Get Data Access
s3control_get_data_access | R Documentation |
Returns a temporary access credential from S3 Access Grants to the grantee or client application¶
Description¶
Returns a temporary access credential from S3 Access Grants to the grantee or client application. The temporary credential is an Amazon Web Services STS token that grants them access to the S3 data.
Permissions¶
You must have the s3:GetDataAccess
permission to use this operation.
Additional Permissions¶
The IAM role that S3 Access Grants assumes must have the following
permissions specified in the trust policy when registering the location:
sts:AssumeRole
, for directory users or groups sts:SetContext
, and
for IAM users or roles sts:SetSourceIdentity
.
Usage¶
s3control_get_data_access(AccountId, Target, Permission,
DurationSeconds, Privilege, TargetType)
Arguments¶
AccountId |
[required] The Amazon Web Services account ID of the S3 Access Grants instance. |
Target |
[required] The S3 URI path of the data to which you are requesting temporary access credentials. If the requesting account has an access grant for this data, S3 Access Grants vends temporary access credentials in the response. |
Permission |
[required] The type of permission granted to your S3 data, which can be set to one of the following values:
|
DurationSeconds |
The session duration, in seconds, of the temporary access credential that S3 Access Grants vends to the grantee or client application. The default value is 1 hour, but the grantee can specify a range from 900 seconds (15 minutes) up to 43200 seconds (12 hours). If the grantee requests a value higher than this maximum, the operation fails. |
Privilege |
The scope of the temporary access credential that S3 Access Grants vends to the grantee or client application.
|
TargetType |
The type of |
Value¶
A list with the following syntax:
list(
Credentials = list(
AccessKeyId = "string",
SecretAccessKey = "string",
SessionToken = "string",
Expiration = as.POSIXct(
"2015-01-01"
)
),
MatchedGrantTarget = "string"
)
Request syntax¶
svc$get_data_access(
AccountId = "string",
Target = "string",
Permission = "READ"|"WRITE"|"READWRITE",
DurationSeconds = 123,
Privilege = "Minimal"|"Default",
TargetType = "Object"
)