Documentation
¶
Index ¶
Constants ¶
This section is empty.
Variables ¶
var Authorize = binding.Bind[*AuthorizeArguments, *AuthorizeOK](command.MustParse("/s3/request/authorize"))
Authorize is the `/s3/request/authorize` command. Ingot invokes it on Hilt (issuer = Ingot, audience = subject = Hilt) to authorize an AWS S3 API request: Hilt verifies the SigV4 signature, looks up the access key's delegations, derives a signing key and re-delegates capabilities to the invocation issuer.
Functions ¶
This section is empty.
Types ¶
type AuthorizeArguments ¶
type AuthorizeArguments struct {
// Request is the AWS S3 API request to authorize.
Request s3.Request `cborgen:"request" dagjsongen:"request"`
}
AuthorizeArguments are the arguments to the `/s3/request/authorize` command.
func (*AuthorizeArguments) MarshalCBOR ¶
func (t *AuthorizeArguments) MarshalCBOR(w io.Writer) error
func (*AuthorizeArguments) MarshalDagJSON ¶
func (t *AuthorizeArguments) MarshalDagJSON(w io.Writer) error
func (*AuthorizeArguments) UnmarshalCBOR ¶
func (t *AuthorizeArguments) UnmarshalCBOR(r io.Reader) (err error)
func (*AuthorizeArguments) UnmarshalDagJSON ¶
func (t *AuthorizeArguments) UnmarshalDagJSON(r io.Reader) (err error)
type AuthorizeOK ¶
type AuthorizeOK struct {
// Bucket is the DID of the bucket addressed by the request. Note: not all
// requests are bucket-scoped, so this field may be nil. e.g. CreateBucket,
// ListAllMyBuckets, etc.
Bucket *did.DID `cborgen:"bucket,omitempty" dagjsongen:"bucket,omitempty"`
// SourceBucket is the DID of the bucket a copy (CopyObject, UploadPartCopy)
// reads from, as resolved and authorized by the service; nil for any other
// request. It equals Bucket for a copy within one bucket. The gateway keys
// what it caches about the request's buckets by the DIDs the service
// names, so a copy across buckets names both.
SourceBucket *did.DID `cborgen:"sourceBucket,omitempty" dagjsongen:"sourceBucket,omitempty"`
// Tenant is the DID of the tenant the access key belongs to (the tenant's
// did:plc). The gateway resolves its DID document to obtain the tenant's
// wrap key — the FEE tenant recipient every stored object is encrypted to.
Tenant did.DID `cborgen:"tenant" dagjsongen:"tenant"`
// Permissions maps the access key DID to its assigned S3 permissions.
Permissions s3.PermissionSet `cborgen:"permissions" dagjsongen:"permissions"`
// Keys maps the access key DID to its derived signing key(s).
Keys s3.KeySet `cborgen:"keys" dagjsongen:"keys"`
// Delegations maps the CID of a delegation whose audience is the invocation
// issuer to its proof chain.
Delegations s3.ProofSet `cborgen:"delegations" dagjsongen:"delegations"`
}
AuthorizeOK is the successful result of `/s3/request/authorize`. It carries the resolved bucket DID (and, for a copy, the source bucket's), the tenant DID, the S3 permission set for the access key, the derived signing key(s) and the (24-hour TTL) delegations re-delegated to the invocation issuer.
Its Permissions, Keys and Delegations fields are slice-valued maps that cbor-gen / dag-json-gen cannot generate inline, but they are wrapped in struct types (s3.PermissionSet etc.) with their own codecs, so this struct is generated normally (the generators delegate to a struct field's codec).
func (*AuthorizeOK) MarshalCBOR ¶
func (t *AuthorizeOK) MarshalCBOR(w io.Writer) error
func (*AuthorizeOK) MarshalDagJSON ¶
func (t *AuthorizeOK) MarshalDagJSON(w io.Writer) error
func (*AuthorizeOK) UnmarshalCBOR ¶
func (t *AuthorizeOK) UnmarshalCBOR(r io.Reader) (err error)
func (*AuthorizeOK) UnmarshalDagJSON ¶
func (t *AuthorizeOK) UnmarshalDagJSON(r io.Reader) (err error)