Conversation
An admin can now run any command as another user: --as USER asks the server for a token acting as them, through reva's admin HTTP service, and uses it in place of the signed-in credential. Nothing else changes. The paths the CLI builds and the shares it lists follow from whom the server says the token belongs to, so no command needs to know. The token is asked for once per command and never cached, so each command has its own entry in reva's audit log and no token for someone else's account is left in /tmp. A completion never impersonates. whoami says whether the user is an admin, and under --as who is impersonating them. A server without admin features is not an error there. The dev revad builds from reva's admin-http branch and makes einstein an admin, so the integration tests cover both sides against a real server.
A path can now carry the identity it is reached as: marie@cb:~/Documents, marie@cb:project/cernbox:data, marie@cb:/eos/user/m/marie/x. It is scp's user@host:path, so it reads as what it is, and pkg/pathspec is still the only place that decides it. A command acts as one user. A USER@cb: path makes the whole command act as USER, as --as does, and paths for two different users are refused before anyone is impersonated. cp and sync are the exception, because their two sides may belong to two people: each side keeps its own identity. When the two differ the server cannot copy, since a COPY carries one credential, so the bytes are relayed through the client, read as one user and written as the other, without touching local disk. copy and paste refuse such a path: the clipboard is the signed-in user's. Each user named is impersonated once per command, and naming yourself is not an impersonation at all. Acting as someone is transparent: nothing in the output says it happened, and whoami answers as the user acted as. reva's audit log is the record. In cp and sync only the cb: marker makes a path remote now. A bare alias such as home:x is a local name there, so a name with a colon in it can no longer turn into a remote path; cb:~/x is the home space, and cb: on its own is the home space too.
The admin HTTP service is now its own reva pull request on master (cs3org/reva#5863), independent of Kerberos authentication (#5827). This environment needs both until they are merged, so it builds a branch that joins them.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Lets a CERNBox admin act as another user.
--as USERruns any command as that user. The CLI gets a token from reva's newPOST /admin/impersonatewith the admin's own credential and uses it in place of theirs. Nothing in the output says it happened; reva's audit log is the record.USER@cb:in front of a path reaches that path as the user, e.g.marie@cb:~/Documentsormarie@cb:project/cernbox:data. A command acts as one user, exceptcpandsync, whose two sides can differ: a copy between two users is streamed through the client, read as one and written as the other.whoamisays whether you are an admin (GET /admin/status).Path syntax change: in
cpandsynconlycb:marks a remote path. A bare alias likehome:xis now local there; usecb:~/xorcb:home:x.Needs cs3org/reva#5863. Until it and cs3org/reva#5827 (Kerberos) are merged, the dev revad builds from
cernbox-cli-dev, a reva branch joining the two; it makes einstein an admin, and the integration tests cover both sides.