2023-10-16 16:50:51 -04:00
|
|
|
// Copyright (c) 2015-2023 MinIO, Inc.
|
2021-11-26 22:22:40 -05:00
|
|
|
//
|
|
|
|
// This file is part of MinIO Object Storage stack
|
|
|
|
//
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This program is distributed in the hope that it will be useful
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU Affero General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
|
|
|
|
|
|
|
package arn
|
|
|
|
|
|
|
|
import (
|
2024-04-04 04:31:34 -04:00
|
|
|
"errors"
|
2021-11-26 22:22:40 -05:00
|
|
|
"fmt"
|
|
|
|
"regexp"
|
|
|
|
"strings"
|
|
|
|
)
|
|
|
|
|
|
|
|
// ARN structure:
|
|
|
|
//
|
|
|
|
// arn:partition:service:region:account-id:resource-type/resource-id
|
|
|
|
//
|
|
|
|
// In this implementation, account-id is empty.
|
|
|
|
//
|
|
|
|
// Reference: https://docs.aws.amazon.com/general/latest/gr/aws-arns-and-namespaces.html
|
|
|
|
|
|
|
|
const (
|
2024-04-04 04:31:34 -04:00
|
|
|
arnPrefixArn = "arn"
|
|
|
|
arnPartitionMinio = "minio"
|
|
|
|
arnServiceIAM = "iam"
|
|
|
|
arnResourceTypeRole = "role"
|
2021-11-26 22:22:40 -05:00
|
|
|
)
|
|
|
|
|
|
|
|
// ARN - representation of resources based on AWS ARNs.
|
|
|
|
type ARN struct {
|
2024-04-04 04:31:34 -04:00
|
|
|
Partition string
|
|
|
|
Service string
|
2021-11-26 22:22:40 -05:00
|
|
|
Region string
|
2024-04-04 04:31:34 -04:00
|
|
|
ResourceType string
|
2021-11-26 22:22:40 -05:00
|
|
|
ResourceID string
|
|
|
|
}
|
|
|
|
|
2022-01-02 12:15:06 -05:00
|
|
|
// Allows english letters, numbers, '.', '-', '_' and '/'. Starts with a
|
|
|
|
// letter or digit. At least 1 character long.
|
2023-10-16 16:50:51 -04:00
|
|
|
var validResourceIDRegex = regexp.MustCompile(`[A-Za-z0-9_/\.-]+$`)
|
2021-11-26 22:22:40 -05:00
|
|
|
|
|
|
|
// NewIAMRoleARN - returns an ARN for a role in MinIO.
|
|
|
|
func NewIAMRoleARN(resourceID, serverRegion string) (ARN, error) {
|
|
|
|
if !validResourceIDRegex.MatchString(resourceID) {
|
2024-04-04 04:31:34 -04:00
|
|
|
return ARN{}, fmt.Errorf("invalid resource ID: %s", resourceID)
|
2021-11-26 22:22:40 -05:00
|
|
|
}
|
|
|
|
return ARN{
|
|
|
|
Partition: arnPartitionMinio,
|
|
|
|
Service: arnServiceIAM,
|
|
|
|
Region: serverRegion,
|
|
|
|
ResourceType: arnResourceTypeRole,
|
|
|
|
ResourceID: resourceID,
|
|
|
|
}, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// String - returns string representation of the ARN.
|
|
|
|
func (arn ARN) String() string {
|
|
|
|
return strings.Join(
|
|
|
|
[]string{
|
2024-04-04 04:31:34 -04:00
|
|
|
arnPrefixArn,
|
|
|
|
arn.Partition,
|
|
|
|
arn.Service,
|
2021-11-26 22:22:40 -05:00
|
|
|
arn.Region,
|
|
|
|
"", // account-id is always empty in this implementation
|
2024-04-04 04:31:34 -04:00
|
|
|
arn.ResourceType + "/" + arn.ResourceID,
|
2021-11-26 22:22:40 -05:00
|
|
|
},
|
|
|
|
":",
|
|
|
|
)
|
|
|
|
}
|
|
|
|
|
|
|
|
// Parse - parses an ARN string into a type.
|
|
|
|
func Parse(arnStr string) (arn ARN, err error) {
|
|
|
|
ps := strings.Split(arnStr, ":")
|
2024-04-04 04:31:34 -04:00
|
|
|
if len(ps) != 6 || ps[0] != string(arnPrefixArn) {
|
|
|
|
err = errors.New("invalid ARN string format")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if ps[1] != string(arnPartitionMinio) {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = errors.New("invalid ARN - bad partition field")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if ps[2] != string(arnServiceIAM) {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = errors.New("invalid ARN - bad service field")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
// ps[3] is region and is not validated here. If the region is invalid,
|
|
|
|
// the ARN would not match any configured ARNs in the server.
|
|
|
|
if ps[4] != "" {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = errors.New("invalid ARN - unsupported account-id field")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
res := strings.SplitN(ps[5], "/", 2)
|
|
|
|
if len(res) != 2 {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = errors.New("invalid ARN - resource does not contain a \"/\"")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if res[0] != string(arnResourceTypeRole) {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = errors.New("invalid ARN: resource type is invalid")
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
if !validResourceIDRegex.MatchString(res[1]) {
|
2024-04-04 04:31:34 -04:00
|
|
|
err = fmt.Errorf("invalid resource ID: %s", res[1])
|
2021-11-26 22:22:40 -05:00
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
arn = ARN{
|
|
|
|
Partition: arnPartitionMinio,
|
|
|
|
Service: arnServiceIAM,
|
|
|
|
Region: ps[3],
|
|
|
|
ResourceType: arnResourceTypeRole,
|
|
|
|
ResourceID: res[1],
|
|
|
|
}
|
|
|
|
return
|
|
|
|
}
|