mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-31 09:18:28 +00:00
fix(admin): percent-decode group name in DELETE /v3/group/{group} (#2358)
Co-authored-by: GatewayJ <8352692332qq.com>
This commit is contained in:
@@ -349,7 +349,7 @@ mod tests {
|
|||||||
fn base64_encoded_checksum_to_hex_string(header_value: &HeaderValue) -> String {
|
fn base64_encoded_checksum_to_hex_string(header_value: &HeaderValue) -> String {
|
||||||
let decoded_checksum = base64::decode(header_value.to_str().unwrap()).unwrap();
|
let decoded_checksum = base64::decode(header_value.to_str().unwrap()).unwrap();
|
||||||
let decoded_checksum = decoded_checksum.into_iter().fold(String::new(), |mut acc, byte| {
|
let decoded_checksum = decoded_checksum.into_iter().fold(String::new(), |mut acc, byte| {
|
||||||
write!(acc, "{byte:02X?}").expect("string will always be writeable");
|
write!(acc, "{byte:02X?}").expect("string will always be writable");
|
||||||
acc
|
acc
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ use crate::{
|
|||||||
use http::{HeaderMap, StatusCode};
|
use http::{HeaderMap, StatusCode};
|
||||||
use hyper::Method;
|
use hyper::Method;
|
||||||
use matchit::Params;
|
use matchit::Params;
|
||||||
|
use percent_encoding::percent_decode_str;
|
||||||
use rustfs_config::MAX_ADMIN_REQUEST_BODY_SIZE;
|
use rustfs_config::MAX_ADMIN_REQUEST_BODY_SIZE;
|
||||||
use rustfs_credentials::get_global_action_cred;
|
use rustfs_credentials::get_global_action_cred;
|
||||||
use rustfs_iam::error::{is_err_no_such_group, is_err_no_such_user};
|
use rustfs_iam::error::{is_err_no_such_group, is_err_no_such_user};
|
||||||
@@ -206,11 +207,17 @@ impl Operation for DeleteGroup {
|
|||||||
)
|
)
|
||||||
.await?;
|
.await?;
|
||||||
|
|
||||||
let group = params
|
let group_raw = params
|
||||||
.get("group")
|
.get("group")
|
||||||
.ok_or_else(|| s3_error!(InvalidArgument, "missing group name in request"))?
|
.ok_or_else(|| s3_error!(InvalidArgument, "missing group name in request"))?
|
||||||
.trim();
|
.trim();
|
||||||
|
|
||||||
|
// Path segments stay percent-encoded in `req.uri.path()` / matchit; IAM uses decoded names (same as GET query).
|
||||||
|
let group_decoded = percent_decode_str(group_raw)
|
||||||
|
.decode_utf8()
|
||||||
|
.map_err(|_| s3_error!(InvalidArgument, "invalid group name encoding"))?;
|
||||||
|
let group = group_decoded.trim();
|
||||||
|
|
||||||
// Validate the group name format
|
// Validate the group name format
|
||||||
if group.is_empty() || group.len() > 256 {
|
if group.is_empty() || group.len() > 256 {
|
||||||
return Err(s3_error!(InvalidArgument, "invalid group name"));
|
return Err(s3_error!(InvalidArgument, "invalid group name"));
|
||||||
|
|||||||
Reference in New Issue
Block a user