package s3api import ( "net/http" "testing" "github.com/seaweedfs/seaweedfs/weed/s3api/s3_constants" ) // TestMapBaseActionToS3Format_ServicePrefixPassthrough verifies that actions // with known service prefixes (s3:, iam:, sts:) are returned unchanged. func TestMapBaseActionToS3Format_ServicePrefixPassthrough(t *testing.T) { tests := []struct { name string input string expect string }{ {"s3 prefix", "s3:GetObject", "s3:GetObject"}, {"iam prefix", "iam:CreateUser", "iam:CreateUser"}, {"sts:AssumeRole", "sts:AssumeRole", "sts:AssumeRole"}, {"sts:GetFederationToken", "sts:GetFederationToken", "sts:GetFederationToken"}, {"sts:GetCallerIdentity", "sts:GetCallerIdentity", "sts:GetCallerIdentity"}, {"coarse Read maps to s3:GetObject", "Read", s3_constants.S3_ACTION_GET_OBJECT}, {"coarse Write maps to s3:PutObject", "Write", s3_constants.S3_ACTION_PUT_OBJECT}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { got := mapBaseActionToS3Format(tt.input) if got != tt.expect { t.Errorf("mapBaseActionToS3Format(%q) = %q, want %q", tt.input, got, tt.expect) } }) } } // TestResolveS3Action_STSActionsPassthrough verifies that STS actions flow // through ResolveS3Action unchanged, both with and without an HTTP request. func TestResolveS3Action_STSActionsPassthrough(t *testing.T) { stsActions := []string{ "sts:AssumeRole", "sts:GetFederationToken", "sts:GetCallerIdentity", } for _, action := range stsActions { t.Run("nil_request_"+action, func(t *testing.T) { got := ResolveS3Action(nil, action, "", "") if got != action { t.Errorf("ResolveS3Action(nil, %q) = %q, want %q", action, got, action) } }) t.Run("with_request_"+action, func(t *testing.T) { r, _ := http.NewRequest(http.MethodPost, "http://localhost/", nil) got := ResolveS3Action(r, action, "", "") if got != action { t.Errorf("ResolveS3Action(r, %q) = %q, want %q", action, got, action) } }) } } func TestResolveS3Action_AttributesBeforeVersionId(t *testing.T) { tests := []struct { name string query string method string baseAction string object string want string }{ { name: "attributes only", query: "attributes", method: http.MethodGet, baseAction: s3_constants.ACTION_READ, object: "key", want: s3_constants.S3_ACTION_GET_OBJECT_ATTRIBUTES, }, { name: "attributes with versionId", query: "attributes&versionId=abc123", method: http.MethodGet, baseAction: s3_constants.ACTION_READ, object: "key", want: s3_constants.S3_ACTION_GET_OBJECT_ATTRIBUTES, }, { name: "versionId only GET", query: "versionId=abc123", method: http.MethodGet, baseAction: s3_constants.ACTION_READ, object: "key", want: s3_constants.S3_ACTION_GET_OBJECT_VERSION, }, { name: "versionId only DELETE", query: "versionId=abc123", method: http.MethodDelete, baseAction: s3_constants.ACTION_WRITE, object: "key", want: s3_constants.S3_ACTION_DELETE_OBJECT_VERSION, }, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { r, _ := http.NewRequest(tt.method, "http://localhost/bucket/"+tt.object+"?"+tt.query, nil) got := ResolveS3Action(r, tt.baseAction, "bucket", tt.object) if got != tt.want { t.Errorf("ResolveS3Action() = %q, want %q", got, tt.want) } }) } } // Bucket subresources registered with ACTION_ADMIN must resolve to their own // S3 actions so a policy granting one of them does not need s3:*, and so no // broader grant sweeps them in. func TestResolveS3Action_AdminBucketSubresources(t *testing.T) { tests := []struct { name string method string query string want string }{ {"get encryption", http.MethodGet, "encryption", s3_constants.S3_ACTION_GET_BUCKET_ENCRYPTION}, {"put encryption", http.MethodPut, "encryption", s3_constants.S3_ACTION_PUT_BUCKET_ENCRYPTION}, {"delete encryption", http.MethodDelete, "encryption", s3_constants.S3_ACTION_PUT_BUCKET_ENCRYPTION}, {"get requestPayment", http.MethodGet, "requestPayment", s3_constants.S3_ACTION_GET_BUCKET_REQUEST_PAYMENT}, {"put requestPayment", http.MethodPut, "requestPayment", s3_constants.S3_ACTION_PUT_BUCKET_REQUEST_PAYMENT}, {"get publicAccessBlock", http.MethodGet, "publicAccessBlock", s3_constants.S3_ACTION_GET_BUCKET_PUBLIC_ACCESS_BLOCK}, {"put publicAccessBlock", http.MethodPut, "publicAccessBlock", s3_constants.S3_ACTION_PUT_BUCKET_PUBLIC_ACCESS_BLOCK}, {"delete publicAccessBlock", http.MethodDelete, "publicAccessBlock", s3_constants.S3_ACTION_PUT_BUCKET_PUBLIC_ACCESS_BLOCK}, {"get ownershipControls", http.MethodGet, "ownershipControls", s3_constants.S3_ACTION_GET_BUCKET_OWNERSHIP_CONTROLS}, {"put ownershipControls", http.MethodPut, "ownershipControls", s3_constants.S3_ACTION_PUT_BUCKET_OWNERSHIP_CONTROLS}, {"delete ownershipControls", http.MethodDelete, "ownershipControls", s3_constants.S3_ACTION_PUT_BUCKET_OWNERSHIP_CONTROLS}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { r, _ := http.NewRequest(tt.method, "http://localhost/bucket?"+tt.query, nil) got := ResolveS3Action(r, s3_constants.ACTION_ADMIN, "bucket", "") if got != tt.want { t.Errorf("ResolveS3Action() = %q, want %q", got, tt.want) } }) } } // CreateBucket is a plain bucket-level PUT registered with ACTION_ADMIN. It // must resolve to s3:CreateBucket so an attached policy granting that action // can authorize it without granting s3:*. func TestResolveS3Action_CreateBucket(t *testing.T) { r, _ := http.NewRequest(http.MethodPut, "http://localhost/new-bucket", nil) if got := ResolveS3Action(r, s3_constants.ACTION_ADMIN, "new-bucket", ""); got != s3_constants.S3_ACTION_CREATE_BUCKET { t.Errorf("ResolveS3Action() = %q, want %q", got, s3_constants.S3_ACTION_CREATE_BUCKET) } } // A base action naming another service carries no S3 request shape, so a query // parameter on the request must not redirect it to an S3 action. func TestResolveS3ActionKeepsNonS3Service(t *testing.T) { tests := []struct { name string method string url string baseAction string }{ {"iam action with batch delete query", http.MethodPost, "http://localhost/?delete", "iam:CreateUser"}, {"iam action with acl query", http.MethodPut, "http://localhost/?acl", "iam:AttachUserPolicy"}, {"iam action with tagging query", http.MethodGet, "http://localhost/?tagging", "iam:ListUsers"}, {"sts action with batch delete query", http.MethodPost, "http://localhost/?delete", "sts:AssumeRole"}, } for _, tt := range tests { t.Run(tt.name, func(t *testing.T) { r, _ := http.NewRequest(tt.method, tt.url, nil) if got := ResolveS3Action(r, tt.baseAction, "", ""); got != tt.baseAction { t.Errorf("ResolveS3Action() = %q, want %q", got, tt.baseAction) } }) } }