oss请求处理
This commit is contained in:
1 parent
18cb51670c
commit
a9a4cdf125
18 files changed
+450
-29
No files matched your search
@@ -16,6 +16,7 @@ import (
|
||||
"net/url"
|
||||
"path"
|
||||
"sort"
|
||||
"strconv"
|
||||
"strings"
|
||||
"syscall"
|
||||
"time"
|
||||
@@ -23,6 +24,11 @@ import (
|
||||
|
||||
const maxOSSErrorBody = 64 << 10
|
||||
|
||||
const (
|
||||
DefaultSignedURLTTL = time.Hour
|
||||
MaximumSignedURLTTL = 9 * time.Hour
|
||||
)
|
||||
|
||||
// OSSHTTPClient implements OSSClient using Aliyun OSS's HTTP authorization
|
||||
// protocol. The supplied HTTP client owns timeout and transport policy.
|
||||
type OSSHTTPClient struct {
|
||||
@@ -112,6 +118,31 @@ func (c *OSSHTTPClient) Delete(ctx context.Context, request OSSObjectRequest) er
|
||||
return consumeOSSResponse(response)
|
||||
}
|
||||
|
||||
// SignGetURL creates an OSS V1 query-signed GET URL. The expiration is bounded
|
||||
// to OSS's documented maximum and the operation is local: no network request is
|
||||
// performed and no secret is embedded in the resulting URL.
|
||||
func (c *OSSHTTPClient) SignGetURL(request OSSObjectRequest, ttl time.Duration) (string, error) {
|
||||
if ttl <= 0 || ttl > MaximumSignedURLTTL {
|
||||
return "", errors.New("OSS signed URL lifetime must be between zero and nine hours")
|
||||
}
|
||||
requestURL, err := ossObjectURL(request.Endpoint, request.Bucket, request.Key, "")
|
||||
if err != nil {
|
||||
return "", err
|
||||
}
|
||||
expires := c.now().UTC().Add(ttl).Unix()
|
||||
canonicalResource := "/" + request.Bucket + "/" + request.Key
|
||||
stringToSign := strings.Join([]string{http.MethodGet, "", "", strconv.FormatInt(expires, 10), canonicalResource}, "\n")
|
||||
mac := hmac.New(sha1.New, []byte(c.accessKeySecret))
|
||||
_, _ = mac.Write([]byte(stringToSign))
|
||||
signature := base64.StdEncoding.EncodeToString(mac.Sum(nil))
|
||||
query := requestURL.Query()
|
||||
query.Set("OSSAccessKeyId", c.accessKeyID)
|
||||
query.Set("Expires", strconv.FormatInt(expires, 10))
|
||||
query.Set("Signature", signature)
|
||||
requestURL.RawQuery = query.Encode()
|
||||
return requestURL.String(), nil
|
||||
}
|
||||
|
||||
func (c *OSSHTTPClient) newRequest(ctx context.Context, method, endpoint, bucket, key, subresource string, body io.Reader) (*http.Request, error) {
|
||||
requestURL, err := ossObjectURL(endpoint, bucket, key, subresource)
|
||||
if err != nil {
|
||||
@@ -307,3 +338,4 @@ func readOSSError(response *http.Response) error {
|
||||
}
|
||||
|
||||
var _ OSSClient = (*OSSHTTPClient)(nil)
|
||||
var _ OSSURLSigner = (*OSSHTTPClient)(nil)
|
||||
Reference in new issue
Block a user