aws / aws/aws-encryption-sdk-java
Allow to pass overrideConfiguration per request
- Vorherrschende Sprache
- Java
- Sterne
- 240
- Forks
- 125
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
### Security issue notifications
If you discover a potential security issue in the AWS Encryption SDK we ask that you notify AWS Security via our [vulnerability reporting page](https://aws.amazon.com/security/vulnerability-reporting/). Please do **not** create a public GitHub issue.
### Problem:
If i want to pass additional headers with Decrypt call (e.g Confused Deputy protection). I need to provide for each account own KmsClient. Instead in SdkV2 i can call .overrideConfiguration on request (you already use it for API_NAMESPACE).
If it will be possible to add .overrideConfiguration per call encrypt/decrypt i can use the same KmsClient for all accounts.
### Solution:
A description of the possible solution in terms of Encryption SDK architecture.
I see 2 options:
1. in AwsCrypto.decryptData/ecryptData provide additional argument with options
2. When construct KmsMasterKeyProvider ask for supplier for override. But there we need to send something in addition to identify context of request
### Out of scope:
Is there anything the solution will intentionally NOT address?
[//]: # (NOTE: If you believe this might be a security issue, please email aws-security@amazon.com instead of creating a GitHub issue. For more details, see the AWS Vulnerability Reporting Guide: https://aws.amazon.com/security/vulnerability-reporting/ )
Beitragsleitfaden
Rechercherichtung
Beginne damit, AwsCrypto.decryptData/encryptData und KmsMasterKeyProvider nachzuverfolgen, um zu verstehen, wo die per-request AWS SDK v2 overrideConfiguration einfließen könnte. Vergleiche die bestehende Verwendung von API_NAMESPACE mit den beiden vorgeschlagenen Optionen und definiere anschließend den erforderlichen Request-Kontext und die API-Struktur für encrypt und decrypt. Erledigt bedeutet, dass ein KmsClient Anfragen für mehrere Konten bedienen kann und zusätzliche Header den KMS-Aufruf erreichen.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- aws, java
- Bereich
- backend-api-design, security
- Issue-Typ
- Feature
- Schwierigkeit
- 5/5
- Geschätzter Aufwand
- Über eine Woche
- Aktivitätsstatus
- Veraltet
- Klarheit
- Muss geklärt werden
- Anfängerfreundlichkeit
- 25/100