aws / aws/aws-encryption-sdk-python

DefaultCryptoMaterialsManager should raise an error if signer key is present in encryption context

Open
#135 2 comments 0 reactions 0 assignees View on GitHub
bug good first issue
Dominant language
Python
Stars
255
Forks
92
Avg merge
2d 17h
Merged PRs (30d)
2

Description

Because `DefaultCryptoMaterialsManager` adds a value to the encryption context if a signed algorithm suite is used, we need to throw an error if the requested encryption context already contains that key.

https://github.com/aws/aws-encryption-sdk-java/blob/eb8702e82759cca53eddc3b5f8423e74ec31aff1/src/main/java/com/amazonaws/encryptionsdk/DefaultCryptoMaterialsManager.java#L55-L58

Contributor guide

Open the contributing guide

Research direction

Start by locating DefaultCryptoMaterialsManager in the Python repository and compare its signed-algorithm encryption-context handling with the cited Java implementation at DefaultCryptoMaterialsManager.java#L55-L58. Confirm the expected behavior for a context that already contains the signer-key entry, then add or update coverage so the operation raises an error in that case.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cryptography
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.