1
votes

Is there a way to configure a container so that for a certain user it allows creation of new objects, but denies deletion and modification of existing objects?

My case is that I provide a web service which receives and serves files using remote openstack swift storage and I want that in case of a credential compromise at the web service level, the person who gains access to those credentials would not be able to alter existing files.

1
This question appears to be off-topic as it's about setting up and configuring a product, and not a programming question. - nos
Then consider doing it programmatically, using the REST API provided... That's how I intend to do it, anyway, if such configurations exist. - Mihai Caracostea
Then please add such relevant info to your question, as it stands now, this is just a support question for some 3. party software. - nos

1 Answers

0
votes

To the best of my knowledge, I don't think it is possible to deny any user from deleting or updating existing objects of the same container, when one can upload objects using credentials.

But you can write a java API and expose it to the user to upload file and internally you can upload the file using the set of credentials. Do not expose the functions that the user is not supposed to do (delete/update etc). You can have all your creds and everything in the code (better to be encrypted). This way you may achieve what you want. But this is a work around.