From 4d3e5d94a9165879da571c308aa7d4c05c963ad1 Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Wed, 24 Jun 2026 19:21:57 -0700 Subject: [PATCH] filer: mint volume read JWT when proxying chunk reads (#10100) The /?proxyChunkId= endpoint forwards the caller's headers to the volume server but never mints a read token, so proxied chunk reads return 401 once jwt.signing.read.key is configured. Generate a fileId-scoped volume token the same way the direct filer read path does, which fixes filer.sync, filer.backup, filerProxy mounts, the MQ broker and the upload gateway in one place. --- weed/server/filer_server_handlers_proxy.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/weed/server/filer_server_handlers_proxy.go b/weed/server/filer_server_handlers_proxy.go index ae73c88b1..5126d421a 100644 --- a/weed/server/filer_server_handlers_proxy.go +++ b/weed/server/filer_server_handlers_proxy.go @@ -97,6 +97,11 @@ func (fs *FilerServer) proxyToVolumeServer(w http.ResponseWriter, r *http.Reques } } + // volume server may require a read JWT even though the proxy endpoint doesn't + if jwt := fs.maybeGetVolumeReadJwtAuthorizationToken(fileId); jwt != "" { + proxyReq.Header.Set("Authorization", "BEARER "+jwt) + } + proxyResponse, postErr := util_http.GetGlobalHttpClient().Do(proxyReq) if postErr != nil {