aws / aws/amazon-s3-encryption-client-python

Make sure that the Docs clarify stream length is not always plaintext length

Open Beginner friendly
#164 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Python
Stars
2
Forks
4
PR merge metrics
No merged PRs in 30d

Description

The S3EC attempts to be as "transparent" as possible when applying client-side encryption. For example, PutObject/GetObject "just works". A deeper example is ranged gets - in Java, a ranged get request will apply to the plaintext range, the customer does not need to manually adjust the range to account for encrypted blocks.

However, there is one aspect that is seemingly not possible, which is contentLength of the GetObject stream. It includes the auth tag. Customers need to read the entire thing, which is their original message length + auth tag (or padding in the case of CBC).

This needs to be well-documented.

Contributor guide

Open the contributing guide

Research direction

Start with the documentation for S3EC GetObject streams and contentLength, then verify how authenticated encryption and CBC padding affect the bytes customers must read. Done means the docs clearly distinguish stream length from original plaintext length and explain that the complete stream must be read.

Written by the indexing model from the issue text.

Assessment

Tech stack
aws, python
Domain
cloud, documentation, security
Issue type
Documentation
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
68/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.