s3api: unify auth error handling across s3tables, iceberg and lance (#11381)

* s3api: fail closed when S3 Tables signature verification fails

* s3api: avoid nil Account dereference in S3 Tables auth log

* iceberg: return auth error instead of falling back to DefaultAllow

* lance: return auth error instead of falling back to DefaultAllow

* s3api: stop trusting client-supplied s3-account-id

The header is set by the server after successful authentication; scrub
inbound values alongside the other internal headers, and apply the same
admin guard to the header fallback branch of getAccountID that the
identity branch already has.

* test: cover table-catalog auth wrappers and principal resolution

* test: configure anonymous identity where catalog clients do not sign

* s3api: scrub s3-account-id after signature verification
This commit is contained in:
Chris Lu
2026-09-18 01:01:04 -07:00
committed by GitHub
parent f40687b34e
commit 0ca1c19821
10 changed files with 256 additions and 43 deletions
+7
View File
@@ -157,6 +157,12 @@ func newEnvironment() (*environment, error) {
}
func (env *environment) start() error {
// The catalog clients here do not sign, so anonymous access is configured explicitly.
iamConfigPath, err := testutil.WriteIAMConfig(env.dataDir, accessKey, secretKey)
if err != nil {
return fmt.Errorf("write IAM config: %w", err)
}
ctx, cancel := context.WithCancel(context.Background())
env.weedCancel = cancel
@@ -171,6 +177,7 @@ func (env *environment) start() error {
"-s3.port.grpc", fmt.Sprintf("%d", env.s3GrpcPort),
"-s3.port.iceberg", fmt.Sprintf("%d", env.icebergPort),
"-s3.port.lance", fmt.Sprintf("%d", env.lancePort),
"-s3.config", iamConfigPath,
"-ip.bind", "0.0.0.0",
"-dir", env.dataDir,
)
+3
View File
@@ -58,6 +58,9 @@ func WriteIAMConfig(dir, accessKey, secretKey string) (string, error) {
"Tagging",
"Write"
]
},
{
"name": "anonymous"
}
]
}`, accessKey, secretKey)