Project

General

Profile

Actions

Bug #62292

open

Bucket policy wildcard * not working properly

Added by hoan nv 9 months ago. Updated 4 months ago.

Status:
Pending Backport
Priority:
Normal
Assignee:
Target version:
-
% Done:

0%

Source:
Tags:
iam backport_processed
Backport:
quincy reef
Regression:
No
Severity:
2 - major
Reviewed:
Affected Versions:
ceph-qa-suite:
Pull request ID:
Crash signature (v1):
Crash signature (v2):

Description

Hi all.

I try put bucket policy

{
  "Id": "Policy1687170406711",
  "Version": "2012-10-17",
  "Statement": [
      {
          "Sid": "Stmt1464968483619",
          "Effect": "Deny",
          "Principal": "*",
          "Action": "s3:PutObject",
          "Resource": [
              "arn:aws:s3:::hoannv-test/*js" 
          ]
      }

  ]
}

after config i upload 2 file.
1.file name test.js , result : it deny upload (correct)
2.file name test.1.js , result : it allow upload (wrong)

I tried same bucket policy on aws, i can't upload file test.1.js (403 Permission)
Thanks


Related issues 2 (2 open0 closed)

Copied to rgw - Backport #63971: reef: Bucket policy wildcard * not working properlyNewAdam EmersonActions
Copied to rgw - Backport #63972: quincy: Bucket policy wildcard * not working properlyNewAdam EmersonActions
Actions #1

Updated by hoan nv 9 months ago

Sorry
This policy will be error


 {
  "Id": "Policy1687170406711",
  "Version": "2012-10-17",
  "Statement": [
      {
          "Sid": "Stmt1464968483619",
          "Effect": "Deny",
          "Principal": "*",
          "Action": "s3:PutObject",
          "Resource": [
              "arn:aws:s3:::hoannv-test/*.js" 
          ]
      }

  ]
}

Actions #2

Updated by Casey Bodley 9 months ago

  • Assignee set to Adam Emerson
  • Tags set to iam
  • Backport set to pacific quincy reef
Actions #4

Updated by Casey Bodley 8 months ago

  • Status changed from New to Fix Under Review
  • Pull request ID set to 53156
Actions #5

Updated by Casey Bodley 4 months ago

  • Status changed from Fix Under Review to Pending Backport
  • Backport changed from pacific quincy reef to quincy reef
Actions #6

Updated by Backport Bot 4 months ago

  • Copied to Backport #63971: reef: Bucket policy wildcard * not working properly added
Actions #7

Updated by Backport Bot 4 months ago

  • Copied to Backport #63972: quincy: Bucket policy wildcard * not working properly added
Actions #8

Updated by Backport Bot 4 months ago

  • Tags changed from iam to iam backport_processed
Actions

Also available in: Atom PDF