mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-12 17:40:43 +02:00
* s3: register account-less identities' synthesized account in the lookup #9962 gave each account-less identity a distinct account id derived from its name (instead of collapsing into admin), but never registered that account in the id->account map. GetAccountNameById then returned empty for such ids, so ACL grantee validation rejected canonical grants to the caller's own account with InvalidRequest, and bucket/object owner display was dropped as 'owner is invalid'. This broke a canned PutObjectAcl by an account-less identity (e.g. TestVersionedObjectAcl with the default 'some_admin_user' identity): ValidateAndTransferGrants -> GetAccountNameById -> 'account id is not exists' -> 400 InvalidRequest. Register the synthesized account at config load so its id resolves to a display name. Add a regression test. * s3: reuse explicitly-configured account for account-less identity Address review: if an account with the same id as an account-less identity's synthesized account is explicitly configured (custom display name/email), reuse it instead of the synthesized one. Add a test.
132 lines
5.0 KiB
Go
132 lines
5.0 KiB
Go
package s3api
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"os"
|
|
"testing"
|
|
|
|
"github.com/aws/aws-sdk-go/service/s3"
|
|
"github.com/seaweedfs/seaweedfs/weed/s3api/s3_constants"
|
|
"github.com/seaweedfs/seaweedfs/weed/s3api/s3err"
|
|
"github.com/stretchr/testify/assert"
|
|
"github.com/stretchr/testify/require"
|
|
)
|
|
|
|
func TestAccountForUnscopedIdentity(t *testing.T) {
|
|
assert.Equal(t, "alice", accountForUnscopedIdentity("alice").Id, "a named identity gets its own account id")
|
|
assert.NotEqual(t, AccountAdmin.Id, accountForUnscopedIdentity("alice").Id, "a named identity must not inherit the admin account")
|
|
assert.Same(t, &AccountAdmin, accountForUnscopedIdentity(AccountAdmin.Id), "the conventional admin keeps the admin account")
|
|
assert.Same(t, &AccountAdmin, accountForUnscopedIdentity(""), "an empty name falls back to the admin account")
|
|
}
|
|
|
|
func TestUnscopedIdentitiesGetDistinctAccounts(t *testing.T) {
|
|
resetMemoryStore()
|
|
|
|
config := `{
|
|
"identities": [
|
|
{"name": "alice", "credentials": [{"accessKey": "alice_ak", "secretKey": "alice_sk"}], "actions": ["Read"]},
|
|
{"name": "admin", "credentials": [{"accessKey": "admin_ak", "secretKey": "admin_sk"}], "actions": ["Admin"]}
|
|
]
|
|
}`
|
|
tmp, err := os.CreateTemp("", "s3-config-*.json")
|
|
require.NoError(t, err)
|
|
defer os.Remove(tmp.Name())
|
|
_, err = tmp.WriteString(config)
|
|
require.NoError(t, err)
|
|
require.NoError(t, tmp.Close())
|
|
|
|
iam := NewIdentityAccessManagementWithStore(&S3ApiServerOption{Config: tmp.Name()}, nil, "memory")
|
|
|
|
alice, _, found := iam.LookupByAccessKey("alice_ak")
|
|
require.True(t, found)
|
|
require.NotNil(t, alice.Account)
|
|
assert.Equal(t, "alice", alice.Account.Id, "a non-admin account-less identity owns resources as itself, not as admin")
|
|
|
|
admin, _, found := iam.LookupByAccessKey("admin_ak")
|
|
require.True(t, found)
|
|
require.NotNil(t, admin.Account)
|
|
assert.Equal(t, AccountAdmin.Id, admin.Account.Id, "the admin identity keeps the admin account")
|
|
}
|
|
|
|
// A distinct non-owner is denied an admin-owned bucket (iam nil => isUserAdmin
|
|
// false, so only real ownership grants access).
|
|
func TestCheckAccessByOwnershipDeniesNonOwner(t *testing.T) {
|
|
adminOwner := AccountAdmin.Id
|
|
s3a := &S3ApiServer{
|
|
bucketRegistry: &BucketRegistry{
|
|
metadataCache: map[string]*BucketMetaData{
|
|
"b": {Name: "b", Owner: &s3.Owner{ID: &adminOwner}},
|
|
},
|
|
notFound: map[string]struct{}{},
|
|
},
|
|
}
|
|
|
|
nonOwner := httptest.NewRequest(http.MethodGet, "/b?ownershipControls=", nil)
|
|
nonOwner.Header.Set(s3_constants.AmzAccountId, "alice")
|
|
assert.Equal(t, s3err.ErrAccessDenied, s3a.checkAccessByOwnership(nonOwner, "b"), "a distinct non-owner is denied the admin-owned bucket")
|
|
|
|
owner := httptest.NewRequest(http.MethodGet, "/b?ownershipControls=", nil)
|
|
owner.Header.Set(s3_constants.AmzAccountId, AccountAdmin.Id)
|
|
assert.Equal(t, s3err.ErrNone, s3a.checkAccessByOwnership(owner, "b"), "the actual owner is still allowed")
|
|
}
|
|
|
|
// An account-less identity's synthesized account must be registered in the
|
|
// account lookup so its id resolves to a display name. Otherwise ACL grantee
|
|
// validation and owner display report the id as "not exists" — the regression
|
|
// where a canned PutObjectAcl granting to the caller's own account returned
|
|
// 400 InvalidRequest.
|
|
func TestUnscopedIdentityAccountResolvesByName(t *testing.T) {
|
|
resetMemoryStore()
|
|
|
|
config := `{
|
|
"identities": [
|
|
{"name": "alice", "credentials": [{"accessKey": "alice_ak", "secretKey": "alice_sk"}], "actions": ["Read", "Write"]}
|
|
]
|
|
}`
|
|
tmp, err := os.CreateTemp("", "s3-config-*.json")
|
|
require.NoError(t, err)
|
|
defer os.Remove(tmp.Name())
|
|
_, err = tmp.WriteString(config)
|
|
require.NoError(t, err)
|
|
require.NoError(t, tmp.Close())
|
|
|
|
iam := NewIdentityAccessManagementWithStore(&S3ApiServerOption{Config: tmp.Name()}, nil, "memory")
|
|
|
|
assert.Equal(t, "alice", iam.GetAccountNameById("alice"),
|
|
"account-less identity id must resolve to a display name for ACL/owner validation")
|
|
}
|
|
|
|
// When an account is explicitly configured with the same id an account-less
|
|
// identity would synthesize, the identity must reuse that configured account so
|
|
// its custom display name/email are preserved.
|
|
func TestUnscopedIdentityReusesConfiguredAccount(t *testing.T) {
|
|
resetMemoryStore()
|
|
|
|
config := `{
|
|
"accounts": [
|
|
{"id": "alice", "displayName": "Alice Smith", "emailAddress": "alice@example.com"}
|
|
],
|
|
"identities": [
|
|
{"name": "alice", "credentials": [{"accessKey": "alice_ak", "secretKey": "alice_sk"}], "actions": ["Read"]}
|
|
]
|
|
}`
|
|
tmp, err := os.CreateTemp("", "s3-config-*.json")
|
|
require.NoError(t, err)
|
|
defer os.Remove(tmp.Name())
|
|
_, err = tmp.WriteString(config)
|
|
require.NoError(t, err)
|
|
require.NoError(t, tmp.Close())
|
|
|
|
iam := NewIdentityAccessManagementWithStore(&S3ApiServerOption{Config: tmp.Name()}, nil, "memory")
|
|
|
|
assert.Equal(t, "Alice Smith", iam.GetAccountNameById("alice"),
|
|
"explicitly configured account display name must be preserved")
|
|
|
|
alice, _, found := iam.LookupByAccessKey("alice_ak")
|
|
require.True(t, found)
|
|
require.NotNil(t, alice.Account)
|
|
assert.Equal(t, "Alice Smith", alice.Account.DisplayName,
|
|
"identity must reuse the configured account, not the synthesized one")
|
|
}
|