Repository navigation
Conversation
- verify redirect requests with V4SignVerifyWithLookup and V2SignVerifyWithLookup against the access keys this server was configured with, instead of the signature package's key store - fall back from V4 to V2 in the same order the gofakes3 auth middleware uses - restore the 302 download and 307 upload redirects: V4SignVerify and V2SignVerify read a package-wide key store that gofakes3 no longer writes, so every signed request failed that check and all traffic fell back to a server-side relay - bump github.com/OpenListTeam/gofakes3 to the commit providing V2SignVerifyWithLookup Co-authored-by: DeepSeek V4.1 Flash <noreply@deepseek.com> Generated-by: WorkBuddy 5.6.2 Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary / 摘要
S3 direct-transfer redirects (302 for downloads, 307 for direct uploads) have never triggered since the gofakes3 dependency moved to the per-instance key store.
s3RequestAuthorizedverified the request withsignature.V4SignVerify(andsignature.V2SignVerifyas the V2 fallback), both of which resolve the access key ID through the signature package's process-wide key store.gofakes3's
706a863movedWithV4Authkeys onto the instance and stopped writing that store. OpenList picked that up in #2813 (gofakes3v0.8.1) and #3071 (v0.8.2-0.20260911142347-cd3c030a83b4). From then on the check returnedInvalidAccessKeyIdfor every request whenever S3 access keys are configured, sodirectObjectURLanddirectUploadURLalways bailed out at the first condition and every object download fell back to a server-side relay.User-visible effect: the S3 endpoint silently stopped saving bandwidth. With
web_proxyoff and a storage that provides a direct link, downloads still ran through the OpenList server, with no error anywhere — the redirect path simply never fires.Root cause, in one line: the redirect path asked a key store that is always empty, so it always concluded the caller was unauthorized.
Changes
server/s3/redirect.gosignature.V4SignVerifyWithLookup, falling back tosignature.V2SignVerifyWithLookup, against the access keys this server was configured withs3RequestAuthorized's signature unchanged, soserver.go,redirectHandler,directObjectURLanddirectUploadURLare untouchedgo.modgithub.com/OpenListTeam/gofakes3to the commit that addsV2SignVerifyWithLookupV4 first, then V2 on
ErrUnsupportAlgorithm— the same order the gofakes3 auth middleware uses, so both paths agree on which requests are authorized.Compatibility
web_proxy,webdav_policyandproxy_typeskeep deciding whether a request may be redirected; this PR only makes the existing check able to pass.web_proxyoff and a storage that provides a direct link, an authorized S3 GET may now return 302 to the provider URL, and a direct upload may return 307. This is the behaviour introduced in feat(s3): support direct transfer redirects #2598 and observed for 139Yun in fix(s3): only skip direct redirect for true sub-resource queries #2604's manual test — that test predates the gofakes3 dependency switch, which is why it passed then. Administrators who need the S3 client to always receive the object body keep that by enabling Web Proxy on the storage, as the S3 guide already recommends for repository tools such as restic and rustic./ 此 PR 包含破坏性变更。
/ 此 PR 修改了公开 API、配置、存储格式或迁移行为。
/ 此 PR 需要关联仓库同步修改。
Related repository PRs / 关联仓库 PR:
Related Issues / 关联 Issue
Testing / 测试
go test ./...Checklist / 检查清单
/ 我已阅读 CONTRIBUTING。
/ 我确认此贡献符合仓库许可证、贡献规范和行为准则。
gofmt,go fmt, orprettierwhere applicable./ 我已按适用情况使用
gofmt、go fmt或prettier格式化变更代码。/ 我已在适用情况下请求相关维护者或代码所有者审查。
AI Disclosure / AI 使用声明
/ 此 PR 包含 AI 辅助内容。
Tools used / 使用工具:
Usage scope / 使用范围:
Code generation / 代码生成
Refactoring / 重构
Documentation / 文档
Tests / 测试
Translation / 翻译
Review assistance / 审查辅助
I have reviewed and validated all AI-assisted content included in this PR.
/ 我已审核并验证此 PR 中的所有 AI 辅助内容。
I have ensured that all AI-assisted commits include
Co-Authored-Byattribution./ 我已确保所有 AI 辅助提交都包含
Co-Authored-By归属信息。I can reproduce all AI-assisted content included in this PR without any AI tools.
/ 我可以在没有任何 AI 工具的情况下重现此 PR 中包含的所有 AI 辅助内容。