tomzx/policy-evaluator

基于 AWS AMI 政策的策略评估器。

dev-master / 0.1.x-dev 2018-02-19 23:16 UTC

This package is auto-updated.

Last update: 2024-09-10 07:45:23 UTC


README

License Latest Stable Version Latest Unstable Version Build Status Code Quality Code Coverage Total Downloads

Policy Evaluator 是一个基于 AWS 政策的简单系统。给定一组语句,Policy Evaluator 将能够回答关于这组策略是否允许(或不允许)在特定资源上执行给定操作的问题。

入门

php composer.phar require tomzx/policy-evaluator

示例

use tomzx\PolicyEvaluator\Evaluator;
use tomzx\PolicyEvaluator\Resource;

Resource::$prefix = 'arn';

$evaluator = new Evaluator([
	'Statement' => [
		[
			'Action' => 'service:*',
			'Resource' => 'arn:aws:*',
			'Effect' => 'Allow',
		],
		[
			'Action' => 's3:*',
			'Resource' => 'arn:aws:s3:::my-bucket/*',
			'Effect' => 'Allow',
		],
	],
]);

$evaluator->canExecuteActionOnResource('service:test', 'arn:aws:test');
$evaluator->canExecuteActionOnResource('s3:GetObject', 'arn:aws:s3:::my-bucket/some-file');

变量支持

use tomzx\PolicyEvaluator\Evaluator;
use tomzx\PolicyEvaluator\Resource;

Resource::$prefix = 'arn';

$evaluator = new Evaluator([
	'Statement' => [
		[
			'Action' => 'service:*',
			'Resource' => 'arn:aws:${aws:username}',
			'Effect' => 'Allow',
		],
	],
]);

$evaluator->canExecuteActionOnResource('service:test', 'arn:aws:test', [
    'aws:username' => 'someUsername',
]);

许可证

代码采用MIT 许可证。请参阅 LICENSE