Huang Kuan Hao created HDDS-16662:
-------------------------------------

             Summary: Refactor shared HMAC-SHA256 logic in S3 signature 
validators
                 Key: HDDS-16662
                 URL: https://issues.apache.org/jira/browse/HDDS-16662
             Project: Apache Ozone
          Issue Type: Sub-task
          Components: S3
            Reporter: Huang Kuan Hao
            Assignee: Huang Kuan Hao


{{ChunksValidator}} and {{AWSV4AuthValidator}} each maintain a thread-local 
{{Mac}} and implement HMAC-SHA256 initialization and signing. Share this logic 
through {{ozone-common}} so request, chunk, and trailer verification use the 
same primitive.

Keep signing-key derivation in OM and the previous-signature chain in 
{{ChunksValidator}}. Preserve signature parsing, constant-time comparison in 
{{ChunksValidator}}, and existing error responses.

Verify request authentication, consecutive signed chunks, signed trailers, 
invalid signatures, and independent requests using different keys. The refactor 
should preserve behavior and avoid sharing mutable request state.

Follow-up to HDDS-15142: https://github.com/apache/ozone/pull/11222



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to