Preflight requests should be available without authentication and authorization #455
Labels
No labels
P0
P1
P2
P3
good first issue
Infrastructure
blocked
bug
config
discussion
documentation
duplicate
enhancement
go
help wanted
internal
invalid
kludge
observability
perfomance
question
refactoring
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference: TrueCloudLab/frostfs-s3-gw#455
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Is your feature request related to a problem? Please describe.
Currently preflight request like this:
failed because of access denied
In s3-gw logs:
But CORS Spec https://fetch.spec.whatwg.org/#cors-protocol-and-credentials says:
And AWS allows such requests without any credentials.
I suppose we should do the same.
Describe the solution you'd like
We can move Preflight handler to middlewares.
There are some problem here though: CORs configuration can be stored in bucket to which s3-gw doesn't have access. Using separate container for cors #422 partially solve this. But we still have to go to tree service for bucket settings and we can still have no access.
Probably we can completely move any CORs info into separate container
Describe alternatives you've considered
Don't do anything.
Additional context
No.
cc @alexvanin
In addition we don't support Options methods in s3 actions