Bucket Policy

Last updated: 2023-09-13 11:34:29

Feature Overview

This document provides an overview of APIs and SDK code samples related to bucket policies.
API
Operation
Description
Setting a bucket policy
Sets a permission policy for the specified bucket
Querying bucket policy
Queries the permission policy of the specified bucket
Deleting a bucket policy
Deletes the permission policy of a specified bucket

Setting a bucket policy

Note

This API (PUT Bucket policy) is used to write a permission policy for a bucket. The policy passed in this API will overwrite the existing one (if any) in the bucket.

Method prototype

CosResult PutBucketPolicy(const PutBucketPolicyReq& req, PutBucketPolicyResp* resp)

Sample Request

qcloud_cos::CosConfig config("./config.json");
qcloud_cos::CosAPI cos(config);

std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.

qcloud_cos::PutBucketPolicyReq req(bucket_name);
qcloud_cos::PutBucketPolicyResp resp;
std::string bucket_policy =
" {"
" \"Statement\": ["
" {"
" \"Principal\": {"
" \"qcs\": ["
" \"qcs::cam::uin/100000000001:uin/100000000011\"" //Replace with the UIN of the account you want to grant permissions to
" ]\n"
" },\n"
" \"Effect\": \"allow\","
" \"Action\": ["
" \"cos:PutObject\""
" ],\n"
" \"Resource\": [" // Change this to the allowed path prefix, which can be determined based on the user login status of your website. Examples: a.jpg, a/*, or * (Using the wildcard * poses significant security risks, please evaluate carefully before using)
" \"qcs::cos:ap-guangzhou:uid/1250000000:examplebucket-1250000000/exampleobject\""
" ],\n"
" \"Condition\": {"
" \"string_equal\": {"
" \"cos:x-cos-mime-limit\": \"image/jpeg\""
" }"
" }"
" }"
" ],"
" \"Version\": \"2.0\""
" }";

req.SetBody(bucket_policy);
qcloud_cos::CosResult result = cos.PutBucketPolicy(req, &resp);

if (result.IsSucc()) {
// ...
} else {
// You can call CosResult's member functions to output error information, such as requestID, etc.
}

Description

Parameter name
Description
Required
Statement
Describes one or more permissions.
Required
Version
The policy syntax version. The default is 2.0.
Required
Principal
Specifies the entity to which the permission is granted. For more information, see Access Policy Language Overview
Required
Action
Here, we refer to the COS API, where you can specify a single operation or a combination of operations based on your requirements, or all operations (*). For example, the action is "name/cos:GetService". Please note the distinction between uppercase and lowercase letters in English.
Required
Effect
allow or deny.
Required
Resource
Specific data authorized to be operated on. It can be any resource, a resource in a path with a specified prefix, a resource in a specified absolute path, or a combination thereof.
Required
Condition
(Optional) Specifies the rule condition. For more information, see condition
Not required

Querying bucket policy

Note

This API is used to read the permission policy of a bucket.

Method prototype

CosResult GetBucketPolicy(const GetBucketPolicyReq& req, GetBucketPolicyResp* resp)

Sample Request

qcloud_cos::CosConfig config("./config.json");
qcloud_cos::CosAPI cos(config);

std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.

qcloud_cos::GetBucketPolicyReq req(bucket_name);
qcloud_cos::GetBucketPolicyResp resp;
qcloud_cos::CosResult result = cos.GetBucketPolicy(req, &resp);

// The call is successful. You can call the resp member functions to get the return content.
if (result.IsSucc()) {
// ...
} else {
// You can call CosResult's member functions to output error information, such as requestID, etc.
}

Response description

GetBucketPolicyResp provides the following member functions to obtain the Policy content returned by Get Bucket Policy.
std::string resp.GetPolicy()

Deleting a bucket policy

Note

This API (DELETE Bucket policy) is used to delete the permission policy of a bucket.

Method prototype

CosResult DeleteBucketPolicy(const DeleteBucketPolicyReq& req, DeleteBucketPolicyResp* resp)

Sample Request

qcloud_cos::CosConfig config("./config.json");
qcloud_cos::CosAPI cos(config);

std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.

qcloud_cos::DeleteBucketPolicyReq req(bucket_name);
qcloud_cos::DeleteBucketPolicyResp resp;
qcloud_cos::CosResult result = cos.DeleteBucketPolicy(req, &resp);

if (result.IsSucc()) {
// ...
} else {
// You can call CosResult's member functions to output error information, such as requestID, etc.
}