tomzx / policy-evaluator
基于 AWS AMI 政策的策略评估器。
dev-master / 0.1.x-dev
2018-02-19 23:16 UTC
Requires
- php: >=5.6.0
Requires (Dev)
- phpunit/phpunit: ^5
This package is auto-updated.
Last update: 2024-09-10 07:45:23 UTC
README
Policy Evaluator
是一个基于 AWS 政策的简单系统。给定一组语句,Policy Evaluator
将能够回答关于这组策略是否允许(或不允许)在特定资源上执行给定操作的问题。
入门
php composer.phar require tomzx/policy-evaluator
示例
use tomzx\PolicyEvaluator\Evaluator; use tomzx\PolicyEvaluator\Resource; Resource::$prefix = 'arn'; $evaluator = new Evaluator([ 'Statement' => [ [ 'Action' => 'service:*', 'Resource' => 'arn:aws:*', 'Effect' => 'Allow', ], [ 'Action' => 's3:*', 'Resource' => 'arn:aws:s3:::my-bucket/*', 'Effect' => 'Allow', ], ], ]); $evaluator->canExecuteActionOnResource('service:test', 'arn:aws:test'); $evaluator->canExecuteActionOnResource('s3:GetObject', 'arn:aws:s3:::my-bucket/some-file');
变量支持
use tomzx\PolicyEvaluator\Evaluator; use tomzx\PolicyEvaluator\Resource; Resource::$prefix = 'arn'; $evaluator = new Evaluator([ 'Statement' => [ [ 'Action' => 'service:*', 'Resource' => 'arn:aws:${aws:username}', 'Effect' => 'Allow', ], ], ]); $evaluator->canExecuteActionOnResource('service:test', 'arn:aws:test', [ 'aws:username' => 'someUsername', ]);