mirror of
https://github.com/rustfs/rustfs.git
synced 2026-09-08 04:58:12 +00:00
623e0aade0
A PutObject whose resolved SSE-KMS key (request header or bucket default rule) does not exist in the KMS answered 500 InternalError with a generic message: KmsError::KeyNotFound fell through to the default arm of the StorageError-to-ApiError mapping. S3 reports this client mistake as 400 KMS.NotFoundException; the mapping now does the same and names the key. s3s has no status for a custom code, so the ApiError-to-S3Error conversion supplies it. The legacy create-key aliases behind /minio/admin/v3/kms/key/create ignored the key-id query parameter that mc sends, creating a key under a generated id instead of the requested name. The alias now honors key-id (and its keyId/key spellings) alongside the name tag, and refuses a request whose two sources disagree. Refs: rustfs/backlog#2330 (KMS-312, KMS-110)