RanaPriyansh opened a new pull request, #867:
URL: https://github.com/apache/arrow-rs-object-store/pull/867

   ## Summary
   
   Azure can grant a user delegation key whose validity does not cover a 
requested signed URL. The fixed cache window can also fetch another key while a 
cached key still covers the signed URL.
   
   This change makes the requested key validity configurable, with a 12-hour 
default. A longer signed URL extends the key request. The cache reuses a key 
only when Azure's returned SignedStart and SignedExpiry cover the serialized 
SAS interval. It rejects an invalid granted interval before caching the key.
   
   Addresses #807.
   
   ## Validation
   
   - `cargo test --features azure --lib` — 175 passed, four ignored.
   - `cargo clippy --features azure -- -D warnings`
   - `cargo clippy --no-default-features --features azure-base -- -D warnings`
   - `cargo clippy --all-features --all-targets -- -D warnings`
   - `cargo fmt --all -- --check`
   - `git diff --check`
   
   Mock Azure responses test public signed URLs, cache reuse, refresh, 
concurrent signers, failed and canceled refresh, granted intervals, and the 
seven-day limit. The public tests compare SAS timestamps with the granted key 
interval and reject an insufficient grant. No live Azure account was used.
   
   Codex used.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to