Repository navigation
[api] Use Locale.ROOT in DLFOpenApiV4Signer - #10087
Conversation
Canonicalize signing header names independently of the JVM default locale. Add a focused regression test comparing US and Turkish locale signatures for the same mixed-case header. Fixes apache#10086
JingsongLi
left a comment
There was a problem hiding this comment.
This fixes a real signature-invariance issue in the public DLF OpenAPI V4 signing path: an uppercase I in a mixed-case X-ACS-* header becomes a Turkish dotless ı under that JVM default locale, changing the canonical header list and authorization value. Locale.ROOT is the correct normalization and matches the existing V1 signer. The default generated lowercase-header path remains unaffected; I found no regression in this one-line change.
The fixed-timestamp/nonce regression compares the complete authorization value across US and Turkish locales and restores the original locale. I ran DLFOpenApiV4SignerTest and DLFRequestSignerTest locally with standard Maven checks: 33/33 passed. The PR head's JDK, Flink, Spark and E2E CI checks also pass.
Purpose
Fixes #10086. Follow-up to #9770 and #9771.
Canonicalize DLF OpenAPI V4 signing header names with
Locale.ROOT. Under a Turkish default locale,X-ACS-SIGNATURE-NONCEotherwise becomesx-acs-sıgnature-nonce, changing the canonical request and signature. The default authentication path generates lowercase headers and is unaffected.Tests
Added
DLFOpenApiV4SignerTest#testAuthorizationWithTurkishLocale, which fixes the timestamp and nonce and compares the complete authorization string for the same mixed-case header under US and Turkish locales. The test restores the original locale in afinallyblock.Confirmed that the regression test fails without the fix and passes with it. All 33 tests passed with the standard Maven checks enabled:
mvn -pl paimon-api -DwildcardSuites=none \ -Dtest=DLFOpenApiV4SignerTest,DLFRequestSignerTest test