Harshavardhana c90999df98 Valid if bucket names are internal (#7476)
This commit fixes a privilege escalation issue against
the S3 and web handlers. An authenticated IAM user
can:

- Read from or write to the internal '.minio.sys'
bucket by simply sending a properly signed
S3 GET or PUT request. Further, the user can
- Read from or write to the internal '.minio.sys'
bucket using the 'Upload'/'Download'/'DownloadZIP'
API by sending a "browser" request authenticated
with its JWT token.
2019-04-03 23:10:37 -07:00
..
2019-02-14 17:53:46 -08:00
2019-02-14 17:53:46 -08:00
2018-06-06 14:21:56 +05:30
2019-02-14 17:53:46 -08:00
2019-02-14 17:53:46 -08:00
2019-03-05 21:34:17 +05:30