Skip to content

Commit 752235a

Browse files
committed
squash! sts: test get_object() before put_object() so there are no ACLs
1 parent 1bdb126 commit 752235a

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

s3tests/functional/test_sts.py

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1082,11 +1082,11 @@ def test_session_policy_bucket_policy_role_arn():
10821082
)
10831083

10841084
# GetObject for nonexistent object should be denied by session policy
1085-
e = assert_raises(ClientError, s3_client.get_object, Bucket=bucket_name_1, Key="test-1.txt")
1085+
e = assert_raises(ClientError, s3_client.get_object, Bucket=bucket_name_1, Key="test-role-arn.txt")
10861086
assert (403, 'AccessDenied') == _get_status_and_error_code(e.response)
10871087

10881088
bucket_body = 'this is a test file'
1089-
s3_put_obj = s3_client.put_object(Body=bucket_body, Bucket=bucket_name_1, Key="test-1.txt")
1089+
s3_put_obj = s3_client.put_object(Body=bucket_body, Bucket=bucket_name_1, Key="test-role-arn.txt")
10901090
assert s3_put_obj['ResponseMetadata']['HTTPStatusCode'] == 200
10911091

10921092
oidc_remove=iam_client.delete_open_id_connect_provider(
@@ -1157,11 +1157,11 @@ def test_session_policy_bucket_policy_session_arn():
11571157
)
11581158

11591159
# GetObject for nonexistent object should be allowed by bucket policy
1160-
e = assert_raises(ClientError, s3_client.get_object, Bucket=bucket_name_1, Key="test-1.txt")
1160+
e = assert_raises(ClientError, s3_client.get_object, Bucket=bucket_name_1, Key="test-session-arn.txt")
11611161
assert (404, 'NoSuchKey') == _get_status_and_error_code(e.response)
11621162

11631163
bucket_body = 'this is a test file'
1164-
s3_put_obj = s3_client.put_object(Body=bucket_body, Bucket=bucket_name_1, Key="test-1.txt")
1164+
s3_put_obj = s3_client.put_object(Body=bucket_body, Bucket=bucket_name_1, Key="test-session-arn.txt")
11651165
assert s3_put_obj['ResponseMetadata']['HTTPStatusCode'] == 200
11661166

11671167
oidc_remove=iam_client.delete_open_id_connect_provider(

0 commit comments

Comments
 (0)