filer: mint volume read JWT when proxying chunk reads (#10100)

The /?proxyChunkId= endpoint forwards the caller's headers to the volume
server but never mints a read token, so proxied chunk reads return 401
once jwt.signing.read.key is configured. Generate a fileId-scoped volume
token the same way the direct filer read path does, which fixes
filer.sync, filer.backup, filerProxy mounts, the MQ broker and the upload
gateway in one place.
This commit is contained in:
Chris Lu authored and GitHub committed 2026-06-24 19:21:57 -07:00
1 parent 7c9f61d4dc
commit 4d3e5d94a9
1 file changed
+5
@@ -97,6 +97,11 @@ func (fs *FilerServer) proxyToVolumeServer(w http.ResponseWriter, r *http.Reques
}
}
// volume server may require a read JWT even though the proxy endpoint doesn't
if jwt := fs.maybeGetVolumeReadJwtAuthorizationToken(fileId); jwt != "" {
proxyReq.Header.Set("Authorization", "BEARER "+jwt)
}
proxyResponse, postErr := util_http.GetGlobalHttpClient().Do(proxyReq)
if postErr != nil {