Skip to content

fix(azure): sign copy source with read SAS when committing report - #205

Open
rmarku wants to merge 2 commits into
CyborgTests:mainfrom
rmarku:fix/azure-commit-sas-copy-source
Open

fix(azure): sign copy source with read SAS when committing report#205
rmarku wants to merge 2 commits into
CyborgTests:mainfrom
rmarku:fix/azure-commit-sas-copy-source

Conversation

@rmarku

@rmarku rmarku commented Aug 14, 2026

Copy link
Copy Markdown
Contributor

Azure authenticates the copy source of a Copy Blob From URL operation independently of the request's shared-key signature. commitPrefix passed a bare, unsigned blob URL to syncCopyFromURL, so against a private container the copy-source read failed with "Server failed to authenticate the request ... www-authenticate header", making every report commit fail on Azure (uploads/downloads were unaffected since those are shared-key signed).

Generate a short-lived read-only SAS for the source blob before the copy, mirroring how the S3 backend names its source inside a signed request.

rmarku added 2 commits August 14, 2026 09:13
Azure authenticates the copy *source* of a Copy Blob From URL operation
independently of the request's shared-key signature. commitPrefix passed a
bare, unsigned blob URL to syncCopyFromURL, so against a private container
the copy-source read failed with "Server failed to authenticate the
request ... www-authenticate header", making every report commit fail on
Azure (uploads/downloads were unaffected since those are shared-key signed).

Generate a short-lived read-only SAS for the source blob before the copy,
mirroring how the S3 backend names its source inside a signed request.
Unit test (node:test, no emulator or network) that stubs listBlobsFlat and
the blob client's syncCopyFromURL/deleteIfExists while letting the real
generateSasUrl run. Asserts the copy source is a signed read-only SAS URL
(sig/se/sp=r present) rather than the bare blob URL. Fails against the
previous bare-url code and passes with the fix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant