* Validates object lock headers * @param {object} bucket - bucket metadata * @param {object} headers - request headers * @param {object} log - the log request * @return {object} - object with error if validation fails
(bucket, headers, log)
| 34 | * @return {object} - object with error if validation fails |
| 35 | */ |
| 36 | function validateHeaders(bucket, headers, log) { |
| 37 | const bucketObjectLockEnabled = bucket.isObjectLockEnabled(); |
| 38 | const objectLegalHold = headers['x-amz-object-lock-legal-hold']; |
| 39 | const objectLockDate = headers['x-amz-object-lock-retain-until-date']; |
| 40 | const objectLockMode = headers['x-amz-object-lock-mode']; |
| 41 | // If retention headers or legal hold header present but |
| 42 | // object lock is not enabled on the bucket return error |
| 43 | if ((objectLockDate || objectLockMode || objectLegalHold) |
| 44 | && !bucketObjectLockEnabled) { |
| 45 | log.trace('bucket is missing ObjectLockConfiguration'); |
| 46 | return errorInstances.InvalidRequest.customizeDescription( |
| 47 | 'Bucket is missing ObjectLockConfiguration'); |
| 48 | } |
| 49 | if ((objectLockMode || objectLockDate) && |
| 50 | !(objectLockMode && objectLockDate)) { |
| 51 | return errorInstances.InvalidArgument.customizeDescription( |
| 52 | 'x-amz-object-lock-retain-until-date and ' + |
| 53 | 'x-amz-object-lock-mode must both be supplied', |
| 54 | ); |
| 55 | } |
| 56 | const validModes = new Set(['GOVERNANCE', 'COMPLIANCE']); |
| 57 | if (objectLockMode && !validModes.has(objectLockMode)) { |
| 58 | return errorInstances.InvalidArgument.customizeDescription( |
| 59 | 'Unknown wormMode directive'); |
| 60 | } |
| 61 | const validLegalHolds = new Set(['ON', 'OFF']); |
| 62 | if (objectLegalHold && !validLegalHolds.has(objectLegalHold)) { |
| 63 | return errorInstances.InvalidArgument.customizeDescription( |
| 64 | 'Legal hold status must be one of "ON", "OFF"'); |
| 65 | } |
| 66 | const currentDate = new Date().toISOString(); |
| 67 | if (objectLockMode && objectLockDate <= currentDate) { |
| 68 | return errorInstances.InvalidArgument.customizeDescription( |
| 69 | 'The retain until date must be in the future!'); |
| 70 | } |
| 71 | return null; |
| 72 | } |
| 73 | |
| 74 | /** |
| 75 | * Compares new object retention to bucket default retention |
no test coverage detected