feat(iam): tri-state, unknown-resource and service-wide policy evaluation - #1381
Draft
NitinKumar004 wants to merge 1 commit into
Draft
NitinKumar004 wants to merge 1 commit into
NitinKumar004 wants to merge 1 commit into
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Part a of tracker AUTHZ-X1 (IAM authorization for query and REST requests).
What
Adds an optional AWS-only capability
PermissionEvaluatortoservices/iam/driver, next toContextualAuthorizerandPolicyInspector:EvaluatePermission(ctx, EvalRequest) Decisionreturns allowed, implicitDeny or explicitDeny.EvaluateServiceWide(ctx, principal, service, condCtx) Decisionanswers "may this principal run everysvc:action on every resource".In
providers/aws/iam,decidebecomes a wrapper overdecideWith(docs, req, mode)with three modes:evaluatePolicyper document)."*"; a NotResource Allow never counts. A Deny that matches the action counts whatever its Resource or NotResource. A condition key missing from the context makes a Deny match and an Allow fail. The Deny half is a deliberate fail-closed deviation from real IAM (commented inevaluatePolicyConservative): with the resource unknown we can't prove the Deny doesn't apply.svc:*(*,s3:*,s*do,s3:Get*doesn't) onResource "*", or when no NotAction entry could matchsvc. A Deny counts when any Action entry could match asvc:action, or when its NotAction doesn't cover all ofsvc:*.The permissions boundary is evaluated in the same mode, and an explicit Deny in either the identity policies or the boundary gives explicitDeny.
condition.gogainsevaluateConditionsWithwith an absent-key rule;evaluateConditionskeeps real IAM semantics.Why
The enforce-auth gate only authorizes JSON-RPC requests today. X1b (next) needs a tri-state answer, a safe answer when the handler can't name the resource yet, and a service-level answer for handlers that are still at tier 0.
EvaluatePermissionandEvaluateServiceWidehave no production caller in this PR; X1b is their first consumer, as the plan sequences.Unchanged
CheckPermissionandCheckPermissionWithContextreturn exactly what they did.CheckPermissionWithContextnow goes through the sharedevaluatePrincipalhelper in known-resource mode. Tests pin known mode against a copy of the old decide loop over a corpus of documents, actions, resources and contexts, and the existing IAM and server/aws authz suites pass as they are. No wire or gate change.Tests
providers/aws/iam/evaluate_modes_test.go: every mode, the conservative Deny cases (missing key, AND with a present key, IfExists Allow), NotAction and NotResource in each mode, boundary in each mode, group Deny beating a user Allow, and CheckPermission agreement.