Compare commits

..

1 Commits

Author SHA1 Message Date
MadDogOwner 9147e1180f fix(s3): verify direct-transfer redirects with the instance access keys
- verify redirect requests with V4SignVerifyWithLookup and
  V2SignVerifyWithLookup against the access keys this server was configured
  with, instead of the signature package's key store
- fall back from V4 to V2 in the same order the gofakes3 auth middleware uses
- restore the 302 download and 307 upload redirects: V4SignVerify and
  V2SignVerify read a package-wide key store that gofakes3 no longer writes, so
  every signed request failed that check and all traffic fell back to a
  server-side relay
- bump github.com/OpenListTeam/gofakes3 to the commit providing
  V2SignVerifyWithLookup

Co-authored-by: DeepSeek V4.1 Flash <noreply@deepseek.com>
Generated-by: WorkBuddy 5.6.2
Signed-off-by: MadDogOwner <xiaoran@xrgzs.top>
2026-10-05 20:19:01 +08:00
3 changed files with 14 additions and 5 deletions
+1 -2
View File
@@ -10,7 +10,7 @@ require (
github.com/KarpelesLab/reflink v1.0.2
github.com/KirCute/zip v1.0.1
github.com/OpenListTeam/go-cache v0.1.0
github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4
github.com/OpenListTeam/gofakes3 v0.8.2
github.com/OpenListTeam/sftpd-openlist v1.0.1
github.com/OpenListTeam/tache v0.2.2
github.com/OpenListTeam/times v0.1.0
@@ -36,7 +36,6 @@ require (
github.com/dhowden/tag v0.0.0-20240417053706-3d75831295e8
github.com/disintegration/imaging v1.6.2
github.com/dlclark/regexp2 v1.12.0
github.com/dlclark/regexp2/v2 v2.8.4
github.com/dustinxie/ecc v0.0.0-20210511000915-959544187564
github.com/fclairamb/ftpserverlib v0.26.1-0.20250709223522-4a925d79caf6
github.com/foxxorcat/mopan-sdk-go v0.1.6
+2 -1
View File
@@ -53,6 +53,8 @@ github.com/OpenListTeam/go-cache v0.1.0 h1:eV2+FCP+rt+E4OCJqLUW7wGccWZNJMV0NNkh+
github.com/OpenListTeam/go-cache v0.1.0/go.mod h1:AHWjKhNK3LE4rorVdKyEALDHoeMnP8SjiNyfVlB+Pz4=
github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4 h1:Zy7/qg6aCS0OF/FPIoJh9/d0IgcIxpWRvn79ACm2R/Y=
github.com/OpenListTeam/gofakes3 v0.8.2-0.20260911142347-cd3c030a83b4/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U=
github.com/OpenListTeam/gofakes3 v0.8.2 h1:iR4B8WH0qWqWkzVTNSj2TgWw6kovTh2bV8TGMOFSnVI=
github.com/OpenListTeam/gofakes3 v0.8.2/go.mod h1:mS9Ywbo6aId6BrRzeYjOIOpK0QDVnMoKOIb0hpaQZ3U=
github.com/OpenListTeam/gsync v0.1.0 h1:ywzGybOvA3lW8K1BUjKZ2IUlT2FSlzPO4DOazfYXjcs=
github.com/OpenListTeam/gsync v0.1.0/go.mod h1:h/Rvv9aX/6CdW/7B8di3xK3xNV8dUg45Fehrd/ksZ9s=
github.com/OpenListTeam/reflink v0.0.0-20260701021214-78760eaeafef h1:67uGHancMF/abMrnkc8abVUWQiG73Wk5d8CKt3RzkFo=
@@ -341,7 +343,6 @@ github.com/disintegration/imaging v1.6.2 h1:w1LecBlG2Lnp8B3jk5zSuNqd7b4DXhcjwek1
github.com/disintegration/imaging v1.6.2/go.mod h1:44/5580QXChDfwIclfc/PCwrr44amcmDAg8hxG0Ewe4=
github.com/dlclark/regexp2 v1.12.0 h1:0j4c5qQmnC6XOWNjP3PIXURXN2gWx76rd3KvgdPkCz8=
github.com/dlclark/regexp2 v1.12.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
github.com/dlclark/regexp2/v2 v2.8.4/go.mod h1:avUrQvPaLz2DrFNHJF0taWAFFX2C1GMSSoeiqFjcBmU=
github.com/dsnet/compress v0.0.2-0.20230904184137-39efe44ab707 h1:2tV76y6Q9BB+NEBasnqvs7e49aEBFI8ejC89PSnWH+4=
github.com/dsnet/compress v0.0.2-0.20230904184137-39efe44ab707/go.mod h1:qssHWj60/X5sZFNxpG4HBPDHVqxNm4DfnCKgrbZOT+s=
github.com/dsnet/golib v0.0.0-20171103203638-1ea166775780/go.mod h1:Lj+Z9rebOhdfkVLjJ8T6VcRQv3SXugXy999NBtR9aFY=
+11 -2
View File
@@ -159,9 +159,18 @@ func s3RequestAuthorized(r *http.Request, authPairs map[string]string) bool {
if len(authPairs) == 0 {
return true
}
result := signature.V4SignVerify(r)
// Verify against the keys this server was configured with. V4SignVerify and
// V2SignVerify read the signature package's process-wide key store, which
// gofakes3 never writes (keys are kept per instance), so they always
// returned InvalidAccessKeyId and the 302/307 direct-transfer redirects
// never ran. Same V4-then-V2 order the auth middleware uses.
lookup := func(accessKey string) (string, bool) {
secret, ok := authPairs[accessKey]
return secret, ok
}
result := signature.V4SignVerifyWithLookup(r, lookup)
if result == signature.ErrUnsupportAlgorithm {
result = signature.V2SignVerify(r)
result = signature.V2SignVerifyWithLookup(r, lookup)
}
return result == signature.ErrNone
}