Repository navigation
fix(iam): build user and policy ARNs from the request's account - #2555
Merged
Merged
Conversation
CreateUser and CreatePolicy took the account for their ARN from a pre-multi-account helper that only knew STS session keys and otherwise fell back to the server's default account. Credentials issued by /_fakecloud/iam/create-admin are not session keys, so users and customer-managed policies created in a non-default account carried the default account id and the policy only resolved by that wrong ARN. Use the partitioned state's account, as CreateRole and CreateGroup already do, and drop the now-unused helper. Fixes #2552
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #2552.
CreateUserandCreatePolicybuilt their ARN fromeffective_account_id, a helper that predates multi-account isolation (#381). It only recognized STS session keys registered incredential_identitiesand otherwise fell back to the server's default account. Keys issued by/_fakecloud/iam/create-adminare not session keys, so users and customer-managed policies created in a non-default account gotarn:aws:iam::123456789012:...while being stored in the caller's account, and the policy only resolved by that wrong ARN.Both handlers now take the account from the partitioned state (
state.account_id), the same sourceCreateRoleandCreateGroupalready use. The unused helper and IAM's copy ofextract_access_keyare removed.No surface changes: this is a behavior fix with no new API, flag, or SDK field, so docs/SDKs/counts are unchanged.
Test plan
multi_account.rs:iam_entity_arns_use_non_default_account: a create-admin user in account B creates a user, policy, role, and group; every ARN names B;GetPolicy/AttachUserPolicy/GetUserresolve by the returned ARNs. Fails on main (arn:aws:iam::123456789012:user/alice).iam_entity_arns_use_assumed_role_account: same assertions through an assumed-role session from A into B.cargo test -p fakecloud-iam, e2eiam,iam_enforcement,iam_persistence,cloudformation_iam,multi_account: all pass.cargo clippy -p fakecloud-iam -p fakecloud-e2e --all-targets -- -D warningsclean.Summary by cubic
Fixes #2552 by making
CreateUserandCreatePolicybuild their ARNs from the partitioned state's account, matching whatCreateRoleandCreateGroupalready do. The old helper only recognized STS session keys and otherwise fell back to the server's default account, so users and customer-managed policies created in a non-default account gotarn:aws:iam::123456789012:...while being stored in the caller's account.effective_account_idhelper and IAM'sextract_access_key.Written for commit 78e76c3. Summary will update on new commits.