mirror of
https://github.com/rustfs/rustfs.git
synced 2026-08-13 16:46:55 +00:00
chore(kms): import canonical internal encryption header constants (#5997)
kms/service.rs re-declared x-rustfs-encryption-key-id and x-rustfs-encryption-algorithm locally; the canonical owners live in rustfs-utils' object_encryption_keys module, which kms already transitively builds. Enable the http feature on the existing rustfs-utils dependency and import the two constants instead. The explanatory comment about why the algorithm header exists (SSE mode vs AEAD cipher round-trip) moves to the import site. No dependency-graph change (cargo tree -p rustfs-kms is unchanged apart from the feature) and no behavior change: the imported values are byte-identical. Ref rustfs/backlog#1833 (PR2).
This commit is contained in:
@@ -62,7 +62,7 @@ moka = { workspace = true, features = ["future"] }
|
||||
# Additional dependencies
|
||||
md-5 = { workspace = true }
|
||||
arc-swap = { workspace = true }
|
||||
rustfs-utils = { workspace = true }
|
||||
rustfs-utils = { workspace = true, features = ["http"] }
|
||||
rustfs-security-governance = { workspace = true }
|
||||
# `EventName` for KMS audit records. A leaf crate with no rustfs dependencies,
|
||||
# so the audit sink can live outside this crate without a second, drifting
|
||||
|
||||
@@ -81,16 +81,14 @@ fn request_encryption_context(context: &ObjectEncryptionContext) -> HashMap<Stri
|
||||
enc_context
|
||||
}
|
||||
|
||||
const INTERNAL_ENCRYPTION_KEY_ID_HEADER: &str = "x-rustfs-encryption-key-id";
|
||||
|
||||
/// Carries the AEAD algorithm the object was sealed with.
|
||||
///
|
||||
/// The S3 `x-amz-server-side-encryption` header records the *SSE mode*
|
||||
/// (`AES256` / `aws:kms`), not the cipher, so it cannot round-trip
|
||||
/// `ChaCha20Poly1305`. Without this header a ChaCha-sealed object comes back
|
||||
/// from the projection claiming `aws:kms` and is then opened with the wrong
|
||||
/// cipher.
|
||||
const INTERNAL_ENCRYPTION_ALGORITHM_HEADER: &str = "x-rustfs-encryption-algorithm";
|
||||
// Canonical owners of the internal encryption header names. Note on
|
||||
// INTERNAL_ENCRYPTION_ALGORITHM_HEADER: it carries the AEAD algorithm the
|
||||
// object was sealed with. The S3 `x-amz-server-side-encryption` header records
|
||||
// the *SSE mode* (`AES256` / `aws:kms`), not the cipher, so it cannot
|
||||
// round-trip `ChaCha20Poly1305`. Without this header a ChaCha-sealed object
|
||||
// comes back from the projection claiming `aws:kms` and is then opened with
|
||||
// the wrong cipher.
|
||||
use rustfs_utils::http::object_encryption_keys::{INTERNAL_ENCRYPTION_ALGORITHM_HEADER, INTERNAL_ENCRYPTION_KEY_ID_HEADER};
|
||||
|
||||
/// Result of object encryption
|
||||
#[derive(Debug, Clone)]
|
||||
|
||||
Reference in New Issue
Block a user