修改设备鉴权模板
功能介绍
应用服务器可调用此接口在物联网平台上修改指定设备鉴权模板。
调用方法
请参见如何调用API。
URI
PUT /v5/iot/{project_id}/device-authentication-templates/{template_id}
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
project_id |
是 |
String |
参数说明:项目ID。获取方法请参见 获取项目ID 。 |
template_id |
是 |
String |
鉴权模板ID |
请求参数
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
X-Auth-Token |
否 |
String |
参数说明:用户Token。通过调用IAM服务 获取IAM用户Token接口获取,接口返回的响应消息头中“X-Subject-Token”就是需要获取的用户Token。简要的获取方法样例请参见 Token认证。 |
Instance-Id |
否 |
String |
参数说明:实例ID。物理多租下各实例的唯一标识,一般华为云租户无需携带该参数,仅在物理多租场景下从管理面访问API时需要携带该参数。您可以在IoTDA管理控制台界面,选择左侧导航栏“总览”页签查看当前实例的ID |
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
description |
否 |
String |
参数说明:鉴权模板的描述信息。 取值范围:长度不超过2048,只允许中文、字母、数字、以及_?'#().,&%@!-等字符的组合 |
status |
否 |
String |
参数说明:是否激活该鉴权模板
|
template_body |
否 |
参数说明:只有模板目标状态为INACTIVE状态下才能修改模板内容,鉴权模板详细内容,json格式。 |
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
parameters |
否 |
Object |
参数说明:鉴权模板参数,目前平台预置了mqtt协议连接参数中的clientId,username与设备证书中的属性,参数名定义如下:
|
resources |
否 |
更新鉴权模板设备资源详情结构体。 |
参数 |
是否必选 |
参数类型 |
描述 |
---|---|---|---|
device_id |
否 |
Object |
设备ID,json对象只能使用FunctionDefinition下的函数从parameters中获取设备ID的取值。 |
timestamp |
否 |
TimestampResource object |
是否校验设备时间戳,若不为空则表示校验,如果设备连接参数(clientId、username)中包含时间戳建议开启校验。开启校验平台会对比设备携带时间戳与平台系统时间,若设备时间戳加一小时小于平台系统时间则校验失败。若想关闭校验则把value属性的值设置为空json:{} |
password |
否 |
Object |
mqtt认证密码,该字段只在设备认证方式为密码认证时生效,证书认证时无效,只能使用FunctionDefinition下的函数从parameters中编程密码的生成方式,平台比较函数解析结果与设备mqtt连接时携带的password是否相等,相等则认证通过。函数中必须包含设备原始密钥参数${iotda::device::secret},且只能在hash函数中使用,若想修改清空该字段则设置为空json:{}。 |
响应参数
状态码:200
参数 |
参数类型 |
描述 |
---|---|---|
template_id |
String |
鉴权模板id |
template_name |
String |
鉴权模板名称 |
create_time |
String |
鉴权模板创建的时间。格式:yyyyMMdd'T'HHmmss'Z',如:20151212T121212Z。 |
update_time |
String |
鉴权模板最后一次修改的时间。格式:yyyyMMdd'T'HHmmss'Z',如:20151212T121212Z。 |
description |
String |
鉴权模板的描述信息 |
status |
String |
参数说明:鉴权模板状态
|
template_body |
AuthenticationTemplateBody object |
参数说明:预调配模板详细内容,json格式。 |
参数 |
参数类型 |
描述 |
---|---|---|
parameters |
Object |
参数说明:鉴权模板参数,目前平台预置了mqtt协议连接参数中的clientId,username与设备证书中的属性,参数名定义如下:
|
resources |
鉴权模板设备资源详情结构体。 |
参数 |
参数类型 |
描述 |
---|---|---|
device_id |
Object |
设备ID,json对象只能使用FunctionDefinition下的函数从parameters中获取设备ID的取值。 |
timestamp |
TimestampResource object |
是否校验设备时间戳,若不为空则表示校验,如果设备连接参数(clientId、username)中包含时间戳建议开启校验。开启校验平台会对比设备携带时间戳与平台系统时间,若设备时间戳加一小时小于平台系统时间则校验失败。若想关闭校验则把value属性的值设置为空json:{} |
password |
Object |
mqtt认证密码,该字段只在设备认证方式为密码认证时生效,证书认证时无效,只能使用FunctionDefinition下的函数从parameters中编程密码的生成方式,平台比较函数解析结果与设备mqtt连接时携带的password是否相等,相等则认证通过。函数中必须包含设备原始密钥参数${iotda::device::secret},且只能在hash函数中使用。 |
请求示例
更新鉴权模板
PUT https://{endpoint}/v5/iot/{project_id}/device-authentication-templates/{template_id} { "description" : "myTemplate", "status" : "ACTIVE", "template_body" : { "parameters" : { "iotda::mqtt::client_id" : { "type" : "String" }, "iotda::mqtt::username" : { "type" : "String" }, "iotda::device::secret" : { "type" : "String" } }, "resources" : { "device_id" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 0 ] }, "timestamp" : { "type" : "UNIX", "value" : { "Fn::MathDiv" : [ { "Fn::ParseLong" : { "Fn::SplitSelect" : [ { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 2 ] }, "=", 1 ] } }, 1000 ] } }, "password" : { "Fn::HmacSHA256" : [ { "Fn::Sub" : [ "clientId${clientId}deviceName${deviceName}productKey${productKey}timestamp${timestamp}", { "clientId" : { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 0 ] }, "deviceName" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 0 ] }, "productKey" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 1 ] }, "timestamp" : { "Fn::SplitSelect" : [ { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 2 ] }, "=", 1 ] } } ] }, "${iotda::device::secret}" ] } } } }
响应示例
状态码:200
OK
{ "template_id" : "5c90fa7d3c4e4405e8525079", "template_name" : "myTemplate", "description" : "myTemplate", "status" : "ACTIVE", "template_body" : { "parameters" : { "iotda::mqtt::client_id" : { "type" : "String" }, "iotda::mqtt::username" : { "type" : "String" }, "iotda::device::secret" : { "type" : "String" } }, "resources" : { "device_id" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 0 ] }, "timestamp" : { "type" : "UNIX", "value" : { "Fn::MathDiv" : [ { "Fn::ParseLong" : { "Fn::SplitSelect" : [ { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 2 ] }, "=", 1 ] } }, 1000 ] } }, "password" : { "Fn::HmacSHA256" : [ { "Fn::Sub" : [ "clientId${clientId}deviceName${deviceName}productKey${productKey}timestamp${timestamp}", { "clientId" : { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 0 ] }, "deviceName" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 0 ] }, "productKey" : { "Fn::SplitSelect" : [ "${iotda::mqtt::username}", "&", 1 ] }, "timestamp" : { "Fn::SplitSelect" : [ { "Fn::SplitSelect" : [ "${iotda::mqtt::client_id}", "|", 2 ] }, "=", 1 ] } } ] }, "${iotda::device::secret}" ] } } }, "create_time" : "20230810T070547Z", "update_time" : "20230810T070547Z" }
SDK代码示例
SDK代码示例如下。
更新鉴权模板
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 |
package com.huaweicloud.sdk.test; import com.huaweicloud.sdk.core.auth.ICredential; import com.huaweicloud.sdk.core.auth.AbstractCredentials; import com.huaweicloud.sdk.core.auth.BasicCredentials; import com.huaweicloud.sdk.core.exception.ConnectionException; import com.huaweicloud.sdk.core.exception.RequestTimeoutException; import com.huaweicloud.sdk.core.exception.ServiceResponseException; import com.huaweicloud.sdk.core.region.Region; import com.huaweicloud.sdk.iotda.v5.*; import com.huaweicloud.sdk.iotda.v5.model.*; public class UpdateDeviceAuthenticationTemplateSolution { public static void main(String[] args) { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment String ak = System.getenv("CLOUD_SDK_AK"); String sk = System.getenv("CLOUD_SDK_SK"); // ENDPOINT:请在控制台的"总览"界面的"平台接入地址"中查看“应用侧”的https接入地址。 String iotdaEndpoint = "<YOUR ENDPOINT>"; String projectId = "{project_id}"; ICredential auth = new BasicCredentials() .withProjectId(projectId) // 标准版/企业版需要使用衍生算法,基础版请删除配置"withDerivedPredicate"; .withDerivedPredicate(AbstractCredentials.DEFAULT_DERIVED_PREDICATE) // Used in derivative ak/sk authentication scenarios .withAk(ak) .withSk(sk); IoTDAClient client = IoTDAClient.newBuilder() .withCredential(auth) // 标准版/企业版:需自行创建Region对象,基础版:请使用IoTDARegion的region对象,如"withRegion(IoTDARegion.CN_NORTH_4)" .withRegion(new Region("cn-north-4", iotdaEndpoint)) .build(); UpdateDeviceAuthenticationTemplateRequest request = new UpdateDeviceAuthenticationTemplateRequest(); request.withTemplateId("{template_id}"); UpdateAuthenticationTemplate body = new UpdateAuthenticationTemplate(); TimestampResource timestampResources = new TimestampResource(); timestampResources.withType("UNIX") .withValue("{\"Fn::MathDiv\":[{\"Fn::ParseLong\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}},1000]}"); UpdateAuthenticationTemplateResource resourcesTemplateBody = new UpdateAuthenticationTemplateResource(); resourcesTemplateBody.withDeviceId("{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]}") .withTimestamp(timestampResources) .withPassword("{\"Fn::HmacSHA256\":[{\"Fn::Sub\":[\"clientId${clientId}deviceName${deviceName}productKey${productKey}timestamp${timestamp}\",{\"clientId\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",0]},\"productKey\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",1]},\"deviceName\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]},\"timestamp\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}}]},\"${iotda::device::secret}\"]}"); UpdateAuthenticationTemplateBody templateBodybody = new UpdateAuthenticationTemplateBody(); templateBodybody.withParameters("{\"iotda::mqtt::client_id\":{\"type\":\"String\"},\"iotda::device::secret\":{\"type\":\"String\"},\"iotda::mqtt::username\":{\"type\":\"String\"}}") .withResources(resourcesTemplateBody); body.withTemplateBody(templateBodybody); body.withStatus("ACTIVE"); body.withDescription("myTemplate"); request.withBody(body); try { UpdateDeviceAuthenticationTemplateResponse response = client.updateDeviceAuthenticationTemplate(request); System.out.println(response.toString()); } catch (ConnectionException e) { e.printStackTrace(); } catch (RequestTimeoutException e) { e.printStackTrace(); } catch (ServiceResponseException e) { e.printStackTrace(); System.out.println(e.getHttpStatusCode()); System.out.println(e.getRequestId()); System.out.println(e.getErrorCode()); System.out.println(e.getErrorMsg()); } } } |
更新鉴权模板
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 |
# coding: utf-8 import os from huaweicloudsdkcore.auth.credentials import BasicCredentials from huaweicloudsdkcore.auth.credentials import DerivedCredentials from huaweicloudsdkcore.region.region import Region as coreRegion from huaweicloudsdkcore.exceptions import exceptions from huaweicloudsdkiotda.v5 import * if __name__ == "__main__": # The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. # In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak = os.environ["CLOUD_SDK_AK"] sk = os.environ["CLOUD_SDK_SK"] # ENDPOINT:请在控制台的"总览"界面的"平台接入地址"中查看“应用侧”的https接入地址,下面创建Client时需要使用自行创建的Region对象,基础版:请选择IoTDAClient中的Region对象 如: IoTDAClient.new_builder().with_region(IoTDARegion.CN_NORTH_4) endpoint = "<YOUR ENDPOINT>"; projectId = "{project_id}" credentials = BasicCredentials(ak, sk, projectId).with_derived_predicate(DerivedCredentials.get_default_derived_predicate()) client = IoTDAClient.new_builder() \ .with_credentials(credentials) \ .with_region(coreRegion(id="cn-north-4", endpoint=endpoint)) \ .build() try: request = UpdateDeviceAuthenticationTemplateRequest() request.template_id = "{template_id}" timestampResources = TimestampResource( type="UNIX", value="{\"Fn::MathDiv\":[{\"Fn::ParseLong\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}},1000]}" ) resourcesTemplateBody = UpdateAuthenticationTemplateResource( device_id="{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]}", timestamp=timestampResources, password="{\"Fn::HmacSHA256\":[{\"Fn::Sub\":[\"clientId${clientId}deviceName${deviceName}productKey${productKey}timestamp${timestamp}\",{\"clientId\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",0]},\"productKey\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",1]},\"deviceName\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]},\"timestamp\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}}]},\"${iotda::device::secret}\"]}" ) templateBodybody = UpdateAuthenticationTemplateBody( parameters="{\"iotda::mqtt::client_id\":{\"type\":\"String\"},\"iotda::device::secret\":{\"type\":\"String\"},\"iotda::mqtt::username\":{\"type\":\"String\"}}", resources=resourcesTemplateBody ) request.body = UpdateAuthenticationTemplate( template_body=templateBodybody, status="ACTIVE", description="myTemplate" ) response = client.update_device_authentication_template(request) print(response) except exceptions.ClientRequestException as e: print(e.status_code) print(e.request_id) print(e.error_code) print(e.error_msg) |
更新鉴权模板
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 |
package main import ( "fmt" "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth/basic" iotda "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/iotda/v5" "github.com/huaweicloud/huaweicloud-sdk-go-v3/services/iotda/v5/model" region "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/region" core_auth "github.com/huaweicloud/huaweicloud-sdk-go-v3/core/auth" ) func main() { // The AK and SK used for authentication are hard-coded or stored in plaintext, which has great security risks. It is recommended that the AK and SK be stored in ciphertext in configuration files or environment variables and decrypted during use to ensure security. // In this example, AK and SK are stored in environment variables for authentication. Before running this example, set environment variables CLOUD_SDK_AK and CLOUD_SDK_SK in the local environment ak := os.Getenv("CLOUD_SDK_AK") sk := os.Getenv("CLOUD_SDK_SK") // endpoint:请在控制台的"总览"界面的"平台接入地址"中查看"应用侧"的https接入地址 endpoint := "<YOUR ENDPOINT>" projectId := "{project_id}" auth := basic.NewCredentialsBuilder(). WithAk(ak). WithSk(sk). WithProjectId(projectId). // 企业版/标准版需要使用衍生算法,基础版请删除该配置"WithDerivedPredicate" WithDerivedPredicate(core_auth.GetDefaultDerivedPredicate()). // Used in derivative ak/sk authentication scenarios Build() client := iotda.NewIoTDAClient( iotda.IoTDAClientBuilder(). // 标准版/企业版需要自行创建region,基础版使用IoTDARegion中的region对象 WithRegion(region.NewRegion("cn-north-4", endpoint)). WithCredential(auth). Build()) request := &model.UpdateDeviceAuthenticationTemplateRequest{} request.TemplateId = "{template_id}" typeTimestamp:= "UNIX" var valueTimestamp interface{} = "{\"Fn::MathDiv\":[{\"Fn::ParseLong\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}},1000]}" timestampResources := &model.TimestampResource{ Type: &typeTimestamp, Value: &valueTimestamp, } var deviceIdResources interface{} = "{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]}" var passwordResources interface{} = "{\"Fn::HmacSHA256\":[{\"Fn::Sub\":[\"clientId${clientId}deviceName${deviceName}productKey${productKey}timestamp${timestamp}\",{\"clientId\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",0]},\"productKey\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",1]},\"deviceName\":{\"Fn::SplitSelect\":[\"${iotda::mqtt::username}\",\"&\",0]},\"timestamp\":{\"Fn::SplitSelect\":[{\"Fn::SplitSelect\":[\"${iotda::mqtt::client_id}\",\"|\",2]},\"=\",1]}}]},\"${iotda::device::secret}\"]}" resourcesTemplateBody := &model.UpdateAuthenticationTemplateResource{ DeviceId: &deviceIdResources, Timestamp: timestampResources, Password: &passwordResources, } var parametersTemplateBody interface{} = "{\"iotda::mqtt::client_id\":{\"type\":\"String\"},\"iotda::device::secret\":{\"type\":\"String\"},\"iotda::mqtt::username\":{\"type\":\"String\"}}" templateBodybody := &model.UpdateAuthenticationTemplateBody{ Parameters: ¶metersTemplateBody, Resources: resourcesTemplateBody, } statusUpdateAuthenticationTemplate:= "ACTIVE" descriptionUpdateAuthenticationTemplate:= "myTemplate" request.Body = &model.UpdateAuthenticationTemplate{ TemplateBody: templateBodybody, Status: &statusUpdateAuthenticationTemplate, Description: &descriptionUpdateAuthenticationTemplate, } response, err := client.UpdateDeviceAuthenticationTemplate(request) if err == nil { fmt.Printf("%+v\n", response) } else { fmt.Println(err) } } |
更多编程语言的SDK代码示例,请参见API Explorer的代码示例页签,可生成自动对应的SDK代码示例。
状态码
状态码 |
描述 |
---|---|
200 |
OK |
400 |
Bad Request |
403 |
Forbidden |
404 |
Not Found |
500 |
Internal Server Error |
错误码
请参见错误码。