{"record":{"id":"f5392bb99f787b71","repo":"hashicorp/terraform","slug":"build-sts-requests-err-s","errorCode":null,"errorMessage":"build sts requests err: %s","messagePattern":"build sts requests err: (.+?)","errorType":"error_code","errorClass":null,"httpStatus":null,"severity":"error","filePath":"internal/backend/remote-state/oss/backend.go","lineNumber":652,"sourceCode":"\treturn providerConfig[ProfileKey], nil\n}\n\nvar securityCredURL = \"http://100.100.100.200/latest/meta-data/ram/security-credentials/\"\n\n// getAuthCredentialByEcsRoleName aims to access meta to get sts credential\n// Actually, the job should be done by sdk, but currently not all resources and products support alibaba-cloud-sdk-go,\n// and their go sdk does support ecs role name.\n// This method is a temporary solution and it should be removed after all go sdk support ecs role name\n// The related PR: https://github.com/terraform-providers/terraform-provider-alicloud/pull/731\nfunc getAuthCredentialByEcsRoleName(ecsRoleName string) (accessKey, secretKey, token string, err error) {\n\n\tif ecsRoleName == \"\" {\n\t\treturn\n\t}\n\trequestUrl := securityCredURL + ecsRoleName\n\thttpRequest, err := http.NewRequest(requests.GET, requestUrl, strings.NewReader(\"\"))\n\tif err != nil {\n\t\terr = fmt.Errorf(\"build sts requests err: %s\", err.Error())\n\t\treturn\n\t}\n\thttpClient := &http.Client{}\n\thttpResponse, err := httpClient.Do(httpRequest)\n\tif err != nil {\n\t\terr = fmt.Errorf(\"get Ecs sts token err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tresponse := responses.NewCommonResponse()\n\terr = responses.Unmarshal(response, httpResponse, \"\")\n\tif err != nil {\n\t\terr = fmt.Errorf(\"unmarshal Ecs sts token response err : %s\", err.Error())\n\t\treturn\n\t}\n\n\tif response.GetHttpStatus() != http.StatusOK {\n\t\terr = fmt.Errorf(\"get Ecs sts token err, httpStatus: %d, message = %s\", response.GetHttpStatus(), response.GetHttpContentString())","sourceCodeStart":634,"sourceCodeEnd":670,"githubUrl":"https://github.com/hashicorp/terraform/blob/d32a084675427f5ac3f7d2868578ef8b2c1dc525/internal/backend/remote-state/oss/backend.go#L634-L670","documentation":"Thrown by getAuthCredentialByEcsRoleName() when http.NewRequest() fails to construct the HTTP GET request to the ECS instance metadata service for STS credentials. The target URL is 'http://100.100.100.200/latest/meta-data/ram/security-credentials/' + ecsRoleName. This is part of the Alibaba Cloud ECS RAM role credential resolution path.","triggerScenarios":"http.NewRequest(requests.GET, requestUrl, strings.NewReader(\"\")) returns an error. This can only fail if the requestUrl is malformed — e.g. containing invalid characters, control characters, or if ecsRoleName contains characters that break URL parsing (spaces, newlines). The securityCredURL base is a valid constant.","commonSituations":"ECS role name containing invalid URL characters (spaces, special symbols). Extremely rare in practice — most RAM role names are alphanumeric with hyphens/underscores. Could indicate a configuration injection issue where the role name comes from an untrusted source.","solutions":["Verify the ecs_role_name backend attribute contains only valid characters (alphanumeric, hyphens, underscores).","URL-encode the role name if it may contain special characters before passing to the backend.","Check that the value isn't accidentally empty or whitespace-only (though empty skips the function entirely)."],"exampleFix":null,"handlingStrategy":"validation","validationCode":"// Validate ECS role name for URL safety before use\nfunc validateECSRoleName(roleName string) error {\n    if roleName == \"\" {\n        return fmt.Errorf(\"ecs_role_name is empty\")\n    }\n    // RAM role names should be alphanumeric with hyphens/underscores\n    validRoleName := regexp.MustCompile(`^[a-zA-Z0-9._-]+$`)\n    if !validRoleName.MatchString(roleName) {\n        return fmt.Errorf(\"ecs_role_name %q contains invalid characters for URL construction\", roleName)\n    }\n    return nil\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Use only alphanumeric characters, hyphens, underscores, and dots in RAM role names.","Validate the ecs_role_name backend attribute before running Terraform.","Avoid spaces or special characters in Alibaba Cloud RAM role names."],"tags":["oss","ecs","metadata-service","url","authentication"],"backgroundTag":null,"analyzedSha":"d32a084675427f5ac3f7d2868578ef8b2c1dc525","analyzedAt":"2026-08-11T18:43:52.779Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}