mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-11 00:37:52 +02:00
capDurationByRole was substituting the role's MaxSessionDuration when the caller omitted DurationSeconds entirely. AWS returns the configured default (typically 1 hour) in that case, not the role's upper bound — a 12h MaxSessionDuration shouldn't silently make every no-duration assume-role mint a 12h session. Return nil when requested is nil; let the downstream calculateSessionDuration in the STS service apply its TokenDuration default. The role-max upper bound still clamps when the request arrives with a concrete value above the cap. Addresses gemini high-priority review on PR #9318.
35 lines
977 B
Go
35 lines
977 B
Go
package integration
|
|
|
|
import "testing"
|
|
|
|
func intPtr(v int64) *int64 { return &v }
|
|
|
|
func TestCapDurationByRole(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
requested *int64
|
|
roleMax int64
|
|
want *int64
|
|
}{
|
|
{"no cap, no request", nil, 0, nil},
|
|
{"no cap, with request", intPtr(7200), 0, intPtr(7200)},
|
|
{"cap only, no request -> nil so STS default applies", nil, 3600, nil},
|
|
{"request below cap -> request", intPtr(1800), 3600, intPtr(1800)},
|
|
{"request equal cap -> request", intPtr(3600), 3600, intPtr(3600)},
|
|
{"request above cap -> cap", intPtr(43200), 3600, intPtr(3600)},
|
|
}
|
|
for _, tc := range cases {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
got := capDurationByRole(tc.requested, tc.roleMax)
|
|
switch {
|
|
case got == nil && tc.want == nil:
|
|
return
|
|
case got == nil || tc.want == nil:
|
|
t.Fatalf("nilness mismatch: got=%v want=%v", got, tc.want)
|
|
case *got != *tc.want:
|
|
t.Fatalf("got=%d want=%d", *got, *tc.want)
|
|
}
|
|
})
|
|
}
|
|
}
|