Please confirm the following
OpenList Version (required)
v4.2.6
Storage Driver Used (required)
115 open
Bug Description (required)
Opening this issue as requested by @jyxjjj in #3063 (comment) to track a possible remaining credential-expiration case after #3063 . I noticed a possible remaining credential-expiration case in retryExpiredToken: it refreshes credentials only for SecurityTokenExpired.
Alibaba Cloud's official Chinese OSS documentation, under InvalidAccessKeyId → "The OSS Access Key Id you provided does not exist in our records", identifies expired and invalidated temporary credentials as the cause. Its recommended solution is to obtain new temporary credentials.
My earlier PR #2575 documented SecurityTokenExpired followed by InvalidAccessKeyId during long Baidu → 115 uploads. If OSS returns InvalidAccessKeyId without a preceding SecurityTokenExpired, the current implementation does not trigger credential refresh. Subsequent part-upload retries would continue using the same credentials and could still fail.
Could this STS upload path also perform a bounded credential refresh and retry for the expiration-related InvalidAccessKeyId case? Since InvalidAccessKeyId can also indicate malformed or disabled keys, recovery should remain bounded and persistent errors should still be reported.
Logs (required)
No runtime logs are available for this report. This is a potential issue identified through source-code inspection and official documentation. A failure against a build containing #3063 has not been established.
Configuration File Content (required)
No configuration is attached. The evidence concerns credential-refresh error handling in drivers/115_open/upload.go; no deployment-specific reproduction is provided.
Reproduction Link (optional)
No response
AI Generated Content
AI model used
Codex (GPT-6)
Please confirm the following
I have read and agree to AGPL-3.0 Section 15 .
The program is provided "as is" without any warranties; you bear all risks of using it.
I have read and agree to AGPL-3.0 Section 16 .
The copyright holders and distributors are not liable for any damages resulting from the use or inability to use the program.
I confirm my description is clear, polite, helps developers quickly locate the issue, and complies with community rules.
I have read the OpenList documentation.
I confirm there are no duplicate issues or discussions.
I confirm this is an
OpenListissue, not caused by other reasons (such as network, dependencies, or operation).I believe this issue must be handled by
OpenListand not by a third party.I confirm this issue is not fixed in the latest version.
I have not read these checkboxes and therefore I just ticked them all, Please close this issue.
OpenList Version (required)
v4.2.6
Storage Driver Used (required)
115 open
Bug Description (required)
Opening this issue as requested by @jyxjjj in #3063 (comment) to track a possible remaining credential-expiration case after #3063 . I noticed a possible remaining credential-expiration case in
retryExpiredToken: it refreshes credentials only forSecurityTokenExpired.Alibaba Cloud's official Chinese OSS documentation, under InvalidAccessKeyId → "The OSS Access Key Id you provided does not exist in our records", identifies expired and invalidated temporary credentials as the cause. Its recommended solution is to obtain new temporary credentials.
My earlier PR #2575 documented
SecurityTokenExpiredfollowed byInvalidAccessKeyIdduring long Baidu → 115 uploads. If OSS returnsInvalidAccessKeyIdwithout a precedingSecurityTokenExpired, the current implementation does not trigger credential refresh. Subsequent part-upload retries would continue using the same credentials and could still fail.Could this STS upload path also perform a bounded credential refresh and retry for the expiration-related
InvalidAccessKeyIdcase? SinceInvalidAccessKeyIdcan also indicate malformed or disabled keys, recovery should remain bounded and persistent errors should still be reported.Logs (required)
No runtime logs are available for this report. This is a potential issue identified through source-code inspection and official documentation. A failure against a build containing #3063 has not been established.
Configuration File Content (required)
No configuration is attached. The evidence concerns credential-refresh error handling in drivers/115_open/upload.go; no deployment-specific reproduction is provided.
Reproduction Link (optional)
No response
AI Generated Content
AI model used
Codex (GPT-6)