mirror of
https://github.com/curl/curl.git
synced 2026-07-28 20:53:06 +03:00
aws_sigv4: fix header computation
Handle canonical headers and signed headers creation as explained here: https://docs.aws.amazon.com/general/latest/gr/sigv4-create-canonical-request.html The algo tells that signed and canonical must contain at last host and x-amz-date. So we check whatever thoses are present in the curl http headers list. If they are, we use the one enter by curl user, otherwise we generate them. then we to lower, and remove space from each http headers plus host and x-amz-date, then sort them all by alphabetical order. This patch also fix a bug with host header, which was ignoring the port. Closes #7966
This commit is contained in:
parent
3c0050d13e
commit
29c4aa00a1
17 changed files with 535 additions and 224 deletions
|
|
@ -225,6 +225,7 @@ test1916 test1917 test1918 test1919 \
|
|||
\
|
||||
test1933 test1934 test1935 test1936 test1937 test1938 test1939 test1940 \
|
||||
test1941 test1942 test1943 test1944 test1945 test1946 test1947 test1948 \
|
||||
test1955 \
|
||||
\
|
||||
test2000 test2001 test2002 test2003 test2004 \
|
||||
\
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ lib%TESTNUMBER
|
|||
</tool>
|
||||
|
||||
<command>
|
||||
http://xxx:yyy@%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
||||
http://xxx:yyy@127.0.0.1:9000/%TESTNUMBER/testapi/test 127.0.0.1:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
|
|
@ -60,8 +60,8 @@ http://xxx:yyy@%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
|||
</strip>
|
||||
<protocol>
|
||||
GET /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: %HOSTIP:%HTTPPORT
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/0/127/xxx4_request, SignedHeaders=content-type;host;x-xxx-date, Signature=d2c2dff48c59ec49dc31ef94f18c5dc1ac3eae2a70d51633a4342dadc0683664
|
||||
Host: 127.0.0.1:9000
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/0/127/xxx4_request, SignedHeaders=content-type;host;x-xxx-date, Signature=3d8e00a02e437211a596143dcd590fcc805b731365c68f7f48951ea6eda39c4f
|
||||
X-Xxx-Date: 19700101T000000Z
|
||||
|
||||
</protocol>
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ lib%TESTNUMBER
|
|||
</tool>
|
||||
|
||||
<command>
|
||||
http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
||||
http://127.0.0.1:9000/%TESTNUMBER/testapi/test 127.0.0.1:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
|
|
@ -60,8 +60,8 @@ http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
|||
</strip>
|
||||
<protocol>
|
||||
GET /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: %HOSTIP:%HTTPPORT
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/0/127/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=938937ca7da6bb3dbf15e30928265ec6f061532d035d2afda92fa7cb10feb196
|
||||
Host: 127.0.0.1:9000
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/0/127/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=cf8dc9a4af903a1a9bb1385d8e2366d780afb501e266436598438395e502d58c
|
||||
X-Yyy-Date: 19700101T000000Z
|
||||
|
||||
</protocol>
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ lib%TESTNUMBER
|
|||
</tool>
|
||||
|
||||
<command>
|
||||
http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
||||
http://127.0.0.1:9000/%TESTNUMBER/testapi/test 127.0.0.1:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
|
|
@ -60,8 +60,8 @@ http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
|||
</strip>
|
||||
<protocol>
|
||||
GET /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: %HOSTIP:%HTTPPORT
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/rrr/127/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=240750deb9263d4c8ece71c016f3919b56e518249390ef075740f94ef8df846f
|
||||
Host: 127.0.0.1:9000
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/rrr/127/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=a0b11b97b54689428d4188b788ed32865d607822d85d3e91cf06141f479dac0b
|
||||
X-Yyy-Date: 19700101T000000Z
|
||||
|
||||
</protocol>
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ lib%TESTNUMBER
|
|||
</tool>
|
||||
|
||||
<command>
|
||||
http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
||||
http://127.0.0.1:9000/%TESTNUMBER/testapi/test 127.0.0.1:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
|
|
@ -60,8 +60,8 @@ http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
|||
</strip>
|
||||
<protocol>
|
||||
GET /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: %HOSTIP:%HTTPPORT
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/rrr/sss/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=f32cf87977cea5d3274b524b53e5d28f4aac54c372f710ae0cc3a9ececaf169f
|
||||
Host: 127.0.0.1:9000
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/rrr/sss/xxx4_request, SignedHeaders=content-type;host;x-yyy-date, Signature=026b713d76b0789bd224c5e41322f74eed088f8a22fd15183ca68376c575c5b0
|
||||
X-Yyy-Date: 19700101T000000Z
|
||||
|
||||
</protocol>
|
||||
|
|
|
|||
|
|
@ -48,7 +48,7 @@ lib%TESTNUMBER
|
|||
</tool>
|
||||
|
||||
<command>
|
||||
http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
||||
http://127.0.0.1:9000/%TESTNUMBER/testapi/test 127.0.0.1:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
|
|
@ -61,8 +61,8 @@ http://%HOSTIP:%HTTPPORT/%TESTNUMBER/testapi/test
|
|||
</strip>
|
||||
<protocol nonewline="yes">
|
||||
POST /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: %HOSTIP:%HTTPPORT
|
||||
Authorization: PROVIDER14-HMAC-SHA256 Credential=keyId/19700101/region/service/provider14_request, SignedHeaders=content-type;host;x-provider2-date, Signature=391e410177d0e9ee80728082446ef69d6b29157fe71f8b4805fce7c186fd956d
|
||||
Host: 127.0.0.1:9000
|
||||
Authorization: PROVIDER14-HMAC-SHA256 Credential=keyId/19700101/region/service/provider14_request, SignedHeaders=content-type;host;x-provider2-date, Signature=4928ccf97a9e71fe27f91db5a3b3c943b6080d25e6f4df8593d4c38e7d1e849b
|
||||
X-Provider2-Date: 19700101T000000Z
|
||||
Content-Length: 8
|
||||
|
||||
|
|
|
|||
Binary file not shown.
75
tests/data/test1955
Normal file
75
tests/data/test1955
Normal file
|
|
@ -0,0 +1,75 @@
|
|||
<testcase>
|
||||
<info>
|
||||
<keywords>
|
||||
HTTP
|
||||
CURLOPT_AWS_SIGV4
|
||||
</keywords>
|
||||
</info>
|
||||
|
||||
# Server-side
|
||||
<reply>
|
||||
<data nocheck="yes">
|
||||
HTTP/1.1 302 OK
|
||||
Date: Thu, 09 Nov 2010 14:49:00 GMT
|
||||
Server: test-server/fake
|
||||
Content-Type: text/html
|
||||
Content-Length: 0
|
||||
Location: /%TESTNUMBER0002
|
||||
|
||||
</data>
|
||||
<data2>
|
||||
HTTP/1.1 200 OK
|
||||
Date: Thu, 09 Nov 2010 14:49:00 GMT
|
||||
Server: test-server/fake
|
||||
Content-Type: text/html
|
||||
Content-Length: 0
|
||||
|
||||
</data2>
|
||||
</reply>
|
||||
|
||||
# Client-side
|
||||
<client>
|
||||
<server>
|
||||
http
|
||||
</server>
|
||||
# this relies on the debug feature which allow to set the time
|
||||
<features>
|
||||
SSL
|
||||
debug
|
||||
crypto
|
||||
</features>
|
||||
<setenv>
|
||||
CURL_FORCEHOST=1
|
||||
</setenv>
|
||||
|
||||
<name>
|
||||
HTTP AWS_SIGV4 with X-Xxx-Content-Sha256
|
||||
</name>
|
||||
<tool>
|
||||
lib%TESTNUMBER
|
||||
</tool>
|
||||
|
||||
<command>
|
||||
http://exam.ple.com:9000/%TESTNUMBER/testapi/test exam.ple.com:9000:%HOSTIP:%HTTPPORT
|
||||
</command>
|
||||
</client>
|
||||
|
||||
# Verify data after the test has been "shot"
|
||||
<verify>
|
||||
<strip>
|
||||
^User-Agent:.*
|
||||
^Content-Type:.*
|
||||
^Accept:.*
|
||||
</strip>
|
||||
<protocol>
|
||||
GET /%TESTNUMBER/testapi/test HTTP/1.1
|
||||
Host: exam.ple.com:9000
|
||||
Authorization: XXX4-HMAC-SHA256 Credential=xxx/19700101/ple/exam/xxx4_request, SignedHeaders=content-type;host;tesmixcase;test0;test1;test2;test_space;x-xxx-date, Signature=819251feec8de52dfaa992320241f23d27cefa979c93e039ae7df03ac486ed16
|
||||
X-Xxx-Date: 19700101T000000Z
|
||||
test2: 1234
|
||||
test_space: t s m end
|
||||
tesMixCase: MixCase
|
||||
|
||||
</protocol>
|
||||
</verify>
|
||||
</testcase>
|
||||
Loading…
Add table
Add a link
Reference in a new issue