mirror of
https://github.com/rustfs/rustfs.git
synced 2026-10-04 04:21:35 +00:00
7a0f8561b6
* fix(oidc): ignore groups without a matching policy at login OIDC login failed with "OIDC policy mapping did not resolve to current policies" whenever any mapped group lacked a policy of the same name. Directory-backed providers such as Active Directory always emit groups like `DOMAIN\Domain Users` that can never be mapped, so group-based authorization was impossible there. Keep only policy names that resolve to an existing policy and are valid in session claims, and reject the login only when none remain. The signed `policy` claim still lists only resolved names, so request-time evaluation and site replication receivers keep their invariant. Refs #8163 * fix(oidc): only ignore unmapped groups-claim values Limit the relaxed resolution to policy names derived solely from the groups claim. Names from ROLE_POLICY, a dedicated CLAIM_NAME claim, or an explicit IAM policy mapping must still all resolve. Reject the login when a mapped name refers to an existing policy whose name is not allowed in session claims: dropping it could remove an explicit Deny and broaden access. Claim-unsafe names are only checked against the in-memory policy cache and never passed to storage-backed policy loading. Refs #8163 * docs(oidc): document ignorable roles claim values and cover wiring Roles claim values are merged into the canonical groups, so values without a matching policy are ignored like groups-claim values. This covers built-in provider roles such as Keycloak's `offline_access`. Document that in the field and method docs and in the provider requirements, and pin it with a test. Assert that the OIDC authorization carries the group claim policies so a regression in the wiring cannot silently disable the relaxation. Refs #8163 * fix(oidc): ignore group policies only after confirmed absence merge_policies drops names whose load fails, so a storage or decode error for an uncached group policy was indistinguishable from a missing one. The group name was then ignored and the session signed without it, which could remove an existing Deny that request-time checks cannot restore. Add IamSys::policy_exists, which consults the cache and then storage and reports false only for NoSuchPolicy while returning every other error. The OIDC binding now ignores a group-derived name only after a confirmed absence and rejects the login when a lookup fails. Refs #8163 --------- Co-authored-by: cxymds <cxymds@gmail.com> Co-authored-by: Chris <anzhengchao@gmail.com>