public inbox for pbs-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Christian Ebner <c.ebner@proxmox.com>
To: pbs-devel@lists.proxmox.com
Subject: [PATCH proxmox 2/3] s3-client: factor out request signing and related header updates
Date: Wed,  7 Oct 2026 14:34:05 +0200	[thread overview]
Message-ID: <20261007123406.429342-3-c.ebner@proxmox.com> (raw)
In-Reply-To: <20261007123406.429342-1-c.ebner@proxmox.com>

Currently this is performed as part of the request prepare, but since
the request time might be to skewed on retries which can in principle
happen after a very long time, this needs to be updated on-demand.

Therefore move the required code into a dedicated reusable helper.

Signed-off-by: Christian Ebner <c.ebner@proxmox.com>
---
 proxmox-s3-client/src/client.rs | 26 +++++++++++++++++---------
 1 file changed, 17 insertions(+), 9 deletions(-)

diff --git a/proxmox-s3-client/src/client.rs b/proxmox-s3-client/src/client.rs
index 7903f090..631bbd0f 100644
--- a/proxmox-s3-client/src/client.rs
+++ b/proxmox-s3-client/src/client.rs
@@ -420,12 +420,6 @@ impl S3Client {
         let payload_digest = hex::encode(hasher.finish());
         let payload_len = contents.len();
 
-        let epoch = proxmox_time::epoch_i64();
-        let datetime = proxmox_time::strftime_utc(AWS_SIGN_V4_DATETIME_FORMAT, epoch)?;
-
-        request
-            .headers_mut()
-            .insert("x-amz-date", HeaderValue::from_str(&datetime)?);
         request
             .headers_mut()
             .insert("host", HeaderValue::from_str(&host_header)?);
@@ -452,13 +446,27 @@ impl S3Client {
                 .insert("Content-MD5", HeaderValue::from_str(&md5_digest)?);
         }
 
-        let signature = aws_sign_v4_signature(&request, &self.options, epoch, &payload_digest)?;
+        self.sign_request(&mut request, &payload_digest)?;
 
-        request
+        Ok(request)
+    }
+
+    /// Set or update the `x-amz-date` header to the current time, calculate the request signature
+    /// based on the provided payload digest and set or update the authorization header accordingly.
+    fn sign_request(&self, request: &mut Request<Body>, payload_digest: &str) -> Result<(), Error> {
+        let epoch = proxmox_time::epoch_i64();
+        let datetime = proxmox_time::strftime_utc(AWS_SIGN_V4_DATETIME_FORMAT, epoch)?;
+
+        let _prev_date = request
+            .headers_mut()
+            .insert("x-amz-date", HeaderValue::from_str(&datetime)?);
+
+        let signature = aws_sign_v4_signature(&request, &self.options, epoch, &payload_digest)?;
+        let _prev_auth = request
             .headers_mut()
             .insert(header::AUTHORIZATION, HeaderValue::from_str(&signature)?);
 
-        Ok(request)
+        Ok(())
     }
 
     /// Send API request to the configured endpoint using the inner https client.
-- 
2.47.3





  parent reply	other threads:[~2026-10-07 12:34 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-10-07 12:34 [PATCH proxmox 0/3] s3-client: fix request signing and update request time on retry Christian Ebner
2026-10-07 12:34 ` [PATCH proxmox 1/3] s3-client: fix header and query parameter sorting during aws sign v4 Christian Ebner
2026-10-07 12:34 ` Christian Ebner [this message]
2026-10-07 12:34 ` [PATCH proxmox 3/3] s3-client: update request time and signature on retries Christian Ebner

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261007123406.429342-3-c.ebner@proxmox.com \
    --to=c.ebner@proxmox.com \
    --cc=pbs-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal