AWS singlesignon: Correct STS AssumeRole API documentation link
Summary
Fixed URL reference to AWS STS AssumeRole API documentation.
Security assessment
The change only repairs a broken hyperlink without modifying security-related content or addressing vulnerabilities.
Evidence
-AWS applications obtain identity-enhanced role sessions by making requests to the AWS STS [AssumeRole](https://docs.aws.amazon.com//STS/latest/APIReference/API_AssumeRole.html) API action and passing a context assertion with the user’s identifier (`userId`) in the `ProvidedContexts` parameter of the request to `AssumeRole`. The context assertion is obtained from the `idToken` claim received in response to a request to `SSO OIDC` to [`CreateTokenWithIAM`](https://docs.aws.amazon.com/singlesignon/latest/OIDCAPIReference/API_CreateTokenWithIAM.html). When an AWS application uses an identity-enhanced role session to access a resource, CloudTrail logs the `userId`, the initiating session, and the action taken. For more information, see Identity-enhanced IAM role session logging.
Diff
diff --git a/singlesignon/latest/userguide/trustedidentitypropagation-identity-enhanced-iam-role-sessions.md b/singlesignon/latest/userguide/trustedidentitypropagation-identity-enhanced-iam-role-sessions.md index e94db7bef..4e56f0387 100644 --- a//singlesignon/latest/userguide/trustedidentitypropagation-identity-enhanced-iam-role-sessions.md +++ b//singlesignon/latest/userguide/trustedidentitypropagation-identity-enhanced-iam-role-sessions.md @@ -13 +13 @@ The [AWS Security Token Service](https://docs.aws.amazon.com/IAM/latest/UserGuid -AWS applications obtain identity-enhanced role sessions by making requests to the AWS STS [AssumeRole](https://docs.aws.amazon.com//STS/latest/APIReference/API_AssumeRole.html) API action and passing a context assertion with the user’s identifier (`userId`) in the `ProvidedContexts` parameter of the request to `AssumeRole`. The context assertion is obtained from the `idToken` claim received in response to a request to `SSO OIDC` to [`CreateTokenWithIAM`](https://docs.aws.amazon.com/singlesignon/latest/OIDCAPIReference/API_CreateTokenWithIAM.html). When an AWS application uses an identity-enhanced role session to access a resource, CloudTrail logs the `userId`, the initiating session, and the action taken. For more information, see Identity-enhanced IAM role session logging. +AWS applications obtain identity-enhanced role sessions by making requests to the AWS STS [AssumeRole](https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html) API action and passing a context assertion with the user’s identifier (`userId`) in the `ProvidedContexts` parameter of the request to `AssumeRole`. The context assertion is obtained from the `idToken` claim received in response to a request to `SSO OIDC` to [`CreateTokenWithIAM`](https://docs.aws.amazon.com/singlesignon/latest/OIDCAPIReference/API_CreateTokenWithIAM.html). When an AWS application uses an identity-enhanced role session to access a resource, CloudTrail logs the `userId`, the initiating session, and the action taken. For more information, see Identity-enhanced IAM role session logging.