mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-26 16:28:15 +00:00
feat(s3): enforce RestrictPublicBuckets for anonymous access (#2033)
Signed-off-by: 安正超 <anzhengchao@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -460,7 +460,7 @@ pub async fn authorize_request<T>(req: &mut S3Request<T>, action: Action) -> S3R
|
||||
}
|
||||
|
||||
if action != Action::S3Action(S3Action::ListAllMyBucketsAction) {
|
||||
if PolicySys::is_allowed(&BucketPolicyArgs {
|
||||
let policy_allowed = PolicySys::is_allowed(&BucketPolicyArgs {
|
||||
bucket: req_info.bucket.as_deref().unwrap_or(""),
|
||||
action,
|
||||
is_owner: false,
|
||||
@@ -469,8 +469,21 @@ pub async fn authorize_request<T>(req: &mut S3Request<T>, action: Action) -> S3R
|
||||
conditions: &conditions,
|
||||
object: req_info.object.as_deref().unwrap_or(""),
|
||||
})
|
||||
.await
|
||||
{
|
||||
.await;
|
||||
|
||||
if policy_allowed {
|
||||
// RestrictPublicBuckets: when true, deny public access even if bucket policy allows it.
|
||||
// Fail closed: if we cannot read the config, do not allow public access.
|
||||
match metadata_sys::get_public_access_block_config(bucket_name).await {
|
||||
Ok((config, _)) => {
|
||||
if config.restrict_public_buckets.unwrap_or(false) {
|
||||
return Err(s3_error!(AccessDenied, "Access Denied"));
|
||||
}
|
||||
}
|
||||
Err(_) => {
|
||||
return Err(s3_error!(AccessDenied, "Access Denied"));
|
||||
}
|
||||
}
|
||||
return Ok(());
|
||||
}
|
||||
|
||||
|
||||
@@ -36,7 +36,7 @@
|
||||
# - DeleteObject: Proper NoSuchBucket for deleted buckets
|
||||
# - Multipart Copy: InvalidRange when CopySourceRange exceeds source size
|
||||
#
|
||||
# Total: 395 tests
|
||||
# Total: 396 tests
|
||||
|
||||
test_basic_key_count
|
||||
test_bucket_create_naming_bad_short_one
|
||||
@@ -216,6 +216,7 @@ test_put_get_delete_public_block
|
||||
test_put_public_block
|
||||
test_block_public_policy
|
||||
test_block_public_policy_with_principal
|
||||
test_block_public_restrict_public_buckets
|
||||
test_get_public_block_deny_bucket_policy
|
||||
test_get_undefined_public_block
|
||||
|
||||
|
||||
@@ -19,7 +19,6 @@ test_account_usage
|
||||
test_atomic_conditional_write_1mb
|
||||
test_atomic_dual_conditional_write_1mb
|
||||
test_atomic_write_bucket_gone
|
||||
test_block_public_restrict_public_buckets
|
||||
test_bucket_create_exists_nonowner
|
||||
test_bucket_get_location
|
||||
test_bucket_head_extended
|
||||
|
||||
Reference in New Issue
Block a user