fix(admin): replicate user secret-key rotation to peer sites (#6893)

This commit is contained in:
唐小鸭
2026-08-30 23:32:07 +08:00
committed by GitHub
parent fcc3c7fb6b
commit 9ee7b1221d
3 changed files with 141 additions and 6 deletions
+12 -2
View File
@@ -1537,7 +1537,7 @@ where
Ok(deleted_at)
}
pub async fn update_user_secret_key(&self, access_key: &str, secret_key: &str) -> Result<()> {
pub async fn update_user_secret_key(&self, access_key: &str, secret_key: &str) -> Result<(OffsetDateTime, AccountStatus)> {
if access_key.is_empty() || secret_key.is_empty() {
return Err(Error::InvalidArgument);
}
@@ -1552,7 +1552,16 @@ where
let mut cred = u.credentials.clone();
cred.secret_key = secret_key.to_string();
// Status is captured from the same credential snapshot the new secret
// is persisted with, so a caller replicating the rotation broadcasts
// exactly what was written rather than re-reading racily.
let status = if cred.is_valid() {
AccountStatus::Enabled
} else {
AccountStatus::Disabled
};
let u = UserIdentity::from(cred);
let updated_at = u.update_at.unwrap_or_else(OffsetDateTime::now_utc);
drop(cache);
drop(users);
@@ -1560,7 +1569,8 @@ where
.save_user_identity(access_key, UserType::Reg, u.clone(), None)
.await?;
self.update_user_with_claims(access_key, u)
self.update_user_with_claims(access_key, u)?;
Ok((updated_at, status))
}
/// Add SSH public key for a user (for SFTP authentication)
+8 -2
View File
@@ -960,7 +960,11 @@ impl<T: Store> IamSys<T> {
Ok(updated_at)
}
pub async fn set_user_secret_key(&self, access_key: &str, secret_key: &str) -> Result<()> {
pub async fn set_user_secret_key(
&self,
access_key: &str,
secret_key: &str,
) -> Result<(OffsetDateTime, rustfs_madmin::AccountStatus)> {
if !is_access_key_valid(access_key) {
return Err(IamError::InvalidAccessKeyLength);
}
@@ -969,7 +973,9 @@ impl<T: Store> IamSys<T> {
return Err(IamError::InvalidSecretKeyLength);
}
self.store.update_user_secret_key(access_key, secret_key).await
let (updated_at, status) = self.store.update_user_secret_key(access_key, secret_key).await?;
self.notify_for_user(access_key, false).await;
Ok((updated_at, status))
}
/// Add SSH public key for a user (for SFTP authentication)