From 9147e1180fa0e8294cdfb67386ea0a418108f7e0 Mon Sep 17 00:00:00 2001 From: MadDogOwner Date: Mon, 5 Oct 2026 20:19:01 +0800 Subject: [PATCH] fix(s3): verify direct-transfer redirects with the instance access keys - verify redirect requests with V4SignVerifyWithLookup and V2SignVerifyWithLookup against the access keys this server was configured with, instead of the signature package's key store - fall back from V4 to V2 in the same order the gofakes3 auth middleware uses - restore the 302 download and 307 upload redirects: V4SignVerify and V2SignVerify read a package-wide key store that gofakes3 no longer writes, so every signed request failed that check and all traffic fell back to a server-side relay - bump github.com/OpenListTeam/gofakes3 to the commit providing V2SignVerifyWithLookup Co-authored-by: DeepSeek V4.1 Flash Generated-by: WorkBuddy 5.6.2 Signed-off-by: MadDogOwner --- go.mod | 2 +- go.sum | 2 ++ server/s3/redirect.go | 13 +++++++++++-- 3 files changed, 14 insertions(+), 3 deletions(-) diff --git a/go.mod b/go.mod index c8b089eb1..a9d79f874 100644 --- a/go.mod +++ b/go.mod @@ -10,7 +10,7 @@ require ( github.com/KarpelesLab/reflink v1.0.2 github.com/KirCute/zip v1.0.1 github.com/OpenListTeam/go-cache v0.1.0 - github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4 + github.com/OpenListTeam/gofakes3 v0.8.2 github.com/OpenListTeam/sftpd-openlist v1.0.1 github.com/OpenListTeam/tache v0.2.2 github.com/OpenListTeam/times v0.1.0 diff --git a/go.sum b/go.sum index 2f3b75f1a..dae5e47a5 100644 --- a/go.sum +++ b/go.sum @@ -53,6 +53,8 @@ github.com/OpenListTeam/go-cache v0.1.0 h1:eV2+FCP+rt+E4OCJqLUW7wGccWZNJMV0NNkh+ github.com/OpenListTeam/go-cache v0.1.0/go.mod h1:AHWjKhNK3LE4rorVdKyEALDHoeMnP8SjiNyfVlB+Pz4= github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4 h1:Zy7/qg6aCS0OF/FPIoJh9/d0IgcIxpWRvn79ACm2R/Y= github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U= +github.com/OpenListTeam/gofakes3 v0.8.2 h1:iR4B8WH0qWqWkzVTNSj2TgWw6kovTh2bV8TGMOFSnVI= +github.com/OpenListTeam/gofakes3 v0.8.2/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U= github.com/OpenListTeam/gsync v0.1.0 h1:ywzGybOvA3lW8K1BUjKZ2IUlT2FSlzPO4DOazfYXjcs= github.com/OpenListTeam/gsync v0.1.0/go.mod h1:h/Rvv9aX/6CdW/7B8di3xK3xNV8dUg45Fehrd/ksZ9s= github.com/OpenListTeam/reflink v0.0.0-20260701021214-78760eaeafef h1:67uGHancMF/abMrnkc8abVUWQiG73Wk5d8CKt3RzkFo= diff --git a/server/s3/redirect.go b/server/s3/redirect.go index 6d8d430bc..b61a9df13 100644 --- a/server/s3/redirect.go +++ b/server/s3/redirect.go @@ -159,9 +159,18 @@ func s3RequestAuthorized(r *http.Request, authPairs map[string]string) bool { if len(authPairs) == 0 { return true } - result := signature.V4SignVerify(r) + // Verify against the keys this server was configured with. V4SignVerify and + // V2SignVerify read the signature package's process-wide key store, which + // gofakes3 never writes (keys are kept per instance), so they always + // returned InvalidAccessKeyId and the 302/307 direct-transfer redirects + // never ran. Same V4-then-V2 order the auth middleware uses. + lookup := func(accessKey string) (string, bool) { + secret, ok := authPairs[accessKey] + return secret, ok + } + result := signature.V4SignVerifyWithLookup(r, lookup) if result == signature.ErrUnsupportAlgorithm { - result = signature.V2SignVerify(r) + result = signature.V2SignVerifyWithLookup(r, lookup) } return result == signature.ErrNone }