Search Options

Display Count
Sort
Preferred Language
Advanced Search

Results 1 - 2 of 2 for denyOnly (0.05 seconds)

  1. cmd/admin-handlers-users.go

    	}
    
    	denyOnly := (targetUser == cred.AccessKey || targetUser == cred.ParentUser)
    	if ldap && !denyOnly {
    		res, _ := globalIAMSys.LDAPConfig.GetValidatedDNForUsername(targetUser)
    		if res != nil && res.NormDN == cred.ParentUser {
    			denyOnly = true
    		}
    	}
    
    	// Check if action is allowed if creating access key for another user
    Created: Sun Apr 05 19:28:12 GMT 2026
    - Last Modified: Fri Aug 29 02:39:48 GMT 2025
    - 90.6K bytes
    - Click Count (0)
  2. cmd/iam.go

    	// As the session policy exists, even if the parent is the root account, it
    	// must be restricted by it. So, we set `.IsOwner` to false here
    	// unconditionally.
    	//
    	// We also set `DenyOnly` arg to false here - this is an IMPORTANT corner
    	// case: DenyOnly is used only for allowing an account to do actions related
    	// to its own account (like create service accounts for itself, among
    Created: Sun Apr 05 19:28:12 GMT 2026
    - Last Modified: Wed Oct 15 17:00:45 GMT 2025
    - 76.5K bytes
    - Click Count (0)
Back to Top