diff --git a/weed/shell/command_s3_config_show.go b/weed/shell/command_s3_config_show.go index 668c883dd..b0b3506ca 100644 --- a/weed/shell/command_s3_config_show.go +++ b/weed/shell/command_s3_config_show.go @@ -48,6 +48,10 @@ func (c *commandS3ConfigShow) Do(args []string, commandEnv *CommandEnv, writer i return err } cfg := resp.Configuration + if cfg == nil { + fmt.Fprintln(writer, "No S3 IAM configuration found.") + return nil + } fmt.Fprintf(writer, "S3 IAM Configuration Summary\n") fmt.Fprintf(writer, "============================\n\n") diff --git a/weed/shell/command_s3_iam_import.go b/weed/shell/command_s3_iam_import.go index 1252557d4..c27d64cc1 100644 --- a/weed/shell/command_s3_iam_import.go +++ b/weed/shell/command_s3_iam_import.go @@ -28,12 +28,12 @@ func (c *commandS3IAMImport) Name() string { func (c *commandS3IAMImport) Help() string { return `import S3 IAM configuration from a JSON file - s3.iam.import -file backup.json + s3.iam.import -file backup.json -force Replaces the entire IAM configuration (users, credentials, policies, service accounts, groups) with the contents of the file. - WARNING: This overwrites the current configuration. + Requires -force to confirm, since this overwrites the current configuration. ` } @@ -44,6 +44,7 @@ func (c *commandS3IAMImport) HasTag(CommandTag) bool { func (c *commandS3IAMImport) Do(args []string, commandEnv *CommandEnv, writer io.Writer) error { f := flag.NewFlagSet(c.Name(), flag.ContinueOnError) file := f.String("file", "", "input JSON file") + force := f.Bool("force", false, "confirm overwrite of the entire IAM configuration") if err := f.Parse(args); err != nil { return err } @@ -51,6 +52,9 @@ func (c *commandS3IAMImport) Do(args []string, commandEnv *CommandEnv, writer io if *file == "" { return fmt.Errorf("-file is required") } + if !*force { + return fmt.Errorf("this overwrites the entire IAM configuration; use -force to confirm") + } data, err := os.ReadFile(*file) if err != nil { diff --git a/weed/shell/command_s3_user_provision.go b/weed/shell/command_s3_user_provision.go index 877c3ff64..9c16719bb 100644 --- a/weed/shell/command_s3_user_provision.go +++ b/weed/shell/command_s3_user_provision.go @@ -6,6 +6,7 @@ import ( "flag" "fmt" "io" + "strings" "time" "github.com/seaweedfs/seaweedfs/weed/iam" @@ -68,6 +69,9 @@ func (c *commandS3UserProvision) Do(args []string, commandEnv *CommandEnv, write if *bucket == "" { return fmt.Errorf("-bucket is required") } + if strings.ContainsAny(*bucket, "*?") { + return fmt.Errorf("-bucket must be a literal bucket name, not a wildcard pattern") + } if *role == "" { return fmt.Errorf("-role is required (readonly, readwrite, admin)") } @@ -119,6 +123,11 @@ func (c *commandS3UserProvision) Do(args []string, commandEnv *CommandEnv, write ctx, cancel := context.WithTimeout(context.Background(), 30*time.Second) defer cancel() + // Step 0: Check if user already exists + if resp, getErr := client.GetUser(ctx, &iam_pb.GetUserRequest{Username: *name}); getErr == nil && resp.Identity != nil { + return fmt.Errorf("user %q already exists", *name) + } + // Step 1: Create policy _, err := client.PutPolicy(ctx, &iam_pb.PutPolicyRequest{ Name: policyName,