postgres_policy.go 3.4 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130
  1. package postgres
  2. import (
  3. "context"
  4. "encoding/json"
  5. "fmt"
  6. "github.com/seaweedfs/seaweedfs/weed/s3api/policy_engine"
  7. )
  8. // GetPolicies retrieves all IAM policies from PostgreSQL
  9. func (store *PostgresStore) GetPolicies(ctx context.Context) (map[string]policy_engine.PolicyDocument, error) {
  10. if !store.configured {
  11. return nil, fmt.Errorf("store not configured")
  12. }
  13. policies := make(map[string]policy_engine.PolicyDocument)
  14. rows, err := store.db.QueryContext(ctx, "SELECT name, document FROM policies")
  15. if err != nil {
  16. return nil, fmt.Errorf("failed to query policies: %w", err)
  17. }
  18. defer rows.Close()
  19. for rows.Next() {
  20. var name string
  21. var documentJSON []byte
  22. if err := rows.Scan(&name, &documentJSON); err != nil {
  23. return nil, fmt.Errorf("failed to scan policy row: %w", err)
  24. }
  25. var document policy_engine.PolicyDocument
  26. if err := json.Unmarshal(documentJSON, &document); err != nil {
  27. return nil, fmt.Errorf("failed to unmarshal policy document for %s: %v", name, err)
  28. }
  29. policies[name] = document
  30. }
  31. return policies, nil
  32. }
  33. // CreatePolicy creates a new IAM policy in PostgreSQL
  34. func (store *PostgresStore) CreatePolicy(ctx context.Context, name string, document policy_engine.PolicyDocument) error {
  35. if !store.configured {
  36. return fmt.Errorf("store not configured")
  37. }
  38. documentJSON, err := json.Marshal(document)
  39. if err != nil {
  40. return fmt.Errorf("failed to marshal policy document: %w", err)
  41. }
  42. _, err = store.db.ExecContext(ctx,
  43. "INSERT INTO policies (name, document) VALUES ($1, $2) ON CONFLICT (name) DO UPDATE SET document = $2, updated_at = CURRENT_TIMESTAMP",
  44. name, documentJSON)
  45. if err != nil {
  46. return fmt.Errorf("failed to insert policy: %w", err)
  47. }
  48. return nil
  49. }
  50. // UpdatePolicy updates an existing IAM policy in PostgreSQL
  51. func (store *PostgresStore) UpdatePolicy(ctx context.Context, name string, document policy_engine.PolicyDocument) error {
  52. if !store.configured {
  53. return fmt.Errorf("store not configured")
  54. }
  55. documentJSON, err := json.Marshal(document)
  56. if err != nil {
  57. return fmt.Errorf("failed to marshal policy document: %w", err)
  58. }
  59. result, err := store.db.ExecContext(ctx,
  60. "UPDATE policies SET document = $2, updated_at = CURRENT_TIMESTAMP WHERE name = $1",
  61. name, documentJSON)
  62. if err != nil {
  63. return fmt.Errorf("failed to update policy: %w", err)
  64. }
  65. rowsAffected, err := result.RowsAffected()
  66. if err != nil {
  67. return fmt.Errorf("failed to get rows affected: %w", err)
  68. }
  69. if rowsAffected == 0 {
  70. return fmt.Errorf("policy %s not found", name)
  71. }
  72. return nil
  73. }
  74. // DeletePolicy deletes an IAM policy from PostgreSQL
  75. func (store *PostgresStore) DeletePolicy(ctx context.Context, name string) error {
  76. if !store.configured {
  77. return fmt.Errorf("store not configured")
  78. }
  79. result, err := store.db.ExecContext(ctx, "DELETE FROM policies WHERE name = $1", name)
  80. if err != nil {
  81. return fmt.Errorf("failed to delete policy: %w", err)
  82. }
  83. rowsAffected, err := result.RowsAffected()
  84. if err != nil {
  85. return fmt.Errorf("failed to get rows affected: %w", err)
  86. }
  87. if rowsAffected == 0 {
  88. return fmt.Errorf("policy %s not found", name)
  89. }
  90. return nil
  91. }
  92. // GetPolicy retrieves a specific IAM policy by name from PostgreSQL
  93. func (store *PostgresStore) GetPolicy(ctx context.Context, name string) (*policy_engine.PolicyDocument, error) {
  94. policies, err := store.GetPolicies(ctx)
  95. if err != nil {
  96. return nil, err
  97. }
  98. if policy, exists := policies[name]; exists {
  99. return &policy, nil
  100. }
  101. return nil, nil // Policy not found
  102. }