2021-04-18 15:41:13 -04:00
|
|
|
// Copyright (c) 2015-2021 MinIO, Inc.
|
|
|
|
//
|
|
|
|
// This file is part of MinIO Object Storage stack
|
|
|
|
//
|
|
|
|
// This program is free software: you can redistribute it and/or modify
|
|
|
|
// it under the terms of the GNU Affero General Public License as published by
|
|
|
|
// the Free Software Foundation, either version 3 of the License, or
|
|
|
|
// (at your option) any later version.
|
|
|
|
//
|
|
|
|
// This program is distributed in the hope that it will be useful
|
|
|
|
// but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
// GNU Affero General Public License for more details.
|
|
|
|
//
|
|
|
|
// You should have received a copy of the GNU Affero General Public License
|
|
|
|
// along with this program. If not, see <http://www.gnu.org/licenses/>.
|
2018-04-24 18:53:30 -04:00
|
|
|
|
|
|
|
package cmd
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/json"
|
|
|
|
"net/http"
|
2020-04-01 03:04:25 -04:00
|
|
|
"net/url"
|
2020-04-06 16:44:16 -04:00
|
|
|
"strconv"
|
2020-04-01 03:04:25 -04:00
|
|
|
"strings"
|
|
|
|
"time"
|
2018-04-24 18:53:30 -04:00
|
|
|
|
2020-01-08 06:31:43 -05:00
|
|
|
jsoniter "github.com/json-iterator/go"
|
2020-07-14 12:38:05 -04:00
|
|
|
miniogopolicy "github.com/minio/minio-go/v7/pkg/policy"
|
2020-04-01 03:04:25 -04:00
|
|
|
xhttp "github.com/minio/minio/cmd/http"
|
2018-04-27 18:02:54 -04:00
|
|
|
"github.com/minio/minio/cmd/logger"
|
2020-01-27 17:12:34 -05:00
|
|
|
"github.com/minio/minio/pkg/bucket/policy"
|
2018-04-24 18:53:30 -04:00
|
|
|
"github.com/minio/minio/pkg/handlers"
|
|
|
|
)
|
|
|
|
|
2018-06-06 15:52:56 -04:00
|
|
|
// PolicySys - policy subsystem.
|
2020-05-20 13:18:15 -04:00
|
|
|
type PolicySys struct{}
|
2018-04-24 18:53:30 -04:00
|
|
|
|
2020-05-19 16:53:54 -04:00
|
|
|
// Get returns stored bucket policy
|
|
|
|
func (sys *PolicySys) Get(bucket string) (*policy.Policy, error) {
|
2020-05-20 13:18:15 -04:00
|
|
|
return globalBucketMetadataSys.GetPolicyConfig(bucket)
|
2018-04-24 18:53:30 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// IsAllowed - checks given policy args is allowed to continue the Rest API.
|
|
|
|
func (sys *PolicySys) IsAllowed(args policy.Args) bool {
|
2020-05-20 13:18:15 -04:00
|
|
|
p, err := sys.Get(args.BucketName)
|
|
|
|
if err == nil {
|
2020-05-19 16:53:54 -04:00
|
|
|
return p.IsAllowed(args)
|
|
|
|
}
|
|
|
|
|
2020-05-20 13:18:15 -04:00
|
|
|
// Log unhandled errors.
|
|
|
|
if _, ok := err.(BucketPolicyNotFound); !ok {
|
|
|
|
logger.LogIf(GlobalContext, err)
|
2018-04-24 18:53:30 -04:00
|
|
|
}
|
|
|
|
|
|
|
|
// As policy is not available for given bucket name, returns IsOwner i.e.
|
|
|
|
// operation is allowed only for owner.
|
|
|
|
return args.IsOwner
|
|
|
|
}
|
|
|
|
|
|
|
|
// NewPolicySys - creates new policy system.
|
|
|
|
func NewPolicySys() *PolicySys {
|
2020-05-20 13:18:15 -04:00
|
|
|
return &PolicySys{}
|
2018-04-24 18:53:30 -04:00
|
|
|
}
|
|
|
|
|
2020-04-06 16:44:16 -04:00
|
|
|
func getConditionValues(r *http.Request, lc string, username string, claims map[string]interface{}) map[string][]string {
|
2019-01-20 23:57:14 -05:00
|
|
|
currTime := UTCNow()
|
2020-04-01 03:04:25 -04:00
|
|
|
|
|
|
|
principalType := "Anonymous"
|
|
|
|
if username != "" {
|
|
|
|
principalType = "User"
|
2020-08-17 20:39:55 -04:00
|
|
|
if len(claims) > 0 {
|
|
|
|
principalType = "AssumedRole"
|
|
|
|
}
|
|
|
|
if username == globalActiveCred.AccessKey {
|
|
|
|
principalType = "Account"
|
|
|
|
}
|
2020-04-01 03:04:25 -04:00
|
|
|
}
|
|
|
|
|
2020-06-12 23:04:01 -04:00
|
|
|
vid := r.URL.Query().Get("versionId")
|
|
|
|
if vid == "" {
|
|
|
|
if u, err := url.Parse(r.Header.Get(xhttp.AmzCopySource)); err == nil {
|
|
|
|
vid = u.Query().Get("versionId")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2021-04-02 12:34:15 -04:00
|
|
|
authType := getRequestAuthType(r)
|
|
|
|
var signatureVersion string
|
|
|
|
switch authType {
|
|
|
|
case authTypeSignedV2, authTypePresignedV2:
|
|
|
|
signatureVersion = signV2Algorithm
|
|
|
|
case authTypeSigned, authTypePresigned, authTypeStreamingSigned, authTypePostPolicy:
|
|
|
|
signatureVersion = signV4Algorithm
|
|
|
|
}
|
|
|
|
|
|
|
|
var authtype string
|
|
|
|
switch authType {
|
|
|
|
case authTypePresignedV2, authTypePresigned:
|
|
|
|
authtype = "REST-QUERY-STRING"
|
|
|
|
case authTypeSignedV2, authTypeSigned, authTypeStreamingSigned:
|
|
|
|
authtype = "REST-HEADER"
|
|
|
|
case authTypePostPolicy:
|
|
|
|
authtype = "POST"
|
|
|
|
}
|
|
|
|
|
2018-12-26 20:39:30 -05:00
|
|
|
args := map[string][]string{
|
2021-04-02 12:34:15 -04:00
|
|
|
"CurrentTime": {currTime.Format(time.RFC3339)},
|
|
|
|
"EpochTime": {strconv.FormatInt(currTime.Unix(), 10)},
|
|
|
|
"SecureTransport": {strconv.FormatBool(r.TLS != nil)},
|
|
|
|
"SourceIp": {handlers.GetSourceIP(r)},
|
|
|
|
"UserAgent": {r.UserAgent()},
|
|
|
|
"Referer": {r.Referer()},
|
|
|
|
"principaltype": {principalType},
|
|
|
|
"userid": {username},
|
|
|
|
"username": {username},
|
|
|
|
"versionid": {vid},
|
|
|
|
"signatureversion": {signatureVersion},
|
|
|
|
"authType": {authtype},
|
2018-12-26 20:39:30 -05:00
|
|
|
}
|
2018-04-24 18:53:30 -04:00
|
|
|
|
2020-04-06 16:44:16 -04:00
|
|
|
if lc != "" {
|
|
|
|
args["LocationConstraint"] = []string{lc}
|
2020-04-01 03:04:25 -04:00
|
|
|
}
|
|
|
|
|
2020-04-06 16:44:16 -04:00
|
|
|
cloneHeader := r.Header.Clone()
|
2020-04-01 03:04:25 -04:00
|
|
|
|
|
|
|
for _, objLock := range []string{
|
|
|
|
xhttp.AmzObjectLockMode,
|
|
|
|
xhttp.AmzObjectLockLegalHold,
|
|
|
|
xhttp.AmzObjectLockRetainUntilDate,
|
|
|
|
} {
|
|
|
|
if values, ok := cloneHeader[objLock]; ok {
|
|
|
|
args[strings.TrimPrefix(objLock, "X-Amz-")] = values
|
|
|
|
}
|
|
|
|
cloneHeader.Del(objLock)
|
|
|
|
}
|
|
|
|
|
|
|
|
for key, values := range cloneHeader {
|
2018-04-24 18:53:30 -04:00
|
|
|
if existingValues, found := args[key]; found {
|
|
|
|
args[key] = append(existingValues, values...)
|
|
|
|
} else {
|
|
|
|
args[key] = values
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-04-01 03:04:25 -04:00
|
|
|
var cloneURLValues = url.Values{}
|
2020-04-06 16:44:16 -04:00
|
|
|
for k, v := range r.URL.Query() {
|
2020-04-01 03:04:25 -04:00
|
|
|
cloneURLValues[k] = v
|
|
|
|
}
|
|
|
|
|
|
|
|
for _, objLock := range []string{
|
|
|
|
xhttp.AmzObjectLockMode,
|
|
|
|
xhttp.AmzObjectLockLegalHold,
|
|
|
|
xhttp.AmzObjectLockRetainUntilDate,
|
|
|
|
} {
|
|
|
|
if values, ok := cloneURLValues[objLock]; ok {
|
|
|
|
args[strings.TrimPrefix(objLock, "X-Amz-")] = values
|
|
|
|
}
|
|
|
|
cloneURLValues.Del(objLock)
|
|
|
|
}
|
|
|
|
|
|
|
|
for key, values := range cloneURLValues {
|
2018-04-24 18:53:30 -04:00
|
|
|
if existingValues, found := args[key]; found {
|
|
|
|
args[key] = append(existingValues, values...)
|
|
|
|
} else {
|
|
|
|
args[key] = values
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2019-10-16 11:59:59 -04:00
|
|
|
// JWT specific values
|
|
|
|
for k, v := range claims {
|
|
|
|
vStr, ok := v.(string)
|
|
|
|
if ok {
|
2020-08-17 20:39:55 -04:00
|
|
|
// Special case for AD/LDAP STS users
|
|
|
|
if k == ldapUser {
|
2020-09-01 02:56:22 -04:00
|
|
|
args["user"] = []string{vStr}
|
|
|
|
} else {
|
|
|
|
args[k] = []string{vStr}
|
2020-08-17 20:39:55 -04:00
|
|
|
}
|
2019-10-16 11:59:59 -04:00
|
|
|
}
|
|
|
|
}
|
2020-04-01 03:04:25 -04:00
|
|
|
|
2018-04-24 18:53:30 -04:00
|
|
|
return args
|
|
|
|
}
|
|
|
|
|
2020-06-12 23:04:01 -04:00
|
|
|
// PolicyToBucketAccessPolicy converts a MinIO policy into a minio-go policy data structure.
|
2018-04-24 18:53:30 -04:00
|
|
|
func PolicyToBucketAccessPolicy(bucketPolicy *policy.Policy) (*miniogopolicy.BucketAccessPolicy, error) {
|
|
|
|
// Return empty BucketAccessPolicy for empty bucket policy.
|
|
|
|
if bucketPolicy == nil {
|
|
|
|
return &miniogopolicy.BucketAccessPolicy{Version: policy.DefaultVersion}, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
data, err := json.Marshal(bucketPolicy)
|
|
|
|
if err != nil {
|
|
|
|
// This should not happen because bucketPolicy is valid to convert to JSON data.
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
var policyInfo miniogopolicy.BucketAccessPolicy
|
2020-01-08 06:31:43 -05:00
|
|
|
var json = jsoniter.ConfigCompatibleWithStandardLibrary
|
2018-04-24 18:53:30 -04:00
|
|
|
if err = json.Unmarshal(data, &policyInfo); err != nil {
|
|
|
|
// This should not happen because data is valid to JSON data.
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return &policyInfo, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// BucketAccessPolicyToPolicy - converts minio-go/policy.BucketAccessPolicy to policy.Policy.
|
|
|
|
func BucketAccessPolicyToPolicy(policyInfo *miniogopolicy.BucketAccessPolicy) (*policy.Policy, error) {
|
|
|
|
data, err := json.Marshal(policyInfo)
|
|
|
|
if err != nil {
|
|
|
|
// This should not happen because policyInfo is valid to convert to JSON data.
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
var bucketPolicy policy.Policy
|
2020-01-08 06:31:43 -05:00
|
|
|
var json = jsoniter.ConfigCompatibleWithStandardLibrary
|
2018-04-24 18:53:30 -04:00
|
|
|
if err = json.Unmarshal(data, &bucketPolicy); err != nil {
|
|
|
|
// This should not happen because data is valid to JSON data.
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
|
|
|
return &bucketPolicy, nil
|
|
|
|
}
|