mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-22 12:26:37 +00:00
feat(s3): enforce RestrictPublicBuckets for anonymous access (#2033)
Signed-off-by: 安正超 <anzhengchao@gmail.com> Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
This commit is contained in:
@@ -460,7 +460,7 @@ pub async fn authorize_request<T>(req: &mut S3Request<T>, action: Action) -> S3R
|
|||||||
}
|
}
|
||||||
|
|
||||||
if action != Action::S3Action(S3Action::ListAllMyBucketsAction) {
|
if action != Action::S3Action(S3Action::ListAllMyBucketsAction) {
|
||||||
if PolicySys::is_allowed(&BucketPolicyArgs {
|
let policy_allowed = PolicySys::is_allowed(&BucketPolicyArgs {
|
||||||
bucket: req_info.bucket.as_deref().unwrap_or(""),
|
bucket: req_info.bucket.as_deref().unwrap_or(""),
|
||||||
action,
|
action,
|
||||||
is_owner: false,
|
is_owner: false,
|
||||||
@@ -469,8 +469,21 @@ pub async fn authorize_request<T>(req: &mut S3Request<T>, action: Action) -> S3R
|
|||||||
conditions: &conditions,
|
conditions: &conditions,
|
||||||
object: req_info.object.as_deref().unwrap_or(""),
|
object: req_info.object.as_deref().unwrap_or(""),
|
||||||
})
|
})
|
||||||
.await
|
.await;
|
||||||
{
|
|
||||||
|
if policy_allowed {
|
||||||
|
// RestrictPublicBuckets: when true, deny public access even if bucket policy allows it.
|
||||||
|
// Fail closed: if we cannot read the config, do not allow public access.
|
||||||
|
match metadata_sys::get_public_access_block_config(bucket_name).await {
|
||||||
|
Ok((config, _)) => {
|
||||||
|
if config.restrict_public_buckets.unwrap_or(false) {
|
||||||
|
return Err(s3_error!(AccessDenied, "Access Denied"));
|
||||||
|
}
|
||||||
|
}
|
||||||
|
Err(_) => {
|
||||||
|
return Err(s3_error!(AccessDenied, "Access Denied"));
|
||||||
|
}
|
||||||
|
}
|
||||||
return Ok(());
|
return Ok(());
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -36,7 +36,7 @@
|
|||||||
# - DeleteObject: Proper NoSuchBucket for deleted buckets
|
# - DeleteObject: Proper NoSuchBucket for deleted buckets
|
||||||
# - Multipart Copy: InvalidRange when CopySourceRange exceeds source size
|
# - Multipart Copy: InvalidRange when CopySourceRange exceeds source size
|
||||||
#
|
#
|
||||||
# Total: 395 tests
|
# Total: 396 tests
|
||||||
|
|
||||||
test_basic_key_count
|
test_basic_key_count
|
||||||
test_bucket_create_naming_bad_short_one
|
test_bucket_create_naming_bad_short_one
|
||||||
@@ -216,6 +216,7 @@ test_put_get_delete_public_block
|
|||||||
test_put_public_block
|
test_put_public_block
|
||||||
test_block_public_policy
|
test_block_public_policy
|
||||||
test_block_public_policy_with_principal
|
test_block_public_policy_with_principal
|
||||||
|
test_block_public_restrict_public_buckets
|
||||||
test_get_public_block_deny_bucket_policy
|
test_get_public_block_deny_bucket_policy
|
||||||
test_get_undefined_public_block
|
test_get_undefined_public_block
|
||||||
|
|
||||||
|
|||||||
@@ -19,7 +19,6 @@ test_account_usage
|
|||||||
test_atomic_conditional_write_1mb
|
test_atomic_conditional_write_1mb
|
||||||
test_atomic_dual_conditional_write_1mb
|
test_atomic_dual_conditional_write_1mb
|
||||||
test_atomic_write_bucket_gone
|
test_atomic_write_bucket_gone
|
||||||
test_block_public_restrict_public_buckets
|
|
||||||
test_bucket_create_exists_nonowner
|
test_bucket_create_exists_nonowner
|
||||||
test_bucket_get_location
|
test_bucket_get_location
|
||||||
test_bucket_head_extended
|
test_bucket_head_extended
|
||||||
|
|||||||
Reference in New Issue
Block a user