Skip to content

fix(uploads): sign S3-compatible upload metadata as headers and allow S3_ENDPOINT in CSP - #8449

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/s3-compatible-direct-uploads
Sep 30, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/s3-compatible-direct-uploads

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • With S3_ENDPOINT set, sign x-amz-meta-* upload metadata as headers (unhoistableHeaders) and return them for the uploader to send, instead of letting the presigner hoist them into the query string. S3-compatible stores such as OVHcloud, SeaweedFS, and RustFS ignore query-string metadata, so the object landed without uploadId and completion failed with "missing required provider metadata". Signed-header metadata is what the other official AWS SDKs do and works on every store checked
  • AWS (no S3_ENDPOINT) keeps the query-string form unchanged, so existing bucket CORS rules can't regress
  • Add the S3_ENDPOINT origin (port kept) to connect-src in both build-time and runtime CSP, plus *.host for virtual-hosted addressing (skipped for S3_FORCE_PATH_STYLE and IP hosts, which the SDK always addresses path-style). Previously the browser blocked every direct upload to a custom endpoint
  • Docs: S3-compatible buckets need CORS AllowedHeaders: ["*"] (or Content-Type, If-None-Match, and the x-amz-meta-* headers)

Fixes #8378

Type of Change

  • Bug fix

Testing

  • presigned-upload.test.ts runs the real SigV4 presigner (local, no network): metadata is signed as headers for a custom endpoint, stays in the query for AWS, and every signed header the uploader controls is supplied with nothing both hoisted and sent
  • csp.test.ts: virtual-hosted, path-style + port, IP host, scheme-less endpoint, and build-time policy
  • New-behavior tests fail with the fix reverted; AWS-unchanged guards pass before and after
  • bun run lint, type-check, check:audits (52/52), docs-manifest:check

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Sep 30, 2026 4:51am UTC

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 6 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/lib/core/security/csp.ts
@greptile-apps

greptile-apps Bot commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[High risk] Changes how upload metadata is signed for S3-compatible storage.

The PR appears safe to merge; the previously reported environment-dependent test has been fixed.

Summary

The PR sends signed upload metadata as headers for custom S3 endpoints, permits those endpoints in the browser CSP, and updates tests and storage documentation. Since the previous review, it also pins the CSP test’s path-style setting as unset.

Reviews (2) · Last reviewed commit: "test(csp): pin S3_FORCE_PATH_STYLE unset..."

Comment thread apps/sim/lib/core/security/csp.test.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 6 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit efbb4f5 into staging Sep 30, 2026
32 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/s3-compatible-direct-uploads branch September 30, 2026 05:00

This branch was previously deployed

1 inactive deployment
Preview — f0696243 Deployed Sep 30, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant