Feature Overview
This document provides an overview of APIs and SDK code samples related to bucket policies.
API | Operation | Description |
Setting a bucket policy | Sets a permission policy for the specified bucket | |
Querying bucket policy | Queries the permission policy of the specified bucket | |
Deleting a bucket policy | Deletes the permission policy of a specified bucket |
Setting a bucket policy
Note
This API (PUT Bucket policy) is used to write a permission policy for a bucket. The policy passed in this API will overwrite the existing one (if any) in the bucket.
Method prototype
CosResult PutBucketPolicy(const PutBucketPolicyReq& req, PutBucketPolicyResp* resp)
Sample Request
qcloud_cos::CosConfig config("./config.json");qcloud_cos::CosAPI cos(config);std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.qcloud_cos::PutBucketPolicyReq req(bucket_name);qcloud_cos::PutBucketPolicyResp resp;std::string bucket_policy =" {"" \"Statement\": ["" {"" \"Principal\": {"" \"qcs\": ["" \"qcs::cam::uin/100000000001:uin/100000000011\"" //Replace with the UIN of the account you want to grant permissions to" ]\n"" },\n"" \"Effect\": \"allow\","" \"Action\": ["" \"cos:PutObject\""" ],\n"" \"Resource\": [" // Change this to the allowed path prefix, which can be determined based on the user login status of your website. Examples: a.jpg, a/*, or * (Using the wildcard * poses significant security risks, please evaluate carefully before using)" \"qcs::cos:ap-guangzhou:uid/1250000000:examplebucket-1250000000/exampleobject\""" ],\n"" \"Condition\": {"" \"string_equal\": {"" \"cos:x-cos-mime-limit\": \"image/jpeg\""" }"" }"" }"" ],"" \"Version\": \"2.0\""" }";req.SetBody(bucket_policy);qcloud_cos::CosResult result = cos.PutBucketPolicy(req, &resp);if (result.IsSucc()) {// ...} else {// You can call CosResult's member functions to output error information, such as requestID, etc.}
Description
Parameter name | Description | Required |
Statement | Describes one or more permissions. | Required |
Version | The policy syntax version. The default is 2.0. | Required |
Principal | Specifies the entity to which the permission is granted. For more information, see Access Policy Language Overview | Required |
Action | Here, we refer to the COS API, where you can specify a single operation or a combination of operations based on your requirements, or all operations ( *). For example, the action is "name/cos:GetService". Please note the distinction between uppercase and lowercase letters in English. | Required |
Effect | allow or deny. | Required |
Resource | Specific data authorized to be operated on. It can be any resource, a resource in a path with a specified prefix, a resource in a specified absolute path, or a combination thereof. | Required |
Condition | (Optional) Specifies the rule condition. For more information, see condition | Not required |
Querying bucket policy
Note
This API is used to read the permission policy of a bucket.
Method prototype
CosResult GetBucketPolicy(const GetBucketPolicyReq& req, GetBucketPolicyResp* resp)
Sample Request
qcloud_cos::CosConfig config("./config.json");qcloud_cos::CosAPI cos(config);std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.qcloud_cos::GetBucketPolicyReq req(bucket_name);qcloud_cos::GetBucketPolicyResp resp;qcloud_cos::CosResult result = cos.GetBucketPolicy(req, &resp);// The call is successful. You can call the resp member functions to get the return content.if (result.IsSucc()) {// ...} else {// You can call CosResult's member functions to output error information, such as requestID, etc.}
Response description
GetBucketPolicyResp provides the following member functions to obtain the Policy content returned by Get Bucket Policy.std::string resp.GetPolicy()
Deleting a bucket policy
Note
This API (DELETE Bucket policy) is used to delete the permission policy of a bucket.
Method prototype
CosResult DeleteBucketPolicy(const DeleteBucketPolicyReq& req, DeleteBucketPolicyResp* resp)
Sample Request
qcloud_cos::CosConfig config("./config.json");qcloud_cos::CosAPI cos(config);std::string bucket_name = "examplebucket-1250000000"; // Replace it with your bucket name, which is in the format of BucketName-APPID (APPID is required). It can be viewed in the COS console at https://console.cloud.tencent.com/cos5/bucket.qcloud_cos::DeleteBucketPolicyReq req(bucket_name);qcloud_cos::DeleteBucketPolicyResp resp;qcloud_cos::CosResult result = cos.DeleteBucketPolicy(req, &resp);if (result.IsSucc()) {// ...} else {// You can call CosResult's member functions to output error information, such as requestID, etc.}