mirror of
https://github.com/pgsty/minio.git
synced 2026-08-11 00:33:28 +03:00
bucket policy: Support for '?' wildcard. (#2353)
- Support for '?' wildcard for resource matching. - Wildcard package is added with Match functions. - Wildcard.Match supports '*' and wild.MatchExtended supports both '*' and '?' wildcards in the pattern string. - Tests for the same for the wide range of cases.
This commit is contained in:
committed by
Harshavardhana
parent
cc0d5b6fe0
commit
2e0742e309
@@ -237,78 +237,6 @@ func TestBucketPolicyActionMatch(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
// TestWildCardMatch - Tests validate the logic of wild card matching.
|
||||
// Its used to match the action and resources of the policy statement and the request.
|
||||
func TestWildCardMatch(t *testing.T) {
|
||||
testCases := []struct {
|
||||
pattern string
|
||||
text string
|
||||
expectedResult bool
|
||||
}{
|
||||
// Test case - 1.
|
||||
// Test case with pattern "*". Expected to match any text.
|
||||
{"*", "s3:GetObject", true},
|
||||
// Test case - 2.
|
||||
// Test case with empty pattern. This only matches empty string.
|
||||
{"", "s3:GetObject", false},
|
||||
// Test case - 3.
|
||||
// Test case with empty pattern. This only matches empty string.
|
||||
{"", "", true},
|
||||
// Test case - 4.
|
||||
// Test case with single "*" at the end.
|
||||
{"s3:*", "s3:ListMultipartUploadParts", true},
|
||||
// Test case - 5.
|
||||
// Test case with a no "*". In this case the pattern and text should be the same.
|
||||
{"s3:ListBucketMultipartUploads", "s3:ListBucket", false},
|
||||
// Test case - 6.
|
||||
// Test case with a no "*". In this case the pattern and text should be the same.
|
||||
{"s3:ListBucket", "s3:ListBucket", true},
|
||||
// Test case - 7.
|
||||
// Test case with a no "*". In this case the pattern and text should be the same.
|
||||
{"s3:ListBucketMultipartUploads", "s3:ListBucketMultipartUploads", true},
|
||||
// Test case - 8.
|
||||
// Test case with pattern containing key name with a prefix. Should accept the same text without a "*".
|
||||
{"my-bucket/oo*", "my-bucket/oo", true},
|
||||
// Test case - 9.
|
||||
// Test case with "*" at the end of the pattern.
|
||||
{"my-bucket/In*", "my-bucket/India/Karnataka/", true},
|
||||
// Test case - 10.
|
||||
// Test case with prefixes shuffled.
|
||||
// This should fail.
|
||||
{"my-bucket/In*", "my-bucket/Karnataka/India/", false},
|
||||
// Test case - 11.
|
||||
// Test case with text expanded to the wildcards in the pattern.
|
||||
{"my-bucket/In*/Ka*/Ban", "my-bucket/India/Karnataka/Ban", true},
|
||||
// Test case - 12.
|
||||
// Test case with the keyname part is repeated as prefix several times.
|
||||
// This is valid.
|
||||
{"my-bucket/In*/Ka*/Ban", "my-bucket/India/Karnataka/Ban/Ban/Ban/Ban/Ban", true},
|
||||
// Test case - 13.
|
||||
// Test case to validate that `*` can be expanded into multiple prefixes.
|
||||
{"my-bucket/In*/Ka*/Ban", "my-bucket/India/Karnataka/Area1/Area2/Area3/Ban", true},
|
||||
// Test case to validate that `*` can be expanded into multiple prefixes.
|
||||
{"my-bucket/In*/Ka*/Ban", "my-bucket/India/State1/State2/Karnataka/Area1/Area2/Area3/Ban", true},
|
||||
// Test case - 14.
|
||||
// Test case where the keyname part of the pattern is expanded in the text.
|
||||
{"my-bucket/In*/Ka*/Ban", "my-bucket/India/Karnataka/Bangalore", false},
|
||||
// Test case - 15.
|
||||
// Test case with prefixes and wildcard expanded for all "*".
|
||||
{"my-bucket/In*/Ka*/Ban*", "my-bucket/India/Karnataka/Bangalore", true},
|
||||
// Test case - 16.
|
||||
// Test case with keyname part being a wildcard in the pattern.
|
||||
{"my-bucket/*", "my-bucket/India", true},
|
||||
// Test case - 17.
|
||||
{"my-bucket/oo*", "my-bucket/odo", false},
|
||||
}
|
||||
// Iterating over the test cases, call the function under test and asert the output.
|
||||
for i, testCase := range testCases {
|
||||
actualResult := wildCardMatch(testCase.pattern, testCase.text)
|
||||
if testCase.expectedResult != actualResult {
|
||||
t.Errorf("Test %d: Expected the result to be `%v`, but instead found it to be `%v`", i+1, testCase.expectedResult, actualResult)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// Wrapper for calling Put Bucket Policy HTTP handler tests for both XL multiple disks and single node setup.
|
||||
func TestPutBucketPolicyHandler(t *testing.T) {
|
||||
ExecObjectLayerTest(t, testPutBucketPolicyHandler)
|
||||
|
||||
Reference in New Issue
Block a user