check if metadata headers/url values are equal with signed headers (#17737)

This commit is contained in:
ruspaul013
2023-07-27 21:44:56 +03:00
committed by GitHub
parent 14ebd82dbd
commit 535f97ba61
3 changed files with 102 additions and 2 deletions
+25
View File
@@ -260,3 +260,28 @@ func signV4TrimAll(input string) string {
// unicode.IsSpace() internally here) to one space and return
return strings.Join(strings.Fields(input), " ")
}
// checkMetaHeaders will check if the metadata from header/url is the same with the one from signed headers
func checkMetaHeaders(signedHeadersMap http.Header, r *http.Request) APIErrorCode {
// check values from http header
for k, val := range r.Header {
if stringsHasPrefixFold(k, "X-Amz-Meta-") {
if signedHeadersMap.Get(k) == val[0] {
continue
}
return ErrUnsignedHeaders
}
}
// check values from url, if no http header
for k, val := range r.Form {
if stringsHasPrefixFold(k, "x-amz-meta-") {
if signedHeadersMap.Get(http.CanonicalHeaderKey(k)) == val[0] {
continue
}
return ErrUnsignedHeaders
}
}
return ErrNone
}