diff --git a/go.mod b/go.mod index c8b089eb1..a9d79f874 100644 --- a/go.mod +++ b/go.mod @@ -10,7 +10,7 @@ require ( github.com/KarpelesLab/reflink v1.0.2 github.com/KirCute/zip v1.0.1 github.com/OpenListTeam/go-cache v0.1.0 - github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4 + github.com/OpenListTeam/gofakes3 v0.8.2 github.com/OpenListTeam/sftpd-openlist v1.0.1 github.com/OpenListTeam/tache v0.2.2 github.com/OpenListTeam/times v0.1.0 diff --git a/go.sum b/go.sum index 2f3b75f1a..dae5e47a5 100644 --- a/go.sum +++ b/go.sum @@ -53,6 +53,8 @@ github.com/OpenListTeam/go-cache v0.1.0 h1:eV2+FCP+rt+E4OCJqLUW7wGccWZNJMV0NNkh+ github.com/OpenListTeam/go-cache v0.1.0/go.mod h1:AHWjKhNK3LE4rorVdKyEALDHoeMnP8SjiNyfVlB+Pz4= github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4 h1:Zy7/qg6aCS0OF/FPIoJh9/d0IgcIxpWRvn79ACm2R/Y= github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U= +github.com/OpenListTeam/gofakes3 v0.8.2 h1:iR4B8WH0qWqWkzVTNSj2TgWw6kovTh2bV8TGMOFSnVI= +github.com/OpenListTeam/gofakes3 v0.8.2/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U= github.com/OpenListTeam/gsync v0.1.0 h1:ywzGybOvA3lW8K1BUjKZ2IUlT2FSlzPO4DOazfYXjcs= github.com/OpenListTeam/gsync v0.1.0/go.mod h1:h/Rvv9aX/6CdW/7B8di3xK3xNV8dUg45Fehrd/ksZ9s= github.com/OpenListTeam/reflink v0.0.0-20260701021214-78760eaeafef h1:67uGHancMF/abMrnkc8abVUWQiG73Wk5d8CKt3RzkFo= diff --git a/server/s3/redirect.go b/server/s3/redirect.go index 6d8d430bc..b61a9df13 100644 --- a/server/s3/redirect.go +++ b/server/s3/redirect.go @@ -159,9 +159,18 @@ func s3RequestAuthorized(r *http.Request, authPairs map[string]string) bool { if len(authPairs) == 0 { return true } - result := signature.V4SignVerify(r) + // Verify against the keys this server was configured with. V4SignVerify and + // V2SignVerify read the signature package's process-wide key store, which + // gofakes3 never writes (keys are kept per instance), so they always + // returned InvalidAccessKeyId and the 302/307 direct-transfer redirects + // never ran. Same V4-then-V2 order the auth middleware uses. + lookup := func(accessKey string) (string, bool) { + secret, ok := authPairs[accessKey] + return secret, ok + } + result := signature.V4SignVerifyWithLookup(r, lookup) if result == signature.ErrUnsupportAlgorithm { - result = signature.V2SignVerify(r) + result = signature.V2SignVerifyWithLookup(r, lookup) } return result == signature.ErrNone }