mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-09-20 13:30:46 +02:00
* s3api: fail closed when S3 Tables signature verification fails * s3api: avoid nil Account dereference in S3 Tables auth log * iceberg: return auth error instead of falling back to DefaultAllow * lance: return auth error instead of falling back to DefaultAllow * s3api: stop trusting client-supplied s3-account-id The header is set by the server after successful authentication; scrub inbound values alongside the other internal headers, and apply the same admin guard to the header fallback branch of getAccountID that the identity branch already has. * test: cover table-catalog auth wrappers and principal resolution * test: configure anonymous identity where catalog clients do not sign * s3api: scrub s3-account-id after signature verification
34 lines
1.1 KiB
Go
34 lines
1.1 KiB
Go
package s3tables
|
|
|
|
import (
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"testing"
|
|
|
|
"github.com/seaweedfs/seaweedfs/weed/s3api/s3_constants"
|
|
"github.com/stretchr/testify/assert"
|
|
)
|
|
|
|
func TestGetAccountIDRejectsHeaderAdmin(t *testing.T) {
|
|
h := NewS3TablesHandler()
|
|
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
|
req.Header.Set(s3_constants.AmzAccountId, s3_constants.AccountAdminId)
|
|
|
|
assert.NotEqual(t, s3_constants.AccountAdminId, h.getAccountID(req),
|
|
"a client-supplied account header must not resolve to the admin principal")
|
|
}
|
|
|
|
func TestGetAccountIDHeaderBranchResolvesCaller(t *testing.T) {
|
|
h := NewS3TablesHandler()
|
|
req := httptest.NewRequest(http.MethodGet, "/", nil)
|
|
req.Header.Set(s3_constants.AmzAccountId, "alice")
|
|
|
|
assert.Equal(t, "alice", h.getAccountID(req))
|
|
}
|
|
|
|
func TestCheckPermissionDenyPolicyBindsNonAdmin(t *testing.T) {
|
|
denyAll := `{"Statement":[{"Effect":"Deny","Principal":"*","Action":"s3tables:DeleteTableBucket"}]}`
|
|
assert.False(t, CheckPermissionWithContext("s3tables:DeleteTableBucket", "mallory", "owner123", denyAll, "arn:aws:s3tables:us-east-1:000000000000:bucket/victim",
|
|
&PolicyContext{DefaultAllow: true}))
|
|
}
|