frostfs-node/pkg/services
Alex Vanin d8f7fed10a [#881] acl: Use session token from request at object.Put
Session token can be present in both object header and
request meta header. They are the same during initial object
placement.

At the object replication, storage node puts object without
any session tokens attached to the request. If container's eACL
denies object.Put for USER role (use bearer to upload), then
replication might fail on objects with session tokens of the
signed by container owner. It is incorrect, so use session
token directly from request meta header.

Signed-off-by: Alex Vanin <alexey@nspcc.ru>
2021-10-08 17:18:32 +03:00
..
accounting [#521] *: use stdlib errors package 2021-05-19 16:42:54 +03:00
audit [#770] logger: Delete spaces in log message keys 2021-09-07 12:55:01 +03:00
container [#872] services/container: Ignore passed routes in load router 2021-10-05 19:29:27 +03:00
control [#860] Re-compile protobuf files after make protoc target update 2021-09-29 17:51:33 +03:00
id [#11] Trim the old functionality 2020-10-02 11:22:55 +03:00
netmap [#660] services/netmap: Don't call IsSupportedVersion in LocalNodeInfo 2021-07-05 11:05:44 +03:00
object [#881] acl: Use session token from request at object.Put 2021-10-08 17:18:32 +03:00
object_manager [#645] placement/traverser: Rename Key method of Node type to PublicKey 2021-09-30 20:57:00 +03:00
policer [#882] policer: add CID to the error message 2021-10-08 08:21:01 +03:00
replicator [#645] *: Use helper functions to build client.NodeInfo structures 2021-09-30 20:57:00 +03:00
reputation [#607] reputation,container: Support address groups in ServerInfo 2021-06-28 15:52:50 +03:00
session [#562] pkg: remove nspcc-dev/neofs-crypto dependency 2021-06-15 14:49:59 +03:00
util [#643] pkg: Sync method names and commentaries to them 2021-06-24 16:10:44 +03:00