(resource:*)
,或者所有操作(action:*)
权限,则存在由于权限范围过大导致数据安全风险。"principal": {"qcs": ["qcs::cam::uin/100000000001:uin/100000000001"]}
"principal": {"qcs": ["qcs::cam::anonymous:anonymous"]}
"principal": {"qcs": ["qcs::cam::uin/100000000001:uin/100000000001"]}
"principal": {"qcs": ["qcs::cam::uin/100000000001:uin/100000000011"]}
"effect" : "allow"
描述 | 对应的 API 接口 |
name/cos:GetService | GET Service |
name/cos:GetBucket | GET Bucket (List Objects) |
name/cos:PutBucket | PUT Bucket |
name/cos:DeleteBucket | DELETE Bucket |
描述 | 对应的 API 接口 |
name/cos:GetObject | GET Object |
name/cos:PutObject | PUT Object |
name/cos:HeadObject | HEAD Object |
name/cos:DeleteObject | DELETE Object |
"action": ["name/cos:GetObject","name/cos:HeadObject"]
qcs:project_id:service_type:region:account:resource
参数 | 描述 | 是否必选 |
qcs | 是 qcloud service 的简称,表示是腾讯云的云服务。 | 是 |
project_id | 描述项目信息,仅为了兼容 CAM 早期逻辑。 | 可选 |
service_type | 描述产品简称,如 COS。 | 是 |
region | 是 | |
account | 描述资源拥有者的主账号信息。目前支持两种方式描述的资源拥有者。一种方式是 uin 方式,即主账号的 UIN 账号,表示为 uin/${OwnerUin} ,如 uin/100000000001。另外一种方式是 uid 方式,即主账号的 APPID,表示为 uid/${appid} ,如 uid/1250000000。目前 COS 的资源拥有者统一使用 uid 的方式表述,即主账号的开发商 APPID。 | 是 |
resource | 描述具体资源详情,在 COS 服务中使用存储桶 XML API 访问域名来描述。 | 是 |
"resource": ["qcs::cos:ap-guangzhou:uid/1250000000:examplebucket-1250000000/*"]
"resource": ["qcs::cos:ap-guangzhou:uid/1250000000:examplebucket-1250000000/folder/*"]
"resource": ["qcs::cos:ap-guangzhou:uid/1250000000:examplebucket-1250000000/folder/exampleobject"]
条件操作符 | 含义 | 条件名 | 示例 |
ip_equal | IP 等于 | qcs:ip | {"ip_equal":{"qcs:ip ":"10.121.2.0/24"}} |
ip_not_equal | IP 不等于 | qcs:ip | {"ip_not_equal":{"qcs:ip ":["10.121.1.0/24", "10.121.2.0/24"]}} |
"ip_equal":{"qcs:ip ":"10.121.2.0/24"}
"ip_equal": {"qcs: ip": ["101.226.100.185","101.226.100.186"]}
{"version": "2.0","principal": {"qcs": ["qcs: : cam: : anonymous: anonymous"]},"statement": [{"action": ["name/cos: GetObject","name/cos: HeadObject"],"condition": {"ip_equal": {"qcs: ip": ["101.226.100.185","101.226.100.186"]}},"effect": "allow","resource": ["qcs: : cos: ap-guangzhou: uid/1250000000: examplebucket-1250000000.ap-guangzhou.myqcloud.com/*"]}]}
本页内容是否解决了您的问题?