Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 10 of 19 for parentuser (0.08 sec)

  1. cmd/sts-handlers.go

    		expiry = requestedDuration
    	}
    
    	parentUser := "custom" + getKeySeparator() + res.Success.User
    
    	// metadata map
    	claims[expClaim] = UTCNow().Add(time.Duration(expiry) * time.Second).Unix()
    	claims[subClaim] = parentUser
    	claims[roleArnClaim] = roleArn.String()
    	claims[parentClaim] = parentUser
    	tokenRevokeType := r.Form.Get(stsRevokeTokenType)
    	if tokenRevokeType != "" {
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 36.6K bytes
    - Viewed (0)
  2. cmd/admin-handlers-idp-openid.go

    	}) {
    		writeErrorResponseJSON(ctx, w, errorCodes.ToAPIErr(ErrAccessDenied), r.URL)
    		return
    	}
    
    	if selfOnly && len(userList) == 0 {
    		selfDN := cred.AccessKey
    		if cred.ParentUser != "" {
    			selfDN = cred.ParentUser
    		}
    		userList = append(userList, selfDN)
    	}
    
    	listType := r.Form.Get("listType")
    	var listSTSKeys, listServiceAccounts bool
    	switch listType {
    	case madmin.AccessKeyListUsersOnly:
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Sat Sep 06 17:38:46 UTC 2025
    - 7.6K bytes
    - Viewed (0)
  3. cmd/admin-handlers-users.go

    		IsOwner:         owner,
    		Claims:          cred.Claims,
    	})
    
    	if !adminPrivilege {
    		parentUser := cred.AccessKey
    		if cred.ParentUser != "" {
    			parentUser = cred.ParentUser
    		}
    		if svcAccount.ParentUser != "" && parentUser != svcAccount.ParentUser {
    			// The service account belongs to another user but return not
    			// found error to mitigate brute force attacks. or the
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 90.6K bytes
    - Viewed (0)
  4. cmd/admin-handlers-idp-ldap.go

    	// root user.
    	if newCred.ParentUser != globalActiveCred.AccessKey {
    		replLogIf(ctx, globalSiteReplicationSys.IAMChangeHook(ctx, madmin.SRIAMItem{
    			Type: madmin.SRIAMItemSvcAcc,
    			SvcAccChange: &madmin.SRSvcAccChange{
    				Create: &madmin.SRSvcAccCreate{
    					Parent:        newCred.ParentUser,
    					AccessKey:     newCred.AccessKey,
    					SecretKey:     newCred.SecretKey,
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 08 02:46:04 UTC 2025
    - 19.2K bytes
    - Viewed (0)
  5. cmd/iam.go

    	for parentUser, info := range parentUsers {
    		if !sys.LDAPConfig.IsLDAPUserDN(parentUser) {
    			continue
    		}
    
    		if info.subClaimValue != "" {
    			// we need to ask LDAP about the actual user DN not normalized DN.
    			allDistNames = append(allDistNames, info.subClaimValue)
    		} else {
    			allDistNames = append(allDistNames, parentUser)
    		}
    	}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 75.3K bytes
    - Viewed (0)
  6. cmd/jwt.go

    		if ucred.ParentUser == globalActiveCred.AccessKey && !globalAPIConfig.permitRootAccess() {
    			return nil, nil, false, errAccessKeyDisabled
    		}
    
    		// Now check if we have a sessionPolicy.
    		if _, ok = eclaims[policy.SessionPolicyName]; ok {
    			owner = false
    		} else {
    			owner = globalActiveCred.AccessKey == ucred.ParentUser
    		}
    
    		groups = ucred.Groups
    	}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 4.5K bytes
    - Viewed (0)
  7. cmd/iam-store.go

    	defer store.unlock()
    
    	accessKey := cred.AccessKey
    	parentUser := cred.ParentUser
    
    	// Found newly requested service account, to be an existing account -
    	// reject such operation (updates to the service account are handled in
    	// a different API).
    	if su, found := cache.iamUsersMap[accessKey]; found {
    		scred := su.Credentials
    		if scred.ParentUser != parentUser {
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 86.7K bytes
    - Viewed (0)
  8. cmd/ftp-server-driver.go

    				Type: madmin.SRIAMItemSTSAcc,
    				STSCredential: &madmin.SRSTSCredential{
    					AccessKey:    cred.AccessKey,
    					SecretKey:    cred.SecretKey,
    					SessionToken: cred.SessionToken,
    					ParentUser:   cred.ParentUser,
    				},
    				UpdatedAt: updatedAt,
    			}))
    
    			mcreds = credentials.NewStaticV4(cred.AccessKey, cred.SecretKey, cred.SessionToken)
    		} else {
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 14.3K bytes
    - Viewed (0)
  9. cmd/sftp-server.go

    		Type: madmin.SRIAMItemSTSAcc,
    		STSCredential: &madmin.SRSTSCredential{
    			AccessKey:    cred.AccessKey,
    			SecretKey:    cred.SecretKey,
    			SessionToken: cred.SessionToken,
    			ParentUser:   cred.ParentUser,
    		},
    		UpdatedAt: updatedAt,
    	}))
    
    	return &ssh.Permissions{
    		CriticalOptions: map[string]string{
    			"AccessKey":    cred.AccessKey,
    			"SecretKey":    cred.SecretKey,
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 16.5K bytes
    - Viewed (0)
  10. cmd/user-provider-utils.go

    	}
    
    	claims := credentials.Claims
    	if _, ok := claims[ldapUser]; ok {
    		return madmin.LDAPProvider // ldap users
    	}
    
    	if _, ok := claims[subClaim]; ok {
    		providerPrefix, _, found := strings.Cut(credentials.ParentUser, getKeySeparator())
    		if found {
    			return providerPrefix // this is true for certificate and custom providers
    		}
    		return madmin.OpenIDProvider // openid users are already hashed, so no separator
    	}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 4.1K bytes
    - Viewed (0)
Back to top