fix(iam): anchor policy wildcards and support ? (AUTHZ-X2) - #1439
Merged
Merged
Conversation
NitinKumar004
marked this pull request as ready for review
October 4, 2026 11:04
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Fixes AUTHZ-X2. The IAM policy matcher (
wildcardMatch) didn't anchor the end of the pattern, so an Allow ons3:*Bucketalso matcheds3:DeleteBucketPolicy, anddynamodb:*TablematchedListTablesandDescribeTableReplicaAutoScaling. It also didn't support?.Changes
providers/aws/iam/wildcard.gowith one anchored glob (*= any run including empty,?= exactly one character). Every AWS IAM matcher now goes through it:*can still span colons (arn:aws:dynamodb:*keeps working).?supported.*can't span a component boundary. The resource component keeps any colons it carries. A pattern with no colon at all (such as*) is still matched against the whole value.coversService,couldMatchService) is case-insensitive and handles?.coversServiceonly says yes when the pattern is a head followed by trailing*s and the head matches a prefix ofsvc:. It can say no to an unusual pattern that does cover the service, but never the reverse, so X1a's conservative property still holds.*-only and case-sensitive as before.Tests
providers/aws/iam/wildcard_match_test.gowas written first and failed on the old code. It coverss3:*Bucketvss3:DeleteBucketPolicy,s3:Get?bject,*matching an empty string,arn:aws:s3:::b/*, the case rules for Action vs Resource, StringLike/StringNotLike, ArnLike per component, and trust principals.TestConservativeModesNeverWiden: across*/?patterns, Action/NotAction and Allow/Deny, the unknown-resource and service-wide modes never allow something a concrete evaluation denies, and never miss a Deny a concrete evaluation hits. The existing X1a tests inevaluate_modes_test.gostill pass.TestWildcardMatchinproviders/aws/iam/iam_test.gonow callsglobMatch, becausewildcardMatchwas removed. Its cases are unchanged. No existing test depended on the old unanchored behaviour.go test -raceon providers/{aws,azure,gcp}/iam, services/iam/..., server/aws, server/aws/{iam,sts,eks}, features/chaos, services/cost and the root IAM tests. All pass. golangci-lint--new-from-rev=origin/developmentreports 0 issues.E2E
Ran
cloudemu serve --enforce-authon port 64566 and used the aws CLI with the keys of a user whose only policy isAllow dynamodb:*Table on *:Behaviour changes to be aware of
arn:aws:iam::*, no longer match a full ARN. IAM compares ARNs component by component, so this follows AWS.S3:getobjectmatchess3:GetObject.