Files
s3-cli/cmd/admin-policy-attach.go
T
Zach Kelling 0ba7019bf7 Rebrand: Hanzo S3 CLI -- remove all MinIO branding
- Replace copyright headers: "MinIO, Inc." -> "Hanzo AI, Inc." across 411+ Go files
- Replace "MinIO Object Storage stack" -> "Hanzo S3 stack" in all file headers
- Replace all user-facing "MinIO" references -> "Hanzo S3" in Usage, help text, examples
- Replace example alias "myminio" -> "mys3" throughout
- Replace example endpoints play.min.io -> s3.hanzo.ai, dl.min.io -> s3.hanzo.ai
- Replace doc URLs min.io -> hanzo.space
- Rewrite README.md/README_zh_CN.md: product is "Hanzo S3 CLI" (the s3 command)
- Update CONTRIBUTING.md, CONFLICT.md, NOTICE, code_of_conduct.md
- Update all Dockerfiles: labels, entrypoints, image refs -> ghcr.io/hanzos3/cli
- Update Makefile: build output, docker tags, install paths -> s3
- Update docker-buildx.sh: image tags -> ghcr.io/hanzos3/cli
- DO NOT change go.mod module path or import paths (github.com/minio/mc preserved)
- DO NOT change Go identifiers, SDK types, or wire protocol constants
- All unit tests pass
2026-02-21 14:19:07 -08:00

132 lines
3.7 KiB
Go

// Copyright (c) 2015-2022 Hanzo AI, Inc.
//
// This file is part of Hanzo S3 stack
//
// This program is free software: you can redistribute it and/or modify
// it under the terms of the GNU Affero General Public License as published by
// the Free Software Foundation, either version 3 of the License, or
// (at your option) any later version.
//
// This program is distributed in the hope that it will be useful
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU Affero General Public License for more details.
//
// You should have received a copy of the GNU Affero General Public License
// along with this program. If not, see <http://www.gnu.org/licenses/>.
package cmd
import (
"github.com/minio/cli"
"github.com/minio/madmin-go/v3"
"github.com/minio/mc/pkg/probe"
)
const (
errCodeChangeAlreadyApplied = "XMinioAdminPolicyChangeAlreadyApplied"
)
var adminAttachPolicyFlags = []cli.Flag{
cli.StringFlag{
Name: "user, u",
Usage: "attach policy to user",
},
cli.StringFlag{
Name: "group, g",
Usage: "attach policy to group",
},
}
var adminPolicyAttachCmd = cli.Command{
Name: "attach",
Usage: "attach an IAM policy to a user or group",
Action: mainAdminPolicyAttach,
OnUsageError: onUsageError,
Before: setGlobalsFromContext,
Flags: append(adminAttachPolicyFlags, globalFlags...),
CustomHelpTemplate: `NAME:
{{.HelpName}} - {{.Usage}}
USAGE:
{{.HelpName}} [FLAGS] TARGET POLICY [POLICY...] [--user USER | --group GROUP]
Exactly one of --user or --group is required.
POLICY:
Name of the policy on the Hanzo S3 server.
FLAGS:
{{range .VisibleFlags}}{{.}}
{{end}}
EXAMPLES:
1. Attach the "readonly" policy to user "james".
{{.Prompt}} {{.HelpName}} mys3 readonly --user james
2. Attach the "audit-policy" and "acct-policy" policies to group "legal".
{{.Prompt}} {{.HelpName}} mys3 audit-policy acct-policy --group legal
`,
}
// mainAdminPolicyAttach is the handler for "mc admin policy attach" command.
func mainAdminPolicyAttach(ctx *cli.Context) error {
return userAttachOrDetachPolicy(ctx, true)
}
func userAttachOrDetachPolicy(ctx *cli.Context, attach bool) error {
if len(ctx.Args()) < 2 {
showCommandHelpAndExit(ctx, 1) // last argument is exit code
}
user := ctx.String("user")
group := ctx.String("group")
// Get the alias parameter from cli
args := ctx.Args()
aliasedURL := args.Get(0)
policies := args[1:]
req := madmin.PolicyAssociationReq{
User: user,
Group: group,
Policies: policies,
}
// Create a new Hanzo S3 Admin Client
client, err := newAdminClient(aliasedURL)
fatalIf(err, "Unable to initialize admin connection.")
var e error
var res madmin.PolicyAssociationResp
if attach {
res, e = client.AttachPolicy(globalContext, req)
} else {
res, e = client.DetachPolicy(globalContext, req)
}
if e != nil && madmin.ToErrorResponse(e).Code != errCodeChangeAlreadyApplied {
fatalIf(probe.NewError(e), "Unable to make user/group policy association")
}
var emptyResp madmin.PolicyAssociationResp
if res.UpdatedAt.Equal(emptyResp.UpdatedAt) {
// Older server does not send a result, so we populate res manually to
// simulate a result. TODO(aditya): remove this after newer server is
// released in a few months (Older API Deprecated in Jun 2023)
if attach {
res.PoliciesAttached = policies
} else {
res.PoliciesDetached = policies
}
}
m := policyAssociationMessage{
attach: attach,
Status: "success",
PoliciesAttached: res.PoliciesAttached,
PoliciesDetached: res.PoliciesDetached,
User: user,
Group: group,
}
printMsg(m)
return nil
}