api-get-policy.go 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109
  1. /*
  2. * Minio Go Library for Amazon S3 Compatible Cloud Storage
  3. * Copyright 2015-2017 Minio, Inc.
  4. *
  5. * Licensed under the Apache License, Version 2.0 (the "License");
  6. * you may not use this file except in compliance with the License.
  7. * You may obtain a copy of the License at
  8. *
  9. * http://www.apache.org/licenses/LICENSE-2.0
  10. *
  11. * Unless required by applicable law or agreed to in writing, software
  12. * distributed under the License is distributed on an "AS IS" BASIS,
  13. * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
  14. * See the License for the specific language governing permissions and
  15. * limitations under the License.
  16. */
  17. package minio
  18. import (
  19. "context"
  20. "encoding/json"
  21. "io/ioutil"
  22. "net/http"
  23. "net/url"
  24. "github.com/minio/minio-go/pkg/policy"
  25. "github.com/minio/minio-go/pkg/s3utils"
  26. )
  27. // GetBucketPolicy - get bucket policy at a given path.
  28. func (c Client) GetBucketPolicy(bucketName, objectPrefix string) (bucketPolicy policy.BucketPolicy, err error) {
  29. // Input validation.
  30. if err := s3utils.CheckValidBucketName(bucketName); err != nil {
  31. return policy.BucketPolicyNone, err
  32. }
  33. if err := s3utils.CheckValidObjectNamePrefix(objectPrefix); err != nil {
  34. return policy.BucketPolicyNone, err
  35. }
  36. policyInfo, err := c.getBucketPolicy(bucketName)
  37. if err != nil {
  38. errResponse := ToErrorResponse(err)
  39. if errResponse.Code == "NoSuchBucketPolicy" {
  40. return policy.BucketPolicyNone, nil
  41. }
  42. return policy.BucketPolicyNone, err
  43. }
  44. return policy.GetPolicy(policyInfo.Statements, bucketName, objectPrefix), nil
  45. }
  46. // ListBucketPolicies - list all policies for a given prefix and all its children.
  47. func (c Client) ListBucketPolicies(bucketName, objectPrefix string) (bucketPolicies map[string]policy.BucketPolicy, err error) {
  48. // Input validation.
  49. if err := s3utils.CheckValidBucketName(bucketName); err != nil {
  50. return map[string]policy.BucketPolicy{}, err
  51. }
  52. if err := s3utils.CheckValidObjectNamePrefix(objectPrefix); err != nil {
  53. return map[string]policy.BucketPolicy{}, err
  54. }
  55. policyInfo, err := c.getBucketPolicy(bucketName)
  56. if err != nil {
  57. errResponse := ToErrorResponse(err)
  58. if errResponse.Code == "NoSuchBucketPolicy" {
  59. return map[string]policy.BucketPolicy{}, nil
  60. }
  61. return map[string]policy.BucketPolicy{}, err
  62. }
  63. return policy.GetPolicies(policyInfo.Statements, bucketName), nil
  64. }
  65. // Default empty bucket access policy.
  66. var emptyBucketAccessPolicy = policy.BucketAccessPolicy{
  67. Version: "2012-10-17",
  68. }
  69. // Request server for current bucket policy.
  70. func (c Client) getBucketPolicy(bucketName string) (policy.BucketAccessPolicy, error) {
  71. // Get resources properly escaped and lined up before
  72. // using them in http request.
  73. urlValues := make(url.Values)
  74. urlValues.Set("policy", "")
  75. // Execute GET on bucket to list objects.
  76. resp, err := c.executeMethod(context.Background(), "GET", requestMetadata{
  77. bucketName: bucketName,
  78. queryValues: urlValues,
  79. contentSHA256Hex: emptySHA256Hex,
  80. })
  81. defer closeResponse(resp)
  82. if err != nil {
  83. return emptyBucketAccessPolicy, err
  84. }
  85. if resp != nil {
  86. if resp.StatusCode != http.StatusOK {
  87. return emptyBucketAccessPolicy, httpRespToErrorResponse(resp, bucketName, "")
  88. }
  89. }
  90. bucketPolicyBuf, err := ioutil.ReadAll(resp.Body)
  91. if err != nil {
  92. return emptyBucketAccessPolicy, err
  93. }
  94. policy := policy.BucketAccessPolicy{}
  95. err = json.Unmarshal(bucketPolicyBuf, &policy)
  96. return policy, err
  97. }