Skip to content

fix(s3): sign content type for direct uploads - #3152

Open
mumingluan wants to merge 1 commit into
OpenListTeam:mainfrom
mumingluan:codex/s3-direct-upload-content-type
Open

mumingluan wants to merge 1 commit into
OpenListTeam:mainfrom
mumingluan:codex/s3-direct-upload-content-type

Conversation

@mumingluan

Copy link
Copy Markdown

Summary / 摘要

S3 direct uploads can return 403 AccessDenied on Ceph RGW when the browser sends a Content-Type header that is absent from the presigned URL's signed headers. The current driver signs only host.

Determine the MIME type using utils.GetMimeType, include it in the presigned PutObject request, and return the same Content-Type through HttpDirectUploadInfo.Headers. The frontend already applies these headers, so the uploaded MIME type matches the signature. Unknown extensions use application/octet-stream.

  • This PR has breaking changes.
  • This PR changes public API, config, storage format, or migration behavior.
    The existing optional headers response field is now populated with Content-Type for S3 direct uploads.
  • This PR requires corresponding changes in related repositories.

Testing / 测试

  • go test ./drivers/s3 -count=1 passed on Windows with Go 1.27.1.
  • git diff --check passed.
  • Manual validation against a Ceph-backed Rainyun S3 endpoint:
    • The original host-only signature returned 403 AccessDenied for a 1 KiB upload carrying Content-Type.
    • Presigned URLs and headers generated by the patched driver uploaded a 1 KiB APK and an 80 MiB file with an unknown extension successfully (200 OK).
    • HeadObject confirmed the stored sizes; temporary objects were deleted.
  • The full repository test suite was not run.

Checklist / 检查清单

  • I have read CONTRIBUTING, the license, and the code of conduct.
  • The change follows the repository contribution format and license.
  • The changed code is formatted with gofmt.
  • Human review before submission is complete.

AI Disclosure / AI 使用声明

  • This PR includes AI-assisted content.
  • Tools used: Codex.
  • Usage scope: diagnosis, code generation, manual validation, and PR wording.
  • Codex reviewed the diff and performed the validation described above. The human collaborator reported the issue, reviewed the proposed diff and PR description, and approved submission.
  • AI-assisted commits include the repository's required Co-authored-by attribution.

- Include the inferred MIME type in presigned PutObject requests
- Return the signed Content-Type header for frontend uploads

Co-authored-by: Codex <267193182+codex@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant