestWithContext(ctx, http.MethodPost, p.stsEndpoint, strings.NewReader(form.Encode()))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: build sts request: %w\", err)\n\t}\n\treq.Header.Set(\"Content-Type\", \"application/x-www-form-urlencoded\")\n\treq.Header.Set(\"Accept\", \"application/xml\")\n\tresp, err := p.sts.Do(req)\n\tif err != nil {\n\t\t// A transport error can carry the request URL but never the form body.\n\t\treturn nil, fmt.Errorf(\"awscreds: sts assume role with web identity failed: %w\", err)\n\t}\n\tdefer resp.Body.Close()\n\tbody, err := io.ReadAll(io.LimitReader(resp.Body, maxBody))\n\tif err != nil {\n\t\treturn nil, fmt.Errorf(\"awscreds: read sts response: %w\", err)\n\t}\n\tif resp.StatusCode != http.StatusOK {\n\t\treturn nil, fmt.Errorf(\"awscreds: sts assume role with web identity: http %d%s\", resp.StatusCode, stsErrorCode(body))\n\t}\n\tvar parsed struct {\n\t\tXMLName xml.Name `xml:\"AssumeRoleWithWebIdentityResponse\"`","sourceCodeStart":314,"sourceCodeEnd":350,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/3ee70a102609e550bd2e68004bf5990a9341c851/shared/platform/awscreds/awscreds.go#L314-L350","documentation":"fromWebIdentity builds the AssumeRoleWithWebIdentity POST to the STS endpoint with http.NewRequestWithContext. If request construction itself fails — which practically means the STS endpoint URL is malformed (unparseable scheme/host) or the context is already canceled/invalid — the error is wrapped as \"awscreds: build sts request\".","triggerScenarios":"http.NewRequestWithContext(ctx, http.MethodPost, p.stsEndpoint, ...) returns err: stsEndpoint was set (via options/env override) to an invalid URL like \"sts.amazonaws.com\" without a scheme, or a typo like \"httpss://...\".","commonSituations":"Self-hosted/compatible STS endpoint configured incorrectly (missing https://); config templating leaving a placeholder like {{STS_URL}} in the endpoint; trailing garbage in the URL from a config file.","solutions":["Print/check the configured STS endpoint; it must be a full absolute URL including scheme (default is https://sts.amazonaws.com or the regional equivalent)","Fix the URL: add https:// if missing, remove placeholders/whitespace, correct the scheme typo","If you don't override the endpoint, remove the override so the built-in default URL is used"],"exampleFix":"// before\np := awscreds.New(...) \np.stsEndpoint = \"sts.us-east-1.amazonaws.com\" // no scheme -> NewRequest fails\n// after\np.stsEndpoint = \"https://sts.us-east-1.amazonaws.com\"","handlingStrategy":"validation","validationCode":"u, err := url.Parse(stsEndpoint)\nif err != nil || u.Scheme == \"\" || u.Host == \"\" {\n    return fmt.Errorf(\"invalid STS endpoint %q: must be absolute https URL\", stsEndpoint)\n}","typeGuard":null,"tryCatchPattern":"creds, err := awscreds.Credentials(ctx, p)\nif err != nil && strings.Contains(err.Error(), \"build sts request\") {\n    return fmt.Errorf(\"check stsEndpoint config: %w\", err)\n}","preventionTips":["Always configure the STS endpoint as a full URL with https:// scheme","Render config templates before startup and fail fast on leftover placeholders","Don't override the endpoint unless you truly need a compatible STS; the default is correct","Add a startup self-check that the endpoint URL parses"],"tags":["aws","sts","url","http"],"backgroundTag":"invalid-url-format","analyzedSha":"3ee70a102609e550bd2e68004bf5990a9341c851","analyzedAt":"2026-09-20T15:53:39.229Z","contentChangedAt":"2026-09-20T15:53:39.229Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}