fix: AccountInfo API for LDAP users (#11874)

Also, ensure admin APIs auth additionally validates groups
This commit is contained in:
Aditya Manthramurthy
2021-03-23 17:39:20 -07:00
committed by GitHub
parent d23485e571
commit 8adfeb0d84
2 changed files with 11 additions and 1 deletions

View File

@@ -162,6 +162,7 @@ func checkAdminRequestAuth(ctx context.Context, r *http.Request, action iampolic
}
if globalIAMSys.IsAllowed(iampolicy.Args{
AccountName: cred.AccessKey,
Groups: cred.Groups,
Action: iampolicy.Action(action),
ConditionValues: getConditionValues(r, "", cred.AccessKey, claims),
IsOwner: owner,