thswlsqls opened a new issue, #10229:
URL: https://github.com/apache/paimon/issues/10229

   
   **Search before asking**
   - [x] I searched in the [issues](https://github.com/apache/paimon/issues) 
and found nothing similar.
   
   **Paimon version**
   master @ 1cf42e256 (2.2-SNAPSHOT)
   
   **Compute Engine**
   Engine-agnostic (OSS FileIO); reached via Flink/Spark presigned-URL 
functions and `Blob#toPresignedUrl`.
   
   **Minimal reproduce step**
   1. Configure a catalog with `fs.oss.sld.enabled=true` and an HTTPS endpoint 
(public, `-internal`, or PrivateLink).
   2. Request a blob presigned URL.
   3. `OSSFileIO.enableSecondLevelDomain` (OSSFileIO.java line 302) turns on 
SLD in the shared client, so the SDK signs a path-style URL: host = endpoint 
host, path = `/bucket/key`.
   4. `OSSBlobPresigner.validatePresignedUrl()` (OSSBlobPresigner.java line 
219) always expects host `bucket.<endpoint host>` and path `/key`.
   
   **What doesn't meet your expectations?**
   Every call fails with "OSS client generated a presigned URL for an invalid 
target." (the first call also leaves a materialized `_bloburl_` copy behind). 
Expected: the path-style URL the client signed is returned, with bucket and key 
still verified.
   
   **Anything else?**
   The SDK puts the bucket in the host only when SLD is off 
(`OSSUtils.buildCanonicalHost`) and in the path when it is on 
(`OSSUtils.determineResourcePath`). SLD-off behavior is correct. CNAME custom 
domains are a separate case.
   
   **Are you willing to submit a PR?**
   - [x] I'm willing to submit a PR!
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to