mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-29 11:15:34 +00:00
* s3: require dedicated object-lock permissions for x-amz-object-lock-* headers PutObject, CreateMultipartUpload, and PostPolicy honor the retention and legal-hold headers after only the route's s3:PutObject check, so a write-only principal could pin a version under COMPLIANCE retention that nobody can remove before its retain-until date. On AWS these headers require s3:PutObjectRetention / s3:PutObjectLegalHold. validateObjectLockHeaders is the shared funnel for all four call sites; it now authorizes the corresponding dedicated action when each header is present. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3: record the verified POST-policy signer as the request identity The handler authenticated the form policy signature but stored only the signer's name, so downstream authorization (the object-lock header check) re-authenticated the form-signed request as anonymous and evaluated the wrong principal. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
230 lines
9.7 KiB
Go
230 lines
9.7 KiB
Go
package s3api
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/gorilla/mux"
|
|
iamlib "github.com/seaweedfs/seaweedfs/weed/iam"
|
|
"github.com/seaweedfs/seaweedfs/weed/s3api/s3_constants"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestObjectLockRoutesUseDedicatedActions(t *testing.T) {
|
|
bindings := handlerActionBindings(t)
|
|
for _, tc := range []struct{ handler, want string }{
|
|
{"GetObjectRetentionHandler", "ACTION_GET_OBJECT_RETENTION"},
|
|
{"PutObjectRetentionHandler", "ACTION_PUT_OBJECT_RETENTION"},
|
|
{"GetObjectLegalHoldHandler", "ACTION_GET_OBJECT_LEGAL_HOLD"},
|
|
{"PutObjectLegalHoldHandler", "ACTION_PUT_OBJECT_LEGAL_HOLD"},
|
|
{"GetObjectLockConfigurationHandler", "ACTION_GET_BUCKET_OBJECT_LOCK_CONFIG"},
|
|
{"PutObjectLockConfigurationHandler", "ACTION_PUT_BUCKET_OBJECT_LOCK_CONFIG"},
|
|
} {
|
|
if got := bindings[tc.handler]; got != tc.want {
|
|
t.Errorf("%s is gated on %s, want %s", tc.handler, got, tc.want)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestGovernanceBypassUsesDedicatedAuthorization(t *testing.T) {
|
|
for _, tc := range []struct {
|
|
name string
|
|
action Action
|
|
allowed bool
|
|
}{
|
|
{"dedicated permission", Action(s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION + ":test-bucket/*"), true},
|
|
{"coarse write", Action(s3_constants.ACTION_WRITE + ":test-bucket/*"), false},
|
|
{"admin", Action(s3_constants.ACTION_ADMIN), true},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
iam := newTestIAM()
|
|
iam.identities[0].Actions = []Action{tc.action}
|
|
iam.identities[0].Account = &Account{Id: "test-account"}
|
|
s3a := &S3ApiServer{iam: iam}
|
|
req := httptest.NewRequest(http.MethodDelete, "http://localhost:8333/test-bucket/test-object", nil)
|
|
req = mux.SetURLVars(req, map[string]string{"bucket": "test-bucket", "object": "test-object"})
|
|
require.NoError(t, signRawHTTPRequest(context.Background(), req,
|
|
"AKIAIOSFODNN7EXAMPLE", "wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY", "us-east-1"))
|
|
|
|
if got := s3a.checkGovernanceBypassPermission(req, "test-bucket", "/test-object"); got != tc.allowed {
|
|
t.Errorf("checkGovernanceBypassPermission() = %v, want %v", got, tc.allowed)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
// The bypass check authorizes against a synthetic request shaped like the
|
|
// real one; DELETE ?versionId used to re-resolve to s3:DeleteObjectVersion,
|
|
// so the delete-version grant silently satisfied the bypass check.
|
|
func TestGovernanceBypassDoesNotInheritDeleteObjectVersion(t *testing.T) {
|
|
iam := &IdentityAccessManagement{}
|
|
require.NoError(t, iam.PutPolicy("DeleteVersions",
|
|
`{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:DeleteObject","s3:DeleteObjectVersion"],"Resource":"arn:aws:s3:::worm/*"}]}`))
|
|
require.NoError(t, iam.PutPolicy("BypassGovernance",
|
|
`{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:DeleteObject","s3:DeleteObjectVersion","s3:BypassGovernanceRetention"],"Resource":"arn:aws:s3:::worm/*"}]}`))
|
|
s3a := &S3ApiServer{iam: iam}
|
|
|
|
req := httptest.NewRequest(http.MethodDelete, "http://localhost:8333/worm/doc.txt?versionId=abc123", nil)
|
|
req = mux.SetURLVars(req, map[string]string{"bucket": "worm", "object": "doc.txt"})
|
|
|
|
req = req.WithContext(s3_constants.SetIdentityInContext(req.Context(), &Identity{
|
|
Name: "deleter",
|
|
PolicyNames: []string{"DeleteVersions"},
|
|
Account: &Account{Id: "test-account"},
|
|
}))
|
|
if s3a.checkGovernanceBypassPermission(req, "worm", "/doc.txt") {
|
|
t.Fatal("s3:DeleteObjectVersion alone satisfied the governance bypass check")
|
|
}
|
|
|
|
req = req.WithContext(s3_constants.SetIdentityInContext(req.Context(), &Identity{
|
|
Name: "breaker",
|
|
PolicyNames: []string{"BypassGovernance"},
|
|
Account: &Account{Id: "test-account"},
|
|
}))
|
|
if !s3a.checkGovernanceBypassPermission(req, "worm", "/doc.txt") {
|
|
t.Fatal("s3:BypassGovernanceRetention did not satisfy the governance bypass check")
|
|
}
|
|
}
|
|
|
|
// The object-lock request headers on PutObject/CreateMultipartUpload must be
|
|
// authorized as s3:PutObjectRetention / s3:PutObjectLegalHold; s3:PutObject
|
|
// alone used to set retention and legal hold on new versions.
|
|
func TestObjectLockHeadersRequireDedicatedActions(t *testing.T) {
|
|
iam := &IdentityAccessManagement{isAuthEnabled: true}
|
|
require.NoError(t, iam.PutPolicy("Writer",
|
|
`{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:PutObject"],"Resource":"arn:aws:s3:::worm/*"}]}`))
|
|
require.NoError(t, iam.PutPolicy("Locked",
|
|
`{"Version":"2012-10-17","Statement":[{"Effect":"Allow","Action":["s3:PutObject","s3:PutObjectRetention","s3:PutObjectLegalHold"],"Resource":"arn:aws:s3:::worm/*"}]}`))
|
|
s3a := &S3ApiServer{iam: iam}
|
|
|
|
retainUntil := time.Now().Add(24 * time.Hour).Format(time.RFC3339)
|
|
for _, tc := range []struct {
|
|
name string
|
|
policy string
|
|
headers map[string]string
|
|
wantErr error
|
|
}{
|
|
{"writer sets retention", "Writer",
|
|
map[string]string{s3_constants.AmzObjectLockMode: "COMPLIANCE", s3_constants.AmzObjectLockRetainUntilDate: retainUntil},
|
|
ErrObjectLockNotAuthorized},
|
|
{"writer sets legal hold", "Writer",
|
|
map[string]string{s3_constants.AmzObjectLockLegalHold: s3_constants.LegalHoldOn},
|
|
ErrObjectLockNotAuthorized},
|
|
{"writer plain put", "Writer", nil, nil},
|
|
{"locked principal sets both", "Locked",
|
|
map[string]string{s3_constants.AmzObjectLockMode: "GOVERNANCE", s3_constants.AmzObjectLockRetainUntilDate: retainUntil, s3_constants.AmzObjectLockLegalHold: s3_constants.LegalHoldOn},
|
|
nil},
|
|
} {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
req := httptest.NewRequest(http.MethodPut, "http://localhost:8333/worm/doc.txt", nil)
|
|
req = mux.SetURLVars(req, map[string]string{"bucket": "worm", "object": "doc.txt"})
|
|
for k, v := range tc.headers {
|
|
req.Header.Set(k, v)
|
|
}
|
|
req = req.WithContext(s3_constants.SetIdentityInContext(req.Context(), &Identity{
|
|
Name: "caller",
|
|
PolicyNames: []string{tc.policy},
|
|
Account: &Account{Id: "test-account"},
|
|
}))
|
|
if err := s3a.validateObjectLockHeaders(req, "worm", "doc.txt", true); !errors.Is(err, tc.wantErr) {
|
|
t.Errorf("validateObjectLockHeaders() = %v, want %v", err, tc.wantErr)
|
|
}
|
|
})
|
|
}
|
|
}
|
|
|
|
func TestGovernanceBypassUsesBodyObjectKey(t *testing.T) {
|
|
iam := newTestIAM()
|
|
iam.identities[0].Actions = []Action{
|
|
Action(s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION + ":test-bucket/allowed/*"),
|
|
}
|
|
iam.identities[0].Account = &Account{Id: "test-account"}
|
|
s3a := &S3ApiServer{iam: iam}
|
|
|
|
req := httptest.NewRequest(http.MethodPost, "http://localhost:8333/test-bucket?delete", nil)
|
|
req = mux.SetURLVars(req, map[string]string{"bucket": "test-bucket"})
|
|
req = req.WithContext(s3_constants.SetIdentityInContext(req.Context(), iam.identities[0]))
|
|
|
|
if !s3a.checkGovernanceBypassPermission(req, "test-bucket", "allowed/object") {
|
|
t.Fatal("object-scoped bypass grant did not authorize a DeleteObjects body key")
|
|
}
|
|
if s3a.checkGovernanceBypassPermission(req, "test-bucket", "denied/object") {
|
|
t.Fatal("object-scoped bypass grant authorized a key outside its prefix")
|
|
}
|
|
}
|
|
|
|
func TestGovernanceBypassNormalizesBodyObjectKey(t *testing.T) {
|
|
iam := newTestIAM()
|
|
iam.identities[0].Account = &Account{Id: "test-account"}
|
|
s3a := &S3ApiServer{iam: iam}
|
|
|
|
req := httptest.NewRequest(http.MethodPost, "http://localhost:8333/test-bucket?delete", nil)
|
|
req = mux.SetURLVars(req, map[string]string{"bucket": "test-bucket"})
|
|
req = req.WithContext(s3_constants.SetIdentityInContext(req.Context(), iam.identities[0]))
|
|
|
|
iam.identities[0].Actions = []Action{
|
|
Action(s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION + ":test-bucket/allowed/o?ject"),
|
|
}
|
|
if !s3a.checkGovernanceBypassPermission(req, "test-bucket", "//allowed//object") {
|
|
t.Fatal("canonical object grant did not authorize the equivalent noncanonical body key")
|
|
}
|
|
|
|
iam.identities[0].Actions = []Action{
|
|
Action(s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION + ":test-bucket/allowed//o?ject"),
|
|
}
|
|
if s3a.checkGovernanceBypassPermission(req, "test-bucket", "//allowed//object") {
|
|
t.Fatal("noncanonical alias grant authorized the canonical mutation target")
|
|
}
|
|
}
|
|
|
|
func TestCoarseReadWriteDoNotGrantObjectLockActions(t *testing.T) {
|
|
identity := &Identity{
|
|
Name: "object-reader-writer",
|
|
Actions: []Action{
|
|
Action(s3_constants.ACTION_READ + ":test-bucket"),
|
|
Action(s3_constants.ACTION_WRITE + ":test-bucket"),
|
|
},
|
|
}
|
|
|
|
for _, action := range []string{
|
|
s3_constants.ACTION_GET_OBJECT_RETENTION,
|
|
s3_constants.ACTION_PUT_OBJECT_RETENTION,
|
|
s3_constants.ACTION_GET_OBJECT_LEGAL_HOLD,
|
|
s3_constants.ACTION_PUT_OBJECT_LEGAL_HOLD,
|
|
s3_constants.ACTION_GET_BUCKET_OBJECT_LOCK_CONFIG,
|
|
s3_constants.ACTION_PUT_BUCKET_OBJECT_LOCK_CONFIG,
|
|
s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION,
|
|
} {
|
|
if identity.CanDo(Action(action), "test-bucket", "some/key") {
|
|
t.Errorf("coarse Read/Write unexpectedly granted %s", action)
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestObjectLockActionsRoundTrip(t *testing.T) {
|
|
for _, tc := range []struct{ policyAction, identityAction string }{
|
|
{"GetObjectRetention", s3_constants.ACTION_GET_OBJECT_RETENTION},
|
|
{"PutObjectRetention", s3_constants.ACTION_PUT_OBJECT_RETENTION},
|
|
{"GetObjectLegalHold", s3_constants.ACTION_GET_OBJECT_LEGAL_HOLD},
|
|
{"PutObjectLegalHold", s3_constants.ACTION_PUT_OBJECT_LEGAL_HOLD},
|
|
{"GetBucketObjectLockConfiguration", s3_constants.ACTION_GET_BUCKET_OBJECT_LOCK_CONFIG},
|
|
{"PutBucketObjectLockConfiguration", s3_constants.ACTION_PUT_BUCKET_OBJECT_LOCK_CONFIG},
|
|
{"BypassGovernanceRetention", s3_constants.ACTION_BYPASS_GOVERNANCE_RETENTION},
|
|
} {
|
|
t.Run(tc.policyAction, func(t *testing.T) {
|
|
for _, action := range []string{tc.policyAction, "s3:" + tc.policyAction} {
|
|
if got := iamlib.MapToStatementAction(action); got != tc.identityAction {
|
|
t.Errorf("MapToStatementAction(%q) = %q, want %q", action, got, tc.identityAction)
|
|
}
|
|
}
|
|
if got := iamlib.MapToIdentitiesAction(tc.identityAction); got != tc.policyAction {
|
|
t.Errorf("MapToIdentitiesAction(%q) = %q, want %q", tc.identityAction, got, tc.policyAction)
|
|
}
|
|
})
|
|
}
|
|
}
|