Files
seaweedfs/weed
Chris Lu e2b58a0a5b fix(iam): support both AWS standard and legacy IAM role ARN formats
Fix issue #7946 where SeaweedFS only recognized legacy IAM role ARN format
(arn:aws:iam::role/RoleName) but not the standard AWS format with account ID
(arn:aws:iam::ACCOUNT:role/RoleName). This was breaking EKS pod identity
integration which expects the standard format.

Changes:
- Update ExtractRoleNameFromArn() to handle both formats by searching for
  'role/' marker instead of matching a fixed prefix
- Update ExtractRoleNameFromPrincipal() to clearly document both STS and IAM
  formats it supports
- Simplify role ARN validation in validateRoleAssumptionForWebIdentity() and
  validateRoleAssumptionForCredentials() to use the extraction function

The fix maintains backward compatibility with legacy format while adding
support for standard AWS format with account ID.

Fixes: https://github.com/seaweedfs/seaweedfs/issues/7946
2026-01-03 10:13:35 -08:00
..
2025-10-13 18:05:17 -07:00
2025-12-31 13:40:14 -08:00
2024-06-25 09:18:11 -07:00
2024-02-14 08:26:38 -08:00
2026-01-01 19:20:59 -08:00
2026-01-01 20:39:22 -08:00