feat(sts): accept AssumeRoleWithWebIdentity from form-encoded POST bodies - #196
Merged
Conversation
…dies AWS SDKs send query-protocol operations as a form-encoded POST body with no query string at all, but the worker only ever surfaced the query string to the router. The STS handler reads its parameters from `RequestInfo::form_body`, which stayed `None`, so every SDK-shaped request fell through to the S3 pipeline and came back `InvalidRequest: unsupported POST operation` instead of credentials. multistore 0.7.0 (developmentseed/multistore#112) added `RequestParts::absorb_form_body` for exactly this; wire it in. It is a no-op passthrough for every other request shape, and rebuilds the body from the collected bytes so a mislabeled S3 write — `Content-Type` is client-controlled — still reaches the gateway with its payload intact. Collection is skipped for a form POST with a missing or oversized `Content-Length` rather than buffering it into WASM memory. Verified locally against `wrangler dev` (stub API + throwaway OIDC key): before, a form-encoded POST /.sts returns `InvalidRequest: unsupported POST operation`; after, it reaches the STS handler and returns `InvalidIdentityToken` for a bad token. The new routing test pins that distinction and needs no OIDC token, so it runs on fork PRs too. Part of #184. The remaining blocker for a true SDK drop-in is #185: AWS SDKs validate `RoleArn` client-side (min 20 chars), so `_default` is rejected before the request is ever sent. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Contributor
|
Claude finished @alukach's task in 3m 2s —— View job Review of PR #196
✅ No blocking issues — safe to merge.
|
|
🚀 Latest commit deployed to https://source-data-proxy-pr-196.source-coop.workers.dev
|
alukach
marked this pull request as ready for review
July 27, 2026 06:15
alukach
pushed a commit
that referenced
this pull request
Jul 27, 2026
🤖 I have created a release *beep* *boop* --- ## [2.3.0](v2.2.2...v2.3.0) (2026-07-27) ### Features * **backend:** enable GCS backend (multistore gcp + wasm-compatible signing) ([#191](#191)) ([33f2b25](33f2b25)) * **s3:** enforce conditional-write preconditions on PutObject ([003db0d](003db0d)) * **s3:** support server-side CopyObject via x-amz-copy-source ([97d5121](97d5121)) * **sts:** accept ARN-shaped alias for the _default role ([#185](#185)) ([8da7e72](8da7e72)) * **sts:** accept AssumeRoleWithWebIdentity from form-encoded POST bodies ([#196](#196)) ([f77e8d2](f77e8d2)) ### Bug Fixes * **gcs:** pass bucket_name to multistore GCS store ([#193](#193)) ([0efb66f](0efb66f)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: source-release-bot[bot] <265100246+source-release-bot[bot]@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
AWS SDKs send query-protocol operations as a form-encoded
POSTbody with no query string at all, but the worker only ever surfaced the query string to the router. The STS handler reads its parameters fromRequestInfo::form_body, which stayedNone, so every SDK-shaped request fell through to the S3 pipeline.multistore 0.7.0 (developmentseed/multistore#112, pulled in by #190) added
RequestParts::absorb_form_bodyfor exactly this. The dep bump alone does not enable it — the runtime has to call it, which is what this PR does.Behavior
POST /.stswithAction=AssumeRoleWithWebIdentity&RoleArn=_default&WebIdentityToken=…in the body:InvalidRequest: unsupported POST operationVerified locally against
wrangler devwith the stub API and a throwaway OIDC key, rebuilding the worker each way to confirm the difference is this change and not a stale isolate.Safety
absorb_form_bodyis a no-op passthrough for every request shape that is not a form-encodedPOST, and it rebuilds the body from the collected bytes — so a mislabeled S3 write (Content-Typeis client-controlled:CompleteMultipartUpload,DeleteObjects) still reaches the gateway with its payload intact. Collection is skipped entirely for a formPOSTwith a missing or oversizedContent-Lengthrather than buffering it into WASM memory.Tests
test_sts_form_encoded_body_reaches_the_sts_handler— needs no identity token, so it runs on fork PRs. Asserts the response is an STS rejection (InvalidIdentityToken) rather than the S3 fall-through; the status code alone does not discriminate, since both are 400. Fails onmain.test_sts_exchange_accepts_a_form_encoded_body— the positive path, under the existingneeds_tokengate.Full local integration run: 24 passed, 11 skipped (credentialed tier, no GitHub OIDC token locally).
Scope
Part of #184. This is one of the two blockers for a true SDK drop-in; the other is #185 — AWS SDKs validate
RoleArnclient-side (min 20 chars), so_defaultis rejected before the request is ever sent. Both are needed beforeboto3.client("sts", endpoint_url=…)works unmodified.🤖 Generated with Claude Code