mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-07 06:47:51 +02:00
* sts: export CalculateSessionDuration Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * s3: honor configured session bounds on AssumeRole and LDAP identity prepareSTSCredentials hardcoded a one-hour session when the caller omitted DurationSeconds, so sts.tokenDuration was ignored and sts.maxSessionLength only clamped explicit requests: asking for 3600s against a 20m ceiling was rejected while omitting the parameter was granted a full hour (#11473). The two affected handlers now use the same default-then-cap calculation as AssumeRoleWithWebIdentity. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * iam: keep MaxSessionDuration through role store copies copyRoleDefinition rebuilt RoleDefinition field by field and dropped MaxSessionDuration, so memory-backed role stores silently discarded the per-role session bound on every write and read (devin on #11478). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * sts: apply per-role MaxSessionDuration to resolved session durations Review follow-up on #11478 (devin): the role bound only ever applied to explicit DurationSeconds values — an omitted duration resolved to the configured default and sailed past a shorter role max on every assume path. - capDurationByRole now resolves min(requested||tokenDuration, roleMax), so AssumeRoleWithWebIdentity and AssumeRoleWithCredentials cap defaults the same way they cap explicit values. - prepareSTSCredentials caps the calculated duration at the named role's MaxSessionDuration, covering the AssumeRole and LDAP handlers; self-assumption has no role definition to consult. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * iam: keep MaxSessionDuration through the cached role store genericCopyRoleDefinition drops MaxSessionDuration the same way copyRoleDefinition did, so the cached filer role store reads back a zero maximum and every downstream duration cap is skipped (greptile on #11478). Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> * sts: only materialize defaults that pass session duration validation Review follow-up on #11478 (greptile): materializing an omitted DurationSeconds into an explicit value could exceed the service's own input bound (a configured tokenDuration above maxSessionLength) and turn a previously working request into a validation error. capDurationByRole now leaves nil anything the service can resolve better itself, clamps a tightened default at maxSessionLengthSeconds, and floors a role bound below 900s to the tightest issuable value. Generated with [Devin](https://devin.ai) Co-Authored-By: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com> --------- Co-authored-by: Devin <158243242+devin-ai-integration[bot]@users.noreply.github.com>
41 lines
1.5 KiB
Go
41 lines
1.5 KiB
Go
package integration
|
|
|
|
import "testing"
|
|
|
|
func intPtr(v int64) *int64 { return &v }
|
|
|
|
func TestCapDurationByRole(t *testing.T) {
|
|
cases := []struct {
|
|
name string
|
|
requested *int64
|
|
roleMax int64
|
|
defaultSec int64
|
|
serviceMaxSec int64
|
|
want *int64
|
|
}{
|
|
{"no cap, no request -> nil keeps service default", nil, 0, 3600, 43200, nil},
|
|
{"no cap, with request", intPtr(7200), 0, 3600, 43200, intPtr(7200)},
|
|
{"cap below default, no request -> cap", nil, 1800, 3600, 43200, intPtr(1800)},
|
|
{"cap above default, no request -> nil", nil, 43200, 3600, 43200, nil},
|
|
{"request below cap -> request", intPtr(1800), 3600, 900, 43200, intPtr(1800)},
|
|
{"request equal cap -> request", intPtr(3600), 3600, 900, 43200, intPtr(3600)},
|
|
{"request above cap -> cap", intPtr(43200), 3600, 900, 43200, intPtr(3600)},
|
|
{"default above service max -> service cap materialized", nil, 0, 7200, 3600, intPtr(3600)},
|
|
{"role bound above service max -> service cap still applies", nil, 40000, 43200, 3600, intPtr(3600)},
|
|
{"role bound below service floor -> tightest issuable", nil, 500, 3600, 43200, intPtr(900)},
|
|
}
|
|
for _, tc := range cases {
|
|
t.Run(tc.name, func(t *testing.T) {
|
|
got := capDurationByRole(tc.requested, tc.roleMax, tc.defaultSec, tc.serviceMaxSec)
|
|
switch {
|
|
case got == nil && tc.want == nil:
|
|
return
|
|
case got == nil || tc.want == nil:
|
|
t.Fatalf("nilness mismatch: got=%v want=%v", got, tc.want)
|
|
case *got != *tc.want:
|
|
t.Fatalf("got=%d want=%d", *got, *tc.want)
|
|
}
|
|
})
|
|
}
|
|
}
|