sigv4 for Lattice unsigned-payload not supported for http requests
- Vorherrschende Sprache
- Java
- Sterne
- 2.6k
- Forks
- 1k
- Ø Merge
- 2 T. 9 Std.
- Gemergte PRs (30 T.)
- 51
Beschreibung
### Describe the bug
When making http (not https) requests to lattice, the payload will always be signed because the signing logic will always sign the body when the protocol http and a streaming body is present. This isn't compatible with VPC Lattice which allows for GRPC over HTTP.
### Expected Behavior
requests to be signed with 'x-amz-content-sha256: UNSIGNED-PAYLOAD'
### Current Behavior
-H 'x-amz-content-sha256: STREAMING-AWS4-ECDSA-P256-SHA256-PAYLOAD'
### Reproduction Steps
```
SdkHttpFullRequest request = SdkHttpFullRequest.builder()
.protocol("HTTP")
.host("test.com:80")
.method(SdkHttpMethod.POST)
.encodedPath("/_status")
.contentStreamProvider(() - > new ByteArrayInputStream("{\"status\":\"ok\"}".getBytes()))
.build();
ExecutionAttributes ea = new ExecutionAttributes();
ea.putAttribute(AwsSignerExecutionAttribute.AWS_CREDENTIALS, EnvironmentVariableCredentialsProvider.create().resolveCredentials());
ea.putAttribute(AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME, "vpc-lattice-svcs");
ea.putAttribute(S3SignerExecutionAttribute.ENABLE_PAYLOAD_SIGNING, false);
AwsCrtS3V4aSigner signer = AwsCrtS3V4aSigner.builder()
.defaultRegionScope(RegionScope.GLOBAL)
.build();
var signedRequest = signer.sign(request, ea);
for (var header: signedRequest.headers().entrySet()) {
for (var value: header.getValue()) {
System.out.print(" -H '" + header.getKey() + ": " + value + "'\n");
}
}
```
will print out some headers, notably
```
-H 'x-amz-content-sha256: STREAMING-AWS4-ECDSA-P256-SHA256-PAYLOAD'
```
### Possible Solution
In DefaultAwsCrtS3V4aSigner (and other signers) change logic to something like
```
private boolean shouldSignPayload(SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {
Boolean payloadSigning =
executionAttributes.getAttribute(S3SignerExecutionAttribute.ENABLE_PAYLOAD_SIGNING);
if (payloadSigning != null && !booleanValue(payloadSigning)) {
return false;
}
if (!request.protocol().equals("https") && request.contentStreamProvider().isPresent()) {
return true;
}
```
to prioritize user choice
or look at `AwsSignerExecutionAttribute.SERVICE_SIGNING_NAME == vpc-lattice-svcs` to decide if the request body should be signed.
### Additional Information/Context
_No response_
### AWS Java SDK version used
2.21.20
### JDK version used
21.0.2
### Operating System and version
macOS 14.4.1
Beitragsleitfaden
Rechercherichtung
Beginnen Sie mit der Reproduktion im Issue und lesen Sie die Payload-Signing-Logik in DefaultAwsCrtS3V4aSigner. Vergleichen Sie anschließend das Verhalten mit den anderen genannten Signern. Das erwartete Ergebnis ist eine HTTP-Anfrage, die mit `x-amz-content-sha256: UNSIGNED-PAYLOAD` signiert ist, wenn Payload Signing deaktiviert ist; stellen Sie sicher, dass die Änderung das HTTPS-Verhalten nicht verändert. Im Issue werden keine Testdateien genannt. Suchen Sie daher die relevanten Signer-Tests und führen Sie sie aus.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- aws, java
- Bereich
- backend-api-design, networking
- Issue-Typ
- Bug
- Schwierigkeit
- 4/5
- Geschätzter Aufwand
- 3-5 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 35/100