mirror of
https://github.com/seaweedfs/seaweedfs.git
synced 2026-10-10 08:17:44 +02:00
filer: mint volume read JWT when proxying chunk reads (#10100)
The /?proxyChunkId= endpoint forwards the caller's headers to the volume server but never mints a read token, so proxied chunk reads return 401 once jwt.signing.read.key is configured. Generate a fileId-scoped volume token the same way the direct filer read path does, which fixes filer.sync, filer.backup, filerProxy mounts, the MQ broker and the upload gateway in one place.
This commit is contained in:
1 parent
7c9f61d4dc
commit
4d3e5d94a9
1 file changed
+5
@@ -97,6 +97,11 @@ func (fs *FilerServer) proxyToVolumeServer(w http.ResponseWriter, r *http.Reques
|
||||
}
|
||||
}
|
||||
|
||||
// volume server may require a read JWT even though the proxy endpoint doesn't
|
||||
if jwt := fs.maybeGetVolumeReadJwtAuthorizationToken(fileId); jwt != "" {
|
||||
proxyReq.Header.Set("Authorization", "BEARER "+jwt)
|
||||
}
|
||||
|
||||
proxyResponse, postErr := util_http.GetGlobalHttpClient().Do(proxyReq)
|
||||
|
||||
if postErr != nil {
|
||||
|
||||
Reference in new issue
Block a user