s3api: unify auth error handling across s3tables, iceberg and lance (#11381)

* s3api: fail closed when S3 Tables signature verification fails

* s3api: avoid nil Account dereference in S3 Tables auth log

* iceberg: return auth error instead of falling back to DefaultAllow

* lance: return auth error instead of falling back to DefaultAllow

* s3api: stop trusting client-supplied s3-account-id

The header is set by the server after successful authentication; scrub
inbound values alongside the other internal headers, and apply the same
admin guard to the header fallback branch of getAccountID that the
identity branch already has.

* test: cover table-catalog auth wrappers and principal resolution

* test: configure anonymous identity where catalog clients do not sign

* s3api: scrub s3-account-id after signature verification
This commit is contained in:
Chris Lu
2026-09-18 01:01:04 -07:00
committed by GitHub
parent f40687b34e
commit 0ca1c19821
10 changed files with 256 additions and 43 deletions
+3
View File
@@ -58,6 +58,9 @@ func WriteIAMConfig(dir, accessKey, secretKey string) (string, error) {
"Tagging",
"Write"
]
},
{
"name": "anonymous"
}
]
}`, accessKey, secretKey)