From 8001c3747d2cc653bb91e14b13f96b09160978f0 Mon Sep 17 00:00:00 2001 From: Chris Lu Date: Fri, 2 Jan 2026 20:53:39 -0800 Subject: [PATCH] fix(s3api): restore error return when access key not found Critical fix: The previous cleanup of sensitive logging inadvertently removed the error return statement when access key lookup fails. This caused the code to continue and call isCredentialExpired() on nil pointer, crashing the server. This explains EOF errors in CORS tests - server was panicking on requests with invalid keys. --- weed/s3api/auth_signature_v4.go | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/weed/s3api/auth_signature_v4.go b/weed/s3api/auth_signature_v4.go index 66a22c52c..32121511f 100644 --- a/weed/s3api/auth_signature_v4.go +++ b/weed/s3api/auth_signature_v4.go @@ -233,8 +233,7 @@ func (iam *IdentityAccessManagement) verifyV4Signature(r *http.Request, shouldCh glog.Warningf("InvalidAccessKeyId: attempted key '%s' not found. Available keys: %d, Auth enabled: %v", authInfo.AccessKey, len(availableKeys), iam.isAuthEnabled) - - } + return nil, nil, "", nil, s3err.ErrInvalidAccessKeyID } // Check service account expiration if cred.isCredentialExpired() {