aws / aws/amazon-s3-encryption-client-java
S3 Encryption client does throw an error for ranges greater than EOF
- Dominant language
- Java
- Stars
- 34
- Forks
- 21
- PR merge metrics
- No merged PRs in 30d
Description
### Problem:
I created a 64KB (65536 bytes) with S3Encryption client, and then did
```
S3Client s3Client = S3Client.builder().region(Region.EU_WEST_1).build();
S3Client s3ECClient = S3EncryptionClient.builder()
.kmsKeyId("xxx")
.wrappedClient(s3Client)
.wrappedAsyncClient(S3AsyncClient.builder().region(Region.EU_WEST_1).build())
.enableLegacyUnauthenticatedModes(true)
.build();
ResponseInputStream inputStream = s3ECClient.getObject(GetObjectRequest.builder()
.bucket("xxxx")
.key("xxxx")
.range("bytes=65536-65635").build());
```
So end of range `65635` is greater than EOF at `65536`. And no error was thrown.
Creating a file with a regular S3 client and then doing
```
ResponseInputStream inputStream = s3Client.getObject(GetObjectRequest.builder()
.bucket("xxx")
.key("xxxx")
.range("bytes=65536-65635").build());
```
throws `software.amazon.awssdk.services.s3.model.S3Exception: The requested range is not satisfiable (Service: S3, Status Code: 416, Request ID:` which is what we expect to be thrown in S3A.
### Solution:
S3 Encryption client should also throw a 416 range not satisfiable error.
Contributor guide
Research direction
Reproduce the range request through S3EncryptionClient.getObject using a 64KB object and bytes=65536-65635, then compare it with the regular S3Client behavior described in the issue. Trace how the encryption client handles the range response; done means the encrypted client reports a 416 range-not-satisfiable error for a range beyond EOF.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- aws, java
- Domain
- backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100