diff --git a/docker/Dockerfile.local b/docker/Dockerfile.local index 9ea378401..2c43f9331 100644 --- a/docker/Dockerfile.local +++ b/docker/Dockerfile.local @@ -4,6 +4,7 @@ COPY ./weed /usr/bin/weed RUN chmod +x /usr/bin/weed && ls -la /usr/bin/weed RUN mkdir -p /etc/seaweedfs COPY ./filer.toml /etc/seaweedfs/filer.toml +COPY ./security.toml /etc/seaweedfs/security.toml COPY ./entrypoint.sh /entrypoint.sh # Install dependencies and create non-root user diff --git a/docker/security.toml b/docker/security.toml new file mode 100644 index 000000000..4581e8824 --- /dev/null +++ b/docker/security.toml @@ -0,0 +1,34 @@ +# Put this file to one of the location, with descending priority +# ./security.toml +# $HOME/.seaweedfs/security.toml +# /etc/seaweedfs/security.toml +# this file is read by master, volume server, filer, and worker + +# comma separated origins allowed to make requests to the filer and s3 gateway. +# enter in this format: https://domain.com, or http://localhost:port +[cors.allowed_origins] +values = "*" + +# this jwt signing key is read by master and volume server, and it is used for write operations: +# - the Master server generates the JWT, which can be used to write a certain file on a volume server +# - the Volume server validates the JWT on writing +# the jwt defaults to expire after 10 seconds. +[jwt.signing] +key = "T3A0RDNWNU1HaA==" +# this jwt signing key is read by master and volume server, and it is used for read operations: +# - the Master server generates the JWT, which can be used to read a certain file on a volume server +# - the Volume server validates the JWT on reading +[jwt.signing.read] +key = "bWVvQm5wdFRRdg==" +# If this JWT key is configured, Filer only accepts writes over HTTP if they are signed with this JWT: +# - f.e. the S3 API Shim generates the JWT +# - the Filer server validates the JWT on writing +# the jwt defaults to expire after 10 seconds. +[jwt.filer_signing] +key = "UmF3WGxYV0JYSw==" +# If this JWT key is configured, Filer only accepts reads over HTTP if they are signed with this JWT: +# - f.e. the S3 API Shim generates the JWT +# - the Filer server validates the JWT on writing +# the jwt defaults to expire after 10 seconds. +[jwt.filer_signing.read] +key = "T1pPekFzNWV4OQ==" diff --git a/weed/admin/handlers/file_browser_handlers.go b/weed/admin/handlers/file_browser_handlers.go index 9b3182a02..70585b429 100644 --- a/weed/admin/handlers/file_browser_handlers.go +++ b/weed/admin/handlers/file_browser_handlers.go @@ -628,9 +628,9 @@ func (h *FileBrowserHandlers) DownloadFile(c *gin.Context) { var jwtToken security.EncodedJwt if len(signingKey) > 0 { jwtToken = security.GenJwtForFilerServer(signingKey, expiresAfterSec) - glog.V(4).Infof("Generated JWT token for filer upload (expires in %d sec)", expiresAfterSec) + glog.V(4).Infof("Generated JWT token for filer download (expires in %d sec)", expiresAfterSec) } else { - glog.V(2).Info("No JWT signing key configured, uploading without authentication") + glog.V(2).Info("No JWT signing key configured, downloadading without authentication") } // Add JWT Token to Authorization Header