mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-11 23:56:53 +00:00
b6d4689c75
Bring the dormant Resource::Kms variant to life: arn:aws:kms:::key/<key_id> patterns (empty-account form, wildcards allowed in the id, alias/<name> reserved as parse-only) now parse, validate, serialize back, and are matched by KMS statements against the requested key id carried in Args::object. Statements without KMS resources keep the legacy match-every-key behaviour, as do call sites that pass no key resource, so nothing changes until the admin/SSE authorization paths start passing key ids. Statement validation rejects KMS resources on non-KMS statements, and bucket policy validation rejects KMS actions and resources outright while stored policies keep deserializing; evaluation skips pure-KMS bucket policy statements with a warning. A kms:Decrypt action is added for the upcoming SSE-KMS read path. Refs rustfs/backlog#1582 (part of rustfs/backlog#1562)
82 lines
2.3 KiB
Rust
82 lines
2.3 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
pub mod action;
|
|
mod doc;
|
|
mod effect;
|
|
mod function;
|
|
mod id;
|
|
pub mod opa;
|
|
#[allow(clippy::module_inception)]
|
|
mod policy;
|
|
mod principal;
|
|
pub mod resource;
|
|
pub mod statement;
|
|
pub(crate) mod utils;
|
|
pub mod variables;
|
|
|
|
pub use action::ActionSet;
|
|
pub use doc::PolicyDoc;
|
|
pub use effect::Effect;
|
|
pub use function::{Functions, is_server_derived_condition_key};
|
|
pub use id::ID;
|
|
pub use policy::*;
|
|
pub use principal::Principal;
|
|
pub use resource::ResourceSet;
|
|
pub use statement::Statement;
|
|
pub use utils::{ClaimLookup, get_claim_case_insensitive};
|
|
|
|
#[derive(thiserror::Error, Debug)]
|
|
#[cfg_attr(test, derive(Eq, PartialEq))]
|
|
pub enum Error {
|
|
#[error("invalid Version '{0}'")]
|
|
InvalidVersion(String),
|
|
|
|
#[error("invalid Effect '{0}'")]
|
|
InvalidEffect(String),
|
|
|
|
#[error("both 'Action' and 'NotAction' are empty")]
|
|
NonAction,
|
|
|
|
#[error("'Action' and 'NotAction' cannot both be specified in the same statement")]
|
|
BothActionAndNotAction,
|
|
|
|
#[error("'Resource' is empty")]
|
|
NonResource,
|
|
|
|
#[error("'Resource' and 'NotResource' cannot both be specified in the same statement")]
|
|
BothResourceAndNotResource,
|
|
|
|
#[error("invalid key name: '{0}'")]
|
|
InvalidKeyName(String),
|
|
|
|
#[error("invalid key: '{0}'")]
|
|
InvalidKey(String),
|
|
|
|
#[error("invalid action: '{0}'")]
|
|
InvalidAction(String),
|
|
|
|
#[error("'Action' contains mixed action families in the same statement")]
|
|
MixedActionFamilies,
|
|
|
|
#[error("invalid resource, type: '{0}', pattern: '{1}'")]
|
|
InvalidResource(String, String),
|
|
|
|
#[error("KMS resources require a statement whose actions are all KMS actions")]
|
|
KmsResourceWithNonKmsAction,
|
|
|
|
#[error("bucket policies do not support KMS actions or resources")]
|
|
KmsUnsupportedInBucketPolicy,
|
|
}
|