aws / aws/aws-sdk-java-v2

sigv4 for Lattice unsigned-payload not supported for http requests

Offen
#5,103 1 Kommentar 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
feature-request p2 service-api
Vorherrschende Sprache
Java
Sterne
2.6k
Forks
1k
Ø Merge
2 T. 9 Std.
Gemergte PRs (30 T.)
51

Beschreibung

### Describe the bug

When making http (not https) requests to lattice, the payload will always be signed because the signing logic will always sign the body when the protocol http and a streaming body is present. This isn't compatible with VPC Lattice which allows for GRPC over HTTP.

### Expected Behavior

requests to be signed with 'x-amz-content-sha256: UNSIGNED-PAYLOAD'

### Current Behavior

-H 'x-amz-content-sha256: STREAMING-AWS4-ECDSA-P256-SHA256-PAYLOAD'

### Reproduction Steps

```
SdkHttpFullRequest request = SdkHttpFullRequest.builder()
.protocol("HTTP")
.host("test.com:80")
.method(SdkHttpMethod.POST)
.encodedPath("/_status")
.contentStreamProvider(() - > new ByteArrayInputStream("{\"status\":\"ok\"}".getBytes()))
.build();

ExecutionAttributes ea = new ExecutionAttributes();
ea.putAttribute(AwsSignerExecutionAttribute.AWS_CREDENTIALS, EnvironmentVariableCredentialsProvider.create().resolveCredentials());
ea.putAttribute(AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME, "vpc-lattice-svcs");
ea.putAttribute(S3SignerExecutionAttribute.ENABLE_PAYLOAD_SIGNING, false);

AwsCrtS3V4aSigner signer = AwsCrtS3V4aSigner.builder()
.defaultRegionScope(RegionScope.GLOBAL)
.build();

var signedRequest = signer.sign(request, ea);
for (var header: signedRequest.headers().entrySet()) {
for (var value: header.getValue()) {
System.out.print(" -H '" + header.getKey() + ": " + value + "'\n");
}
}
```

will print out some headers, notably

```
-H 'x-amz-content-sha256: STREAMING-AWS4-ECDSA-P256-SHA256-PAYLOAD'
```

### Possible Solution

In DefaultAwsCrtS3V4aSigner (and other signers) change logic to something like

```
private boolean shouldSignPayload(SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
Boolean payloadSigning =
executionAttributes.getAttribute(S3SignerExecutionAttribute.ENABLE_PAYLOAD_SIGNING);
if (payloadSigning != null && !booleanValue(payloadSigning)) {
return false;
}

if (!request.protocol().equals("https") && request.contentStreamProvider().isPresent()) {
return true;
}
```

to prioritize user choice

or look at `AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME == vpc-lattice-svcs` to decide if the request body should be signed.

### Additional Information/Context

_No response_

### AWS Java SDK version used

2.21.20

### JDK version used

21.0.2

### Operating System and version

macOS 14.4.1

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie mit der Reproduktion im Issue und lesen Sie die Payload-Signing-Logik in DefaultAwsCrtS3V4aSigner. Vergleichen Sie anschließend das Verhalten mit den anderen genannten Signern. Das erwartete Ergebnis ist eine HTTP-Anfrage, die mit `x-amz-content-sha256: UNSIGNED-PAYLOAD` signiert ist, wenn Payload Signing deaktiviert ist; stellen Sie sicher, dass die Änderung das HTTPS-Verhalten nicht verändert. Im Issue werden keine Testdateien genannt. Suchen Sie daher die relevanten Signer-Tests und führen Sie sie aus.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
aws, java
Bereich
backend-api-design, networking
Issue-Typ
Bug
Schwierigkeit
4/5
Geschätzter Aufwand
3-5 Tage
Aktivitätsstatus
Veraltet
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
35/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.