Search Options

Results per page
Sort
Preferred Languages
Advance

Results 1 - 8 of 8 for sessionPolicy (0.07 sec)

  1. cmd/admin-handlers-users.go

    			return
    		}
    	}
    
    	// if session policy is nil or empty, then it is implied policy
    	impliedPolicy := sessionPolicy == nil || (sessionPolicy.Version == "" && len(sessionPolicy.Statements) == 0)
    
    	var svcAccountPolicy policy.Policy
    
    	if !impliedPolicy {
    		svcAccountPolicy = *sessionPolicy
    	} else {
    		policiesNames, err := globalIAMSys.PolicyDBGet(svcAccount.ParentUser, svcAccount.Groups...)
    		if err != nil {
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 90.6K bytes
    - Viewed (0)
  2. cmd/jwt.go

    		if ucred.ParentUser == globalActiveCred.AccessKey && !globalAPIConfig.permitRootAccess() {
    			return nil, nil, false, errAccessKeyDisabled
    		}
    
    		// Now check if we have a sessionPolicy.
    		if _, ok = eclaims[policy.SessionPolicyName]; ok {
    			owner = false
    		} else {
    			owner = globalActiveCred.AccessKey == ucred.ParentUser
    		}
    
    		groups = ucred.Groups
    	}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 4.5K bytes
    - Viewed (0)
  3. cmd/iam.go

    		return auth.Credentials{}, time.Time{}, auth.ErrNoAccessKeyWithSecretKey
    	}
    
    	var policyBuf []byte
    	if opts.sessionPolicy != nil {
    		err := opts.sessionPolicy.Validate()
    		if err != nil {
    			return auth.Credentials{}, time.Time{}, err
    		}
    		policyBuf, err = json.Marshal(opts.sessionPolicy)
    		if err != nil {
    			return auth.Credentials{}, time.Time{}, err
    		}
    		if len(policyBuf) > maxSVCSessionPolicySize {
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 75.3K bytes
    - Viewed (0)
  4. cmd/iam-store.go

    		m.Set(iamPolicyClaimNameSA(), inheritedPolicyType)
    	}
    
    	if opts.sessionPolicy != nil { // session policies is being updated
    		if err := opts.sessionPolicy.Validate(); err != nil {
    			return updatedAt, err
    		}
    
    		if opts.sessionPolicy.Version != "" && len(opts.sessionPolicy.Statements) > 0 {
    			policyBuf, err := json.Marshal(opts.sessionPolicy)
    			if err != nil {
    				return updatedAt, err
    			}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 86.7K bytes
    - Viewed (0)
  5. cmd/sts-handlers.go

    		return nil
    	}
    
    	sessionPolicy, err := policy.ParseConfig(bytes.NewReader([]byte(sessionPolicyStr)))
    	if err != nil {
    		return err
    	}
    
    	// Version in policy must not be empty
    	if sessionPolicy.Version == "" {
    		return errors.New("Version cannot be empty expecting '2012-10-17'")
    	}
    
    	policyBuf, err := json.Marshal(sessionPolicy)
    	if err != nil {
    		return err
    	}
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 36.6K bytes
    - Viewed (0)
  6. cmd/site-replication.go

    		return errSRInvalidRequest(errInvalidArgument)
    	}
    	switch {
    	case change.Create != nil:
    		var sp *policy.Policy
    		var err error
    		if len(change.Create.SessionPolicy) > 0 {
    			sp, err = policy.ParseConfig(bytes.NewReader(change.Create.SessionPolicy))
    			if err != nil {
    				return wrapSRErr(err)
    			}
    		}
    		// skip overwrite of local update if peer sent stale info
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 184.7K bytes
    - Viewed (0)
  7. cmd/admin-handlers-idp-ldap.go

    					SecretKey:     newCred.SecretKey,
    					Groups:        newCred.Groups,
    					Name:          newCred.Name,
    					Description:   newCred.Description,
    					Claims:        opts.claims,
    					SessionPolicy: madmin.SRSessionPolicy(createReq.Policy),
    					Status:        auth.AccountOn,
    					Expiration:    createReq.Expiration,
    				},
    			},
    			UpdatedAt: updatedAt,
    		}))
    	}
    }
    
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 08 02:46:04 UTC 2025
    - 19.2K bytes
    - Viewed (0)
  8. cmd/sts-handlers_test.go

                "ldapUsername": "svc.algorithm",
                "parent": "uid=svc.algorithm,ou=swengg,dc=min,dc=io",
                "sa-policy": "inherited-policy"
            },
            "sessionPolicy": null,
            "status": "on",
            "name": "",
            "description": ""
        }
    }
    `,
    		// Built-in user-to-policies mapping should be imported without errors
    		// even if LDAP is enabled.
    Registered: Sun Sep 07 19:28:11 UTC 2025
    - Last Modified: Fri Aug 29 02:39:48 UTC 2025
    - 100.2K bytes
    - Viewed (1)
Back to top