oss请求处理

This commit is contained in:
andy committed 2026-08-19 10:52:55 +08:00
1 parent 18cb51670c
commit a9a4cdf125
18 files changed
+450 -29

No files matched your search

+32
View File
@@ -16,6 +16,7 @@ import (
"net/url"
"path"
"sort"
"strconv"
"strings"
"syscall"
"time"
@@ -23,6 +24,11 @@ import (
const maxOSSErrorBody = 64 << 10
const (
DefaultSignedURLTTL = time.Hour
MaximumSignedURLTTL = 9 * time.Hour
)
// OSSHTTPClient implements OSSClient using Aliyun OSS's HTTP authorization
// protocol. The supplied HTTP client owns timeout and transport policy.
type OSSHTTPClient struct {
@@ -112,6 +118,31 @@ func (c *OSSHTTPClient) Delete(ctx context.Context, request OSSObjectRequest) er
return consumeOSSResponse(response)
}
// SignGetURL creates an OSS V1 query-signed GET URL. The expiration is bounded
// to OSS's documented maximum and the operation is local: no network request is
// performed and no secret is embedded in the resulting URL.
func (c *OSSHTTPClient) SignGetURL(request OSSObjectRequest, ttl time.Duration) (string, error) {
if ttl <= 0 || ttl > MaximumSignedURLTTL {
return "", errors.New("OSS signed URL lifetime must be between zero and nine hours")
}
requestURL, err := ossObjectURL(request.Endpoint, request.Bucket, request.Key, "")
if err != nil {
return "", err
}
expires := c.now().UTC().Add(ttl).Unix()
canonicalResource := "/" + request.Bucket + "/" + request.Key
stringToSign := strings.Join([]string{http.MethodGet, "", "", strconv.FormatInt(expires, 10), canonicalResource}, "\n")
mac := hmac.New(sha1.New, []byte(c.accessKeySecret))
_, _ = mac.Write([]byte(stringToSign))
signature := base64.StdEncoding.EncodeToString(mac.Sum(nil))
query := requestURL.Query()
query.Set("OSSAccessKeyId", c.accessKeyID)
query.Set("Expires", strconv.FormatInt(expires, 10))
query.Set("Signature", signature)
requestURL.RawQuery = query.Encode()
return requestURL.String(), nil
}
func (c *OSSHTTPClient) newRequest(ctx context.Context, method, endpoint, bucket, key, subresource string, body io.Reader) (*http.Request, error) {
requestURL, err := ossObjectURL(endpoint, bucket, key, subresource)
if err != nil {
@@ -307,3 +338,4 @@ func readOSSError(response *http.Response) error {
}
var _ OSSClient = (*OSSHTTPClient)(nil)
var _ OSSURLSigner = (*OSSHTTPClient)(nil)