Files
seaweedfs/weed/s3api
Chris Lu e088b494f6 fix(s3): replace mock presigned URL signature with HMAC-SHA256 signing
The presigned URL manager used generateMockSignature() which computed a
plain SHA256 hash without any secret key, allowing anyone to forge valid
presigned URL signatures.

Replace with signPresignedURL() that implements AWS SigV4 HMAC-SHA256
signing: derives a signing key via the standard HMAC chain
(date -> region -> service -> aws4_request), then signs a canonical
request built from the HTTP method, path, query, and expiration.

NewS3PresignedURLManager now accepts an optional signingKey variadic
parameter for backward compatibility.
2026-04-01 21:28:32 -07:00
..
2026-01-28 14:34:07 -08:00
2024-07-04 11:00:41 -07:00
2026-02-20 18:40:47 -08:00
2024-07-04 11:00:41 -07:00
2025-08-21 08:28:07 -07:00
2025-08-21 08:28:07 -07:00
2025-08-22 01:15:42 -07:00
2025-10-27 23:04:55 -07:00
2025-10-27 23:04:55 -07:00
2025-10-13 18:05:17 -07:00
2025-07-28 02:49:43 -07:00

see https://blog.aqwari.net/xml-schema-go/

1. go get aqwari.net/xml/cmd/xsdgen
2. Add EncodingType element for ListBucketResult in AmazonS3.xsd
3. xsdgen -o s3api_xsd_generated.go -pkg s3api AmazonS3.xsd
4. Remove empty Grantee struct in s3api_xsd_generated.go
5. Remove xmlns: sed s'/http:\/\/s3.amazonaws.com\/doc\/2006-03-01\/\ //' s3api_xsd_generated.go