mirror of
https://github.com/versity/versitygw.git
synced 2026-09-22 07:54:14 +00:00
Bucket policy `Principal` named callers by access key id. Under the standalone IAM service it now names them by AWS-style ARN, as real S3 does: a user ARN, a role ARN (covering every session of that role), an assumed-role ARN (covering one session), the account root ARN or bare account id, or `*`. Every other IAM backend has no ARNs to name anything by and keeps access-key principals unchanged, gated on a new `auth.PrincipalResolver` capability interface that only the standalone client implements. `auth.Account` carries `Arn` and `RoleArn`, filled at authentication time, so a session can be matched against both its own ARN and its role's. Principals are validated at PutBucketPolicy time through a new `/private/resolve-principals` endpoint, which rejects anything that does not name a live identity with `MalformedPolicy: Invalid principal in policy`. An `Allow` naming the account root ARN or bare account id delegates to the account's own IAM rather than granting on its own, while a `Deny` naming it denies every principal in the account outright. Denial messages now name the caller by ARN wherever one exists. Also fixes `aws:PrincipalArn` for assumed-role sessions, which reported the session ARN where AWS reports the role's, and stops an unreachable IAM service being reported as a malformed policy.
33 lines
1.5 KiB
Go
33 lines
1.5 KiB
Go
// Copyright 2026 Versity Software
|
|
// This file is licensed under the Apache License, Version 2.0
|
|
// (the "License"); you may not use this file except in compliance
|
|
// with the License. You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
package auth
|
|
|
|
// PrincipalResolver is implemented by IAM backends whose identities are
|
|
// named by AWS-style principal ARNs — currently only the standalone IAM
|
|
// service client. Its presence is what switches a bucket policy's Principal
|
|
// element from naming access key ids to naming ARNs, the way real S3 does.
|
|
//
|
|
// Every other backend (internal, LDAP, Vault, IPA, S3, single) has no ARNs
|
|
// to name anything by: its accounts are access keys and nothing else. Those
|
|
// backends do not implement this, and their bucket policies keep naming
|
|
// access key ids exactly as before.
|
|
type PrincipalResolver interface {
|
|
// ResolvePrincipals returns the subset of principals that do not name
|
|
// anything — the write-time check behind PutBucketPolicy, mirroring
|
|
// ResolveAccounts' "return what does not exist" contract for access
|
|
// keys. The wildcard "*" is handled by the caller and never reaches
|
|
// here.
|
|
ResolvePrincipals(principals []string) ([]string, error)
|
|
}
|