Files
s3-cli/cmd/admin-accesskey-sts-revoke.go
T
Zach Kelling 0ba7019bf7 Rebrand: Hanzo S3 CLI -- remove all MinIO branding
- Replace copyright headers: "MinIO, Inc." -> "Hanzo AI, Inc." across 411+ Go files
- Replace "MinIO Object Storage stack" -> "Hanzo S3 stack" in all file headers
- Replace all user-facing "MinIO" references -> "Hanzo S3" in Usage, help text, examples
- Replace example alias "myminio" -> "mys3" throughout
- Replace example endpoints play.min.io -> s3.hanzo.ai, dl.min.io -> s3.hanzo.ai
- Replace doc URLs min.io -> hanzo.space
- Rewrite README.md/README_zh_CN.md: product is "Hanzo S3 CLI" (the s3 command)
- Update CONTRIBUTING.md, CONFLICT.md, NOTICE, code_of_conduct.md
- Update all Dockerfiles: labels, entrypoints, image refs -> ghcr.io/hanzos3/cli
- Update Makefile: build output, docker tags, install paths -> s3
- Update docker-buildx.sh: image tags -> ghcr.io/hanzos3/cli
- DO NOT change go.mod module path or import paths (github.com/minio/mc preserved)
- DO NOT change Go identifiers, SDK types, or wire protocol constants
- All unit tests pass
2026-02-21 14:19:07 -08:00

150 lines
4.5 KiB
Go

// Copyright (c) 2015-2025 Hanzo AI, Inc.
//
// This file is part of Hanzo S3 stack
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package cmd
import (
"github.com/minio/cli"
json "github.com/minio/colorjson"
"github.com/minio/madmin-go/v3"
"github.com/minio/mc/pkg/probe"
)
var adminAccesskeySTSRevokeFlags = []cli.Flag{
cli.BoolFlag{
Name: "all",
Usage: "revoke all STS accounts for the specified user",
},
cli.BoolFlag{
Name: "self",
Usage: "revoke all STS accounts for the authenticated user",
},
cli.StringFlag{
Name: "token-type",
Usage: "specify the token type to revoke",
},
}
var adminAccesskeySTSRevokeCmd = cli.Command{
Name: "sts-revoke",
Usage: "revokes all STS accounts or specified types for the specified user",
Action: mainAdminAccesskeySTSRevoke,
OnUsageError: onUsageError,
Before: setGlobalsFromContext,
Flags: append(adminAccesskeySTSRevokeFlags, globalFlags...),
CustomHelpTemplate: `NAME:
{{.HelpName}} - {{.Usage}}
USAGE:
{{.HelpName}} ALIAS USER [--all | --token-type TOKEN_TYPE]
Exactly one of --all or --token-type must be specified.
FLAGS:
{{range .VisibleFlags}}{{.}}
{{end}}
EXAMPLES:
1. Revoke all STS accounts for user "user1"
{{.Prompt}} {{.HelpName}} mys3 user1 --all
2. Revoke STS accounts of a token type "app-1" for user "user1"
{{.Prompt}} {{.HelpName}} mys3 user1 --token-type app-1
3. Revoke all STS accounts for the authenticated user
{{.Prompt}} {{.HelpName}} mys3 --self
4. Revoke STS accounts of a token type "app-1" for the authenticated user
{{.Prompt}} {{.HelpName}} mys3 --self --token-type app-1
`,
}
type stsRevokeMessage struct {
Status string `json:"status"`
User string `json:"user"`
TokenRevokeType string `json:"tokenRevokeType,omitempty"`
}
func (m stsRevokeMessage) String() string {
userString := "user " + m.User
if m.User == "" {
userString = "authenticated user"
}
if m.TokenRevokeType == "" {
return "Successfully revoked all STS accounts for " + userString
}
return "Successfully revoked all STS accounts of type " + m.TokenRevokeType + " for " + userString
}
func (m stsRevokeMessage) JSON() string {
if m.Status == "" {
m.Status = "success"
}
jsonMessageBytes, e := json.MarshalIndent(m, "", " ")
fatalIf(probe.NewError(e), "Unable to marshal into JSON.")
return string(jsonMessageBytes)
}
// checkSTSRevokeSyntax - validate all the passed arguments
func checkSTSRevokeSyntax(ctx *cli.Context) {
if len(ctx.Args()) > 2 || len(ctx.Args()) == 0 {
showCommandHelpAndExit(ctx, 1)
}
if !ctx.Bool("self") && ctx.Args().Get(1) == "" {
fatalIf(errInvalidArgument().Trace(), "Must specify user or use --self flag.")
}
if ctx.Bool("self") && ctx.Args().Get(1) != "" {
fatalIf(errInvalidArgument().Trace(), "Cannot specify user with --self flag.")
}
if (!ctx.Bool("all") && ctx.String("token-type") == "") || (ctx.Bool("all") && ctx.String("token-type") != "") {
fatalIf(errDummy().Trace(), "Exactly one of --all or --token-type must be specified.")
}
}
// mainAdminAccesskeySTSRevoke is the handle for "mc admin accesskey sts-revoke" command.
func mainAdminAccesskeySTSRevoke(ctx *cli.Context) error {
checkSTSRevokeSyntax(ctx)
// Get the alias parameter from cli
args := ctx.Args()
aliasedURL := args.Get(0)
user := args.Get(1) // will be empty if --self flag is set
tokenRevokeType := ctx.String("token-type")
fullRevoke := ctx.Bool("all")
// Create a new Hanzo S3 Admin Client
client, err := newAdminClient(aliasedURL)
fatalIf(err, "Unable to initialize admin connection.")
e := client.RevokeTokens(globalContext, madmin.RevokeTokensReq{
User: user,
TokenRevokeType: tokenRevokeType,
FullRevoke: fullRevoke,
})
fatalIf(probe.NewError(e).Trace(args...), "Unable to revoke tokens for %s", user)
printMsg(stsRevokeMessage{
User: user,
TokenRevokeType: tokenRevokeType,
})
return nil
}