1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60
|
// Copyright (c) 2015-2024 MinIO, Inc.
//
// This file is part of MinIO Object Storage stack
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package policy
import (
"github.com/minio/pkg/v3/policy/condition"
)
// STSAction - STS policy action.
type STSAction string
const (
// AssumeRoleWithWebIdentityAction - STS action for AssumeRoleWithWebIdentity call
AssumeRoleWithWebIdentityAction = "sts:AssumeRoleWithWebIdentity"
// AllSTSActions - select all STS actions
AllSTSActions = "*"
)
// List of all supported sts actions.
var supportedSTSActions = map[STSAction]struct{}{
AssumeRoleWithWebIdentityAction: {},
AllSTSActions: {},
}
// IsValid - checks if action is valid or not.
func (action STSAction) IsValid() bool {
_, ok := supportedSTSActions[action]
return ok
}
func createSTSActionConditionKeyMap() map[Action]condition.KeySet {
allSupportedSTSKeys := []condition.Key{}
for _, keyName := range condition.AllSupportedSTSKeys {
allSupportedSTSKeys = append(allSupportedSTSKeys, keyName.ToKey())
}
return ActionConditionKeyMap{
AllSTSActions: condition.NewKeySet(allSupportedSTSKeys...),
AssumeRoleWithWebIdentityAction: condition.NewKeySet([]condition.Key{condition.STSDurationSeconds.ToKey()}...),
}
}
// stsActionConditionKeyMap - holds mapping of supported condition key for an action.
var stsActionConditionKeyMap = createSTSActionConditionKeyMap()
|