The presigned URL manager used generateMockSignature() which computed a
plain SHA256 hash without any secret key, allowing anyone to forge valid
presigned URL signatures.
Replace with signPresignedURL() that implements AWS SigV4 HMAC-SHA256
signing: derives a signing key via the standard HMAC chain
(date -> region -> service -> aws4_request), then signs a canonical
request built from the HTTP method, path, query, and expiration.
NewS3PresignedURLManager now accepts an optional signingKey variadic
parameter for backward compatibility.