Opening this issue as requested by @jyxjjj in #3063 (comment) to track a possible remaining credential-expiration case after PR #3063. I noticed a possible remaining credential-expiration case in retryExpiredToken: it refreshes credentials only for SecurityTokenExpired.
Alibaba Cloud's official Chinese OSS documentation, under InvalidAccessKeyId → "The OSS Access Key Id you provided does not exist in our records", identifies expired and invalidated temporary credentials as the cause. Its recommended solution is to obtain new temporary credentials.
My earlier PR #2575 documented SecurityTokenExpired followed by InvalidAccessKeyId during long Baidu → 115 uploads. If OSS returns InvalidAccessKeyId without a preceding SecurityTokenExpired, the current implementation does not trigger credential refresh. Subsequent part-upload retries would continue using the same credentials and could still fail.
Could this STS upload path also perform a bounded credential refresh and retry for the expiration-related InvalidAccessKeyId case? Since InvalidAccessKeyId can also indicate malformed or disabled keys, recovery should remain bounded and persistent errors should still be reported.
Opening this issue as requested by @jyxjjj in #3063 (comment) to track a possible remaining credential-expiration case after PR #3063. I noticed a possible remaining credential-expiration case in
retryExpiredToken: it refreshes credentials only forSecurityTokenExpired.Alibaba Cloud's official Chinese OSS documentation, under InvalidAccessKeyId → "The OSS Access Key Id you provided does not exist in our records", identifies expired and invalidated temporary credentials as the cause. Its recommended solution is to obtain new temporary credentials.
My earlier PR #2575 documented
SecurityTokenExpiredfollowed byInvalidAccessKeyIdduring long Baidu → 115 uploads. If OSS returnsInvalidAccessKeyIdwithout a precedingSecurityTokenExpired, the current implementation does not trigger credential refresh. Subsequent part-upload retries would continue using the same credentials and could still fail.Could this STS upload path also perform a bounded credential refresh and retry for the expiration-related
InvalidAccessKeyIdcase? SinceInvalidAccessKeyIdcan also indicate malformed or disabled keys, recovery should remain bounded and persistent errors should still be reported.