feat(auth): resource ARNs for IAM, SQS, SNS and DynamoDB (AUTHZ-X1e) - #1443
Draft
NitinKumar004 wants to merge 1 commit into
Draft
NitinKumar004 wants to merge 1 commit into
NitinKumar004 wants to merge 1 commit into
Conversation
IAM, SQS, SNS and DynamoDB now name the resource each request acts on, so resource-scoped Allow and Deny statements apply under --enforce-auth. SQS and DynamoDB move from the gate's target table to their own IAMChecks; the gate's DynamoDB-only deriveResource is gone.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AUTHZ-X1e from the AUTHZ-X1 plan (§2 Resource ARNs). Before this change, IAM, SNS and SQS were authorized under
--enforce-authagainst an unknown resource, and DynamoDB had a table ARN only for requests with a top-levelTableName. As a result, a policy such assqs:SendMessageon one queue denied every queue, andAllow dynamodb:*withDeny ... table/prodalso blocked aBatchWriteItemthat touched onlydev. With this change, each request is authorized against the resource it actually acts on.What changed
IAM (
server/aws/iam/authz.go)iamActionsnow maps every served action to its resource type: user, role, group, policy, instance-profile or mfa.Pathand the name, the same way the backend builds it on create. The deny message only names what the request sent.PolicyArn,SerialNumberandPolicySourceArnare accepted only in this account, or as an AWS managed policy for policies.*.GetUserwithoutUserName, andCreateServiceLinkedRole, stay unknown.SQS (
server/aws/sqs/authz.go)QueueUrl(last path segment, which is the only key the backend matches),QueueName,SourceArn, or the source ARN inside a move-task handle. The ARN isarn:aws:sqs:<server region>:<server account>:<name>.*Batchoperations are authorized as the single-message action (sqs:SendMessage,sqs:DeleteMessage,sqs:ChangeMessageVisibility), which is how AWS authorizes them.ListQueuesuses*.SNS (
server/aws/sns/authz.go)TopicArn,TargetArnorResourceArn, using the last field, which is the topic the handler runs on. For aSubscriptionArnit uses the topic field.CreateTopicusesName.PublishBatchis authorized assns:Publish.publishTarget, so the gate and dispatch read the same parameter.DynamoDB (
server/aws/dynamodb/authz.go)Query,Scanand the contributor-insights ops usetable/x/index/ywhenIndexNameis set.BatchGetItemandBatchWriteItemget one check per table.TransactWriteItemsgetsPutItem,UpdateItem,DeleteItemorConditionCheckItemper element, with the element kind picked by the sametoTxOpdispatch uses.TransactGetItemsgetsGetItemper table.tableFromARNthe handler uses.GetRecordsis authorized on the stream of the table its shard iterator names.Gate and shared helpers
deriveResourceandjsonFieldare removed from the gate. JSON-RPC handlers still on the target table get an unknown resource.Scope, never from the request.awsauthzgainsScope.ARN,Scope.GlobalARNandJSONBody.JSONBodydecodes the same waywire.DecodeJSONdoes and puts the body back.I checked the action-to-resource mapping against the service authorization reference data for IAM, SQS, SNS and DynamoDB (servicereference.us-east-1.amazonaws.com, the machine-readable form of the "Actions, resources, and condition keys" pages).
Known gaps, left for later:
CreateServiceLinkedRolestays unknown, because the role name is derived in the provider.Tests
IAMCheckstable tests for iam, sqs, sns, dynamodb and streams.server/aws/authz_resource_arns_test.goadds matrix rows:sqs:SendMessageon q1 passes on q1, including the batch op, and returns 403 on q2.sns:*on t1 lets a publish to t1 through but denies t2, and deniesUnsubscribeof a t2 subscription.Allow dynamodb:*withDeny table/prodblocks prod inPutItem,BatchWriteItemandTransactWriteItems, and only there.Querygrant does not cover the base table.iam:*onuser/dev/*coversalice(path/dev/) by name but notbob.contrib/serveradds a real-SDK subtest under serve--enforce-auth, scoped to q1: q1 send and batch pass, q2 is denied, and so isReceiveMessage.developmentand pass here.Verification
go build ./...go vetandgo test -raceonserver/aws,server/aws/{iam,sqs,sns,dynamodb},server/wire/awsauthz,providers/aws/iamandcompat/awsgo -C contrib/server test -run Enforcegolangci-lint --new-from-rev=origin/development: 0 issuescoveragegen: no changeaws CLI against
cloudemu serve --enforce-authon :64966, bootstrapped with the admin token and a seedediamUserskey. Thelimiteduser had SendMessage on q1, Publish on t1, item ops ontdev, and GetUser/TagUser onuser/dev/*.tdevput/get/batch, and get-user/tag-user on alice.tprodput, atdev+tprodbatch and transact, and bob get/tag.tprodwere empty and bob had no tags.