Huang Kuan Hao created HDDS-16662:
-------------------------------------
Summary: Refactor shared HMAC-SHA256 logic in S3 signature
validators
Key: HDDS-16662
URL: https://issues.apache.org/jira/browse/HDDS-16662
Project: Apache Ozone
Issue Type: Sub-task
Components: S3
Reporter: Huang Kuan Hao
Assignee: Huang Kuan Hao
{{ChunksValidator}} and {{AWSV4AuthValidator}} each maintain a thread-local
{{Mac}} and implement HMAC-SHA256 initialization and signing. Share this logic
through {{ozone-common}} so request, chunk, and trailer verification use the
same primitive.
Keep signing-key derivation in OM and the previous-signature chain in
{{ChunksValidator}}. Preserve signature parsing, constant-time comparison in
{{ChunksValidator}}, and existing error responses.
Verify request authentication, consecutive signed chunks, signed trailers,
invalid signatures, and independent requests using different keys. The refactor
should preserve behavior and avoid sharing mutable request state.
Follow-up to HDDS-15142: https://github.com/apache/ozone/pull/11222
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]