Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[v16] Fix AWS SigV4 parsing #51044

Merged
merged 1 commit into from
Jan 15, 2025
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
23 changes: 16 additions & 7 deletions lib/utils/aws/aws.go
Original file line number Diff line number Diff line change
Expand Up @@ -94,24 +94,33 @@ type SigV4 struct {
}

// ParseSigV4 AWS SigV4 credentials string sections.
// AWS SigV4 header example:
// Authorization: AWS4-HMAC-SHA256
// Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request,
// AWS SigV4 header example below adds newlines for readability only - the real
// header must be a single continuous string with commas (and optional spaces)
// between the Credential, SignedHeaders, and Signature:
// Authorization: AWS4-HMAC-SHA256 Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request,
// SignedHeaders=host;range;x-amz-date,
// Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024
func ParseSigV4(header string) (*SigV4, error) {
if header == "" {
return nil, trace.BadParameter("empty AWS SigV4 header")
}
sectionParts := strings.Split(header, " ")
if !strings.HasPrefix(header, AmazonSigV4AuthorizationPrefix+" ") {
return nil, trace.BadParameter("missing AWS SigV4 authorization algorithm")
}
header = strings.TrimPrefix(header, AmazonSigV4AuthorizationPrefix+" ")

components := strings.Split(header, ",")
if len(components) != 3 {
return nil, trace.BadParameter("expected AWS SigV4 Authorization header with 3 comma-separated components but got %d", len(components))
}

m := make(map[string]string)
for _, v := range sectionParts {
kv := strings.Split(v, "=")
for _, v := range components {
kv := strings.Split(strings.Trim(v, " "), "=")
if len(kv) != 2 {
continue
}
m[kv[0]] = strings.TrimSuffix(kv[1], ",")
m[kv[0]] = kv[1]
}

authParts := strings.Split(m[credentialAuthHeaderElem], "/")
Expand Down
29 changes: 26 additions & 3 deletions lib/utils/aws/aws_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -50,19 +50,42 @@ func TestExtractCredFromAuthHeader(t *testing.T) {
wantErr: require.NoError,
},
{
name: "signed headers section missing",
input: "AWS4-HMAC-SHA256 Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request, Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
name: "valid header without spaces",
input: "AWS4-HMAC-SHA256 Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request,SignedHeaders=host;x-amz-content-sha256;x-amz-date,Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
expCred: &SigV4{
KeyID: "AKIAIOSFODNN7EXAMPLE",
Date: "20130524",
Region: "us-east-1",
Service: "s3",
Signature: "fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
SignedHeaders: []string{
"host",
"x-amz-content-sha256",
"x-amz-date",
},
},
wantErr: require.NoError,
},
{
name: "valid with empty list of signed headers",
input: "AWS4-HMAC-SHA256 Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request,SignedHeaders=,Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
expCred: &SigV4{
KeyID: "AKIAIOSFODNN7EXAMPLE",
Date: "20130524",
Region: "us-east-1",
Service: "s3",
Signature: "fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
SignedHeaders: nil,
},
wantErr: require.NoError,
},
{
name: "credential section missing",
name: "signed headers section missing",
input: "AWS4-HMAC-SHA256 Credential=AKIAIOSFODNN7EXAMPLE/20130524/us-east-1/s3/aws4_request, Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
wantErr: require.Error,
},
{
name: "credential section missing",
input: "AWS4-HMAC-SHA256 SignedHeaders=host;range;x-amz-date, Signature=fe5f80f77d5fa3beca038a248ff027d0445342fe2855ddc963176630326f1024",
wantErr: require.Error,
},
Expand Down
Loading