s3: audit the assumed-role principal and the STS caller (#10519)

* s3: log the requester's principal ARN in the audit entry

An STS session authenticates as an opaque session subject, so requester
alone gave an operator no way back to the assumed role or the session
name. Record the principal ARN next to the identity name and emit it as
requester_arn.

* s3: record the caller identity in the STS handlers

AssumeRole, GetFederationToken and GetCallerIdentity verify the caller
themselves and are not wrapped by the auth middleware that records the
identity, so every audit entry for minting a session had an empty
requester.

* s3: resolve the audit principal ARN the way policy evaluation does

A JWT-authenticated identity carries no PrincipalArn — the auth layer
hands the principal over in a request header — so reading the field
directly left requester_arn empty for OIDC callers. buildPrincipalARN is
the resolver the policy path already uses: header first, then the
identity's own ARN, then a synthesized user ARN for legacy identities
that have none.
This commit is contained in:
Chris Lu authored and GitHub committed 2026-07-31 19:51:03 -07:00
1 parent fa432f9a6a
commit 1ce106e69d
9 files changed
+220 -27

No files matched your search

+6 -6
View File
@@ -705,6 +705,11 @@ func (s3a *S3ApiServer) UnifiedPostHandler(w http.ResponseWriter, r *http.Reques
s3err.WriteErrorResponse(w, r, s3err.ErrServiceUnavailable)
return
}
// AssumeRoleWithWebIdentity/WithLDAPIdentity carry no SigV4 caller, so
// identity may be nil here; the STS handlers record their own caller.
if identity != nil {
r = r.WithContext(recordIdentityInContext(r, identity))
}
s3a.stsHandlers.HandleSTSRequest(w, r)
} else {
// IAM
@@ -716,12 +721,7 @@ func (s3a *S3ApiServer) UnifiedPostHandler(w http.ResponseWriter, r *http.Reques
// Store identity in context
// Always set identity in context when non-nil to ensure downstream handlers have access
ctx := r.Context()
if identity.Name != "" {
ctx = SetIdentityNameInContext(ctx, identity.Name)
}
ctx = SetIdentityInContext(ctx, identity)
r = r.WithContext(ctx)
r = r.WithContext(recordIdentityInContext(r, identity))
targetUserName := r.Form.Get("UserName")