apache / apache/iceberg-python
S3 remote-signer Request header case duplicated
- Dominant language
- Python
- Stars
- 1.1k
- Forks
- 581
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 78
Description
### Apache Iceberg version
0.9.1 (latest release)
### Please describe the bug 🐞
request header **X-Amz-Content-SHA256** passed to the catalog service is **STREAMING-UNSIGNED-PAYLOAD-TRAILER**, and the header **X-Amz-Content-SHA256** returned by the catalog service is **UNSIGNED-PAYLOAD**
but the code logic will add both headers to the request (two X-Amz-Content-SHA256 header).
At this time, there is a possibility that the signature will not be passed (because the file storage service get **STREAMING-UNSIGNED-PAYLOAD-TRAILER** header, bug signed with **UNSIGNED-PAYLOAD**)
https://github.com/apache/iceberg-python/blob/52d810efb62e39ec6d8d6a2f4cd2cad8165e2d2c/pyiceberg/io/fsspec.py#L106-L121
line120-121 change to this can can solve the problem
```python
headers = HTTPHeaders()
for key, value in response_json["headers"].items():
headers.add_header(key, ", ".join(value))
request.headers = headers
```
### Willingness to contribute
- [x] I can contribute a fix for this bug independently
- [x] I would be willing to contribute a fix for this bug with guidance from the Iceberg community
- [ ] I cannot contribute a fix for this bug at this time
Contributor guide
No contributing guide indexed for this repository
Research direction
Start in pyiceberg/io/fsspec.py at lines 106-121 and trace how remote-signer response headers are copied into the request. Verify the change preserves the returned value without creating duplicate X-Amz-Content-SHA256 headers, then validate the resulting request and signing behavior with the relevant tests.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, python
- Domain
- cloud
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Clearly specified
- Newbie friendliness
- 68/100