Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2dbc76fa36 |
@@ -75,7 +75,7 @@ or partial matching is supported.
|
|||||||
**Signed data format** (colon-separated):
|
**Signed data format** (colon-separated):
|
||||||
|
|
||||||
```
|
```
|
||||||
HMAC-SHA256(secret, "host:path:query:width:height:format:expiration:quality:fit")
|
HMAC-SHA256(secret, "host:path:query:width:height:format:expiration")
|
||||||
```
|
```
|
||||||
|
|
||||||
Where:
|
Where:
|
||||||
@@ -87,20 +87,13 @@ Where:
|
|||||||
- `height` — requested height in pixels, `0` for original
|
- `height` — requested height in pixels, `0` for original
|
||||||
- `format` — output format (jpeg, png, webp, avif, gif, orig)
|
- `format` — output format (jpeg, png, webp, avif, gif, orig)
|
||||||
- `expiration` — Unix timestamp when signature expires
|
- `expiration` — Unix timestamp when signature expires
|
||||||
- `quality` — output quality 1-100; sign `85` (the default) when the URL
|
|
||||||
omits the `q` parameter
|
|
||||||
- `fit` — fit mode (cover, contain, fill, inside, outside); sign `cover`
|
|
||||||
(the default) when the URL omits the `fit` parameter
|
|
||||||
|
|
||||||
The `q` and `fit` query parameters are covered by the signature. A URL
|
**Example:** resize
|
||||||
signed for one quality or fit value will not verify when replayed with a
|
`https://cdn.example.com/photos/cat.jpg` to 800x600 WebP with
|
||||||
different value; the effective (post-default) value is what is signed.
|
expiration 1704067200:
|
||||||
|
|
||||||
**Example:** resize `https://cdn.example.com/photos/cat.jpg` to 800x600
|
|
||||||
WebP with expiration 1704067200, default quality and fit:
|
|
||||||
|
|
||||||
1. Build input:
|
1. Build input:
|
||||||
`cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200:85:cover`
|
`cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200`
|
||||||
2. Compute HMAC-SHA256 with your secret key
|
2. Compute HMAC-SHA256 with your secret key
|
||||||
3. Base64URL-encode the result
|
3. Base64URL-encode the result
|
||||||
4. URL:
|
4. URL:
|
||||||
|
|||||||
@@ -452,8 +452,6 @@ func signatureRequest(req *ImageRequest) *signature.Request {
|
|||||||
Width: req.Size.Width,
|
Width: req.Size.Width,
|
||||||
Height: req.Size.Height,
|
Height: req.Size.Height,
|
||||||
Format: string(req.Format),
|
Format: string(req.Format),
|
||||||
Quality: req.Quality,
|
|
||||||
FitMode: string(req.FitMode),
|
|
||||||
Signature: req.Signature,
|
Signature: req.Signature,
|
||||||
Expires: req.Expires,
|
Expires: req.Expires,
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -1,122 +0,0 @@
|
|||||||
package signature_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"sneak.berlin/go/pixa/internal/signature"
|
|
||||||
)
|
|
||||||
|
|
||||||
// Fixed inputs for the quality/fit golden vectors. They are independent of
|
|
||||||
// the constants in golden_test.go so this file pins the current signed
|
|
||||||
// format on its own.
|
|
||||||
const (
|
|
||||||
qfSigningKey = "golden-test-key"
|
|
||||||
qfExpiresUnix int64 = 1704067200 // 2024-01-01T00:00:00Z
|
|
||||||
qfFitCover = "cover"
|
|
||||||
qfFitContain = "contain"
|
|
||||||
)
|
|
||||||
|
|
||||||
type qualityFitGoldenVector struct {
|
|
||||||
name string
|
|
||||||
req signature.Request
|
|
||||||
// wantSignature is the exact base64url (RFC 4648 URL-safe, padded)
|
|
||||||
// HMAC-SHA256 signature for the request with Expires set to
|
|
||||||
// qfExpiresUnix, under the signed format
|
|
||||||
// "host:path:query:width:height:format:expiration:quality:fit".
|
|
||||||
wantSignature string
|
|
||||||
}
|
|
||||||
|
|
||||||
// qualityFitGoldenVectors returns the known-answer vectors that pin quality
|
|
||||||
// and fit as signed components. The three default-value vectors use the
|
|
||||||
// effective quality (85) and fit ("cover") the handler applies when a URL
|
|
||||||
// omits q and fit, so they are the signatures real signed URLs must carry.
|
|
||||||
func qualityFitGoldenVectors() []qualityFitGoldenVector {
|
|
||||||
return []qualityFitGoldenVector{
|
|
||||||
{
|
|
||||||
name: "resized, default quality and fit",
|
|
||||||
req: signature.Request{
|
|
||||||
SourceHost: testHost,
|
|
||||||
SourcePath: testPath,
|
|
||||||
Width: 800,
|
|
||||||
Height: 600,
|
|
||||||
Format: testFormatWebP,
|
|
||||||
Quality: 85,
|
|
||||||
FitMode: qfFitCover,
|
|
||||||
},
|
|
||||||
// "cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200:85:cover"
|
|
||||||
wantSignature: "kdqeGoW2SX7qnaYtoB970wEnLydn0UnIgQYQLfAnjXQ=",
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "resized with query, default quality and fit",
|
|
||||||
req: signature.Request{
|
|
||||||
SourceHost: testHost,
|
|
||||||
SourcePath: testPath,
|
|
||||||
SourceQuery: "token=abc&v=2",
|
|
||||||
Width: 800,
|
|
||||||
Height: 600,
|
|
||||||
Format: testFormatWebP,
|
|
||||||
Quality: 85,
|
|
||||||
FitMode: qfFitCover,
|
|
||||||
},
|
|
||||||
// "cdn.example.com:/photos/cat.jpg:token=abc&v=2:800:600:webp:1704067200:85:cover"
|
|
||||||
wantSignature: "pKgVBOTd_Q_EikI7MNQLC9Q8Hurdxzyv3EIYvVhqc2I=",
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "original size, default quality and fit",
|
|
||||||
req: signature.Request{
|
|
||||||
SourceHost: testHost,
|
|
||||||
SourcePath: testPath,
|
|
||||||
Width: 0,
|
|
||||||
Height: 0,
|
|
||||||
Format: testFormatPNG,
|
|
||||||
Quality: 85,
|
|
||||||
FitMode: qfFitCover,
|
|
||||||
},
|
|
||||||
// "cdn.example.com:/photos/cat.jpg::0:0:png:1704067200:85:cover"
|
|
||||||
wantSignature: "6_rZ0yyVbGZRs8kG7n7HLgLi5Jt8vjiWQljIEL1jbIs=",
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "non-default quality and fit",
|
|
||||||
req: signature.Request{
|
|
||||||
SourceHost: testHost,
|
|
||||||
SourcePath: testPath,
|
|
||||||
Width: 800,
|
|
||||||
Height: 600,
|
|
||||||
Format: testFormatWebP,
|
|
||||||
Quality: 40,
|
|
||||||
FitMode: qfFitContain,
|
|
||||||
},
|
|
||||||
// "cdn.example.com:/photos/cat.jpg::800:600:webp:1704067200:40:contain"
|
|
||||||
wantSignature: "pGaXpPUbI3A7nMx-4T9bfq9bYWBNL0kY4bxlcv3g1F8=",
|
|
||||||
},
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSigner_GoldenVectors_QualityFit pins the exact HMAC-SHA256 signature
|
|
||||||
// output for requests that carry quality and fit as signed components. If
|
|
||||||
// these assertions fail, the signed byte format
|
|
||||||
// ("host:path:query:width:height:format:expiration:quality:fit") or the
|
|
||||||
// base64url encoding has changed, breaking every signature already issued.
|
|
||||||
// Update these constants only as part of a deliberate, documented signature
|
|
||||||
// format migration.
|
|
||||||
func TestSigner_GoldenVectors_QualityFit(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
signer := signature.New(qfSigningKey)
|
|
||||||
|
|
||||||
for _, tt := range qualityFitGoldenVectors() {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
signReq := tt.req
|
|
||||||
signReq.Expires = time.Unix(qfExpiresUnix, 0)
|
|
||||||
|
|
||||||
gotSignature := signer.Sign(&signReq)
|
|
||||||
if gotSignature != tt.wantSignature {
|
|
||||||
t.Errorf("Sign() = %q, want %q (signed byte format changed?)",
|
|
||||||
gotSignature, tt.wantSignature)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -1,68 +0,0 @@
|
|||||||
package signature_test
|
|
||||||
|
|
||||||
import (
|
|
||||||
"errors"
|
|
||||||
"testing"
|
|
||||||
"time"
|
|
||||||
|
|
||||||
"sneak.berlin/go/pixa/internal/signature"
|
|
||||||
)
|
|
||||||
|
|
||||||
// signedQualityFitRequest returns a request signed for quality 85 and fit
|
|
||||||
// mode "cover", the effective defaults the handler applies before
|
|
||||||
// verification.
|
|
||||||
func signedQualityFitRequest(signer *signature.Signer) *signature.Request {
|
|
||||||
req := &signature.Request{
|
|
||||||
SourceHost: testHost,
|
|
||||||
SourcePath: testPath,
|
|
||||||
Width: 800,
|
|
||||||
Height: 600,
|
|
||||||
Format: testFormatWebP,
|
|
||||||
Quality: 85,
|
|
||||||
FitMode: "cover",
|
|
||||||
Expires: time.Now().Add(1 * time.Hour),
|
|
||||||
}
|
|
||||||
req.Signature = signer.Sign(req)
|
|
||||||
|
|
||||||
return req
|
|
||||||
}
|
|
||||||
|
|
||||||
// TestSigner_Verify_QualityAndFitAreSigned proves that quality and fit are
|
|
||||||
// covered by the signature: a URL signed for one quality or fit mode must
|
|
||||||
// not verify when replayed with a different quality or fit mode. This is the
|
|
||||||
// amplification vector from the issue — one signed URL replayed across many
|
|
||||||
// quality and fit values yields many unauthorized cache entries and
|
|
||||||
// transcodes — so it must be rejected.
|
|
||||||
func TestSigner_Verify_QualityAndFitAreSigned(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
signer := signature.New("test-secret-key")
|
|
||||||
|
|
||||||
cases := []struct {
|
|
||||||
name string
|
|
||||||
tamper func(r *signature.Request)
|
|
||||||
}{
|
|
||||||
{
|
|
||||||
name: "replayed with different quality",
|
|
||||||
tamper: func(r *signature.Request) { r.Quality = 40 },
|
|
||||||
},
|
|
||||||
{
|
|
||||||
name: "replayed with different fit mode",
|
|
||||||
tamper: func(r *signature.Request) { r.FitMode = "contain" },
|
|
||||||
},
|
|
||||||
}
|
|
||||||
|
|
||||||
for _, tt := range cases {
|
|
||||||
t.Run(tt.name, func(t *testing.T) {
|
|
||||||
t.Parallel()
|
|
||||||
|
|
||||||
req := signedQualityFitRequest(signer)
|
|
||||||
tt.tamper(req)
|
|
||||||
|
|
||||||
err := signer.Verify(req)
|
|
||||||
if !errors.Is(err, signature.ErrInvalid) {
|
|
||||||
t.Errorf("Verify() = %v, want %v", err, signature.ErrInvalid)
|
|
||||||
}
|
|
||||||
})
|
|
||||||
}
|
|
||||||
}
|
|
||||||
@@ -37,15 +37,6 @@ type Request struct {
|
|||||||
Height int
|
Height int
|
||||||
// Format is the requested output format (e.g. "webp").
|
// Format is the requested output format (e.g. "webp").
|
||||||
Format string
|
Format string
|
||||||
// Quality is the requested output quality (1-100) for lossy formats.
|
|
||||||
// It is the effective value the request resolves to: callers pass the
|
|
||||||
// default quality when the request omits the parameter, so an omitted
|
|
||||||
// quality signs identically to that same value stated explicitly.
|
|
||||||
Quality int
|
|
||||||
// FitMode is how the image is fit into the requested dimensions
|
|
||||||
// (e.g. "cover"). Like Quality it is the effective value: callers pass
|
|
||||||
// the default fit mode when the request omits the parameter.
|
|
||||||
FitMode string
|
|
||||||
// Signature is the HMAC signature to verify.
|
// Signature is the HMAC signature to verify.
|
||||||
Signature string
|
Signature string
|
||||||
// Expires is the signature expiration timestamp.
|
// Expires is the signature expiration timestamp.
|
||||||
@@ -65,8 +56,7 @@ func New(secretKey string) *Signer {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Sign generates an HMAC-SHA256 signature for the given request.
|
// Sign generates an HMAC-SHA256 signature for the given request.
|
||||||
// The signature covers: host + path + query + width + height + format +
|
// The signature covers: host + path + query + width + height + format + expiration.
|
||||||
// expiration + quality + fit.
|
|
||||||
func (s *Signer) Sign(req *Request) string {
|
func (s *Signer) Sign(req *Request) string {
|
||||||
data := s.buildSignatureData(req)
|
data := s.buildSignatureData(req)
|
||||||
mac := hmac.New(sha256.New, s.secretKey)
|
mac := hmac.New(sha256.New, s.secretKey)
|
||||||
@@ -78,8 +68,7 @@ func (s *Signer) Sign(req *Request) string {
|
|||||||
|
|
||||||
// Verify checks if the signature on the request is valid and not expired.
|
// Verify checks if the signature on the request is valid and not expired.
|
||||||
// Signatures are exact-match only: every component of the signed data
|
// Signatures are exact-match only: every component of the signed data
|
||||||
// (host, path, query, dimensions, format, expiration, quality, fit) must
|
// (host, path, query, dimensions, format, expiration) must match exactly.
|
||||||
// match exactly.
|
|
||||||
// No suffix matching, wildcard matching, or partial matching is supported.
|
// No suffix matching, wildcard matching, or partial matching is supported.
|
||||||
// A signature for "cdn.example.com" will NOT verify for "example.com" or
|
// A signature for "cdn.example.com" will NOT verify for "example.com" or
|
||||||
// "other.cdn.example.com", and vice versa.
|
// "other.cdn.example.com", and vice versa.
|
||||||
@@ -153,13 +142,11 @@ func (s *Signer) GenerateSignedURL(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// buildSignatureData creates the string to be signed.
|
// buildSignatureData creates the string to be signed.
|
||||||
// Format: "host:path:query:width:height:format:expiration:quality:fit"
|
// Format: "host:path:query:width:height:format:expiration"
|
||||||
// All components are used verbatim (exact match). No normalization,
|
// All components are used verbatim (exact match). No normalization,
|
||||||
// suffix matching, or wildcard expansion is performed. Quality and fit
|
// suffix matching, or wildcard expansion is performed.
|
||||||
// are the effective transform values, so replaying a signed URL with a
|
|
||||||
// different quality or fit mode fails verification.
|
|
||||||
func (s *Signer) buildSignatureData(req *Request) string {
|
func (s *Signer) buildSignatureData(req *Request) string {
|
||||||
return fmt.Sprintf("%s:%s:%s:%d:%d:%s:%d:%d:%s",
|
return fmt.Sprintf("%s:%s:%s:%d:%d:%s:%d",
|
||||||
req.SourceHost,
|
req.SourceHost,
|
||||||
req.SourcePath,
|
req.SourcePath,
|
||||||
req.SourceQuery,
|
req.SourceQuery,
|
||||||
@@ -167,8 +154,6 @@ func (s *Signer) buildSignatureData(req *Request) string {
|
|||||||
req.Height,
|
req.Height,
|
||||||
req.Format,
|
req.Format,
|
||||||
req.Expires.Unix(),
|
req.Expires.Unix(),
|
||||||
req.Quality,
|
|
||||||
req.FitMode,
|
|
||||||
)
|
)
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+5
-1
@@ -17,7 +17,11 @@ run_with_cgo_deps() {
|
|||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
echo "Running tests..."
|
echo "Running tests..."
|
||||||
run_with_cgo_deps "CGO_ENABLED=1 go test -timeout 30s -race -v ./..."
|
# Run without -v first for clean output on success; on failure rerun
|
||||||
|
# with -v for full diagnostics, then exit non-zero (REPO_POLICIES.md
|
||||||
|
# conditional-verbose-rerun pattern). The first run already proved the
|
||||||
|
# tests broken, so the build fails even if the rerun happens to pass.
|
||||||
|
run_with_cgo_deps "CGO_ENABLED=1 go test -timeout 30s -race -cover ./... || { echo '--- Rerunning with -v for details ---'; CGO_ENABLED=1 go test -timeout 30s -race -v ./...; exit 1; }"
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user