Skip to content

[api] Use Locale.ROOT in DLFOpenApiV4Signer - #10087

Merged
JingsongLi merged 1 commit into
apache:masterfrom
taoran92:fix/dlf-openapi-v4-header-locale
Sep 24, 2026
Merged

JingsongLi merged 1 commit into
apache:masterfrom
taoran92:fix/dlf-openapi-v4-header-locale

Conversation

@taoran92

Copy link
Copy Markdown
Member

Purpose

Fixes #10086. Follow-up to #9770 and #9771.

Canonicalize DLF OpenAPI V4 signing header names with Locale.ROOT. Under a Turkish default locale, X-ACS-SIGNATURE-NONCE otherwise becomes x-acs-sıgnature-nonce, changing the canonical request and signature. The default authentication path generates lowercase headers and is unaffected.

Tests

Added DLFOpenApiV4SignerTest#testAuthorizationWithTurkishLocale, which fixes the timestamp and nonce and compares the complete authorization string for the same mixed-case header under US and Turkish locales. The test restores the original locale in a finally block.

Confirmed that the regression test fails without the fix and passes with it. All 33 tests passed with the standard Maven checks enabled:

mvn -pl paimon-api -DwildcardSuites=none \
  -Dtest=DLFOpenApiV4SignerTest,DLFRequestSignerTest test

Canonicalize signing header names independently of the JVM default locale. Add a focused regression test comparing US and Turkish locale signatures for the same mixed-case header.

Fixes apache#10086

@JingsongLi JingsongLi left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This fixes a real signature-invariance issue in the public DLF OpenAPI V4 signing path: an uppercase I in a mixed-case X-ACS-* header becomes a Turkish dotless ı under that JVM default locale, changing the canonical header list and authorization value. Locale.ROOT is the correct normalization and matches the existing V1 signer. The default generated lowercase-header path remains unaffected; I found no regression in this one-line change.

The fixed-timestamp/nonce regression compares the complete authorization value across US and Turkish locales and restores the original locale. I ran DLFOpenApiV4SignerTest and DLFRequestSignerTest locally with standard Maven checks: 33/33 passed. The PR head's JDK, Flink, Spark and E2E CI checks also pass.

@JingsongLi
JingsongLi merged commit ad4e62d into apache:master Sep 24, 2026
18 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Bug] DLFOpenApiV4Signer uses the default locale to canonicalize header names

2 participants