Files
versitygw/auth/principal_resolver.go
T
niksis02 c84c5f645a feat: accept principal ARNs in bucket policies under standalone IAM
Bucket policy `Principal` named callers by access key id. Under the standalone IAM service it now names them by AWS-style ARN, as real S3 does: a user ARN, a role ARN (covering every session of that role), an assumed-role ARN (covering one session), the account root ARN or bare account id, or `*`. Every other IAM backend has no ARNs to name anything by and keeps access-key principals unchanged, gated on a new `auth.PrincipalResolver` capability interface that only the standalone client implements.

`auth.Account` carries `Arn` and `RoleArn`, filled at authentication time, so a session can be matched against both its own ARN and its role's. Principals are validated at PutBucketPolicy time through a new `/private/resolve-principals` endpoint, which rejects anything that does not name a live identity with `MalformedPolicy: Invalid principal in policy`.

An `Allow` naming the account root ARN or bare account id delegates to the account's own IAM rather than granting on its own, while a `Deny` naming it denies every principal in the account outright. Denial messages now name the caller by ARN wherever one exists.

Also fixes `aws:PrincipalArn` for assumed-role sessions, which reported the session ARN where AWS reports the role's, and stops an unreachable IAM service being reported as a malformed policy.
2026-09-03 23:51:55 +04:00

33 lines
1.5 KiB
Go

// Copyright 2026 Versity Software
// This file is licensed under the Apache License, Version 2.0
// (the "License"); you may not use this file except in compliance
// with the License. You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.
package auth
// PrincipalResolver is implemented by IAM backends whose identities are
// named by AWS-style principal ARNs — currently only the standalone IAM
// service client. Its presence is what switches a bucket policy's Principal
// element from naming access key ids to naming ARNs, the way real S3 does.
//
// Every other backend (internal, LDAP, Vault, IPA, S3, single) has no ARNs
// to name anything by: its accounts are access keys and nothing else. Those
// backends do not implement this, and their bucket policies keep naming
// access key ids exactly as before.
type PrincipalResolver interface {
// ResolvePrincipals returns the subset of principals that do not name
// anything — the write-time check behind PutBucketPolicy, mirroring
// ResolveAccounts' "return what does not exist" contract for access
// keys. The wildcard "*" is handled by the caller and never reaches
// here.
ResolvePrincipals(principals []string) ([]string, error)
}