Skip to content

Conversation

Fred1155
Copy link
Contributor

Motivation and Context

Adding the field allowlist when converting PutObjectRequest and CopyObjectRequest to transfer manager request like UploadPartRequest. This is to prevent copying unexpected field to the the target request.

Modifications

Added two allowlist, which is all the current fields in PutObjectRequest and CopyObjectRequest. This is to preserve backward compatibility
Added a function validateRequestFields to validate the fields set in the original request is in the allowlist

Testing

Screenshots (if appropriate)

Types of changes

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)

Checklist

  • I have read the CONTRIBUTING document
  • Local run of mvn install succeeds
  • My code follows the code style of this project
  • My change requires a change to the Javadoc documentation
  • I have updated the Javadoc documentation accordingly
  • I have added tests to cover my changes
  • All new and existing tests passed
  • I have added a changelog entry. Adding a new entry must be accomplished by running the scripts/new-change script and following the instructions. Commit the new file created by the script in .changes/next-release with your changes.
  • My change is to implement 1.11 parity feature and I have updated LaunchChangelog

License

  • I confirm that this pull request can be released under the Apache 2 license

@Fred1155 Fred1155 requested a review from a team as a code owner August 18, 2025 16:27
@@ -53,12 +54,104 @@ public final class SdkPojoConversionUtils {
new HashSet<>(Arrays.asList("ChecksumSHA1", "ChecksumSHA256", "ContentMD5", "ChecksumCRC32C", "ChecksumCRC32",
"ChecksumCRC64NVME", "ContentLength"));

private static final Set<String> PUT_OBJECT_TO_UPLOAD_PART_ALLOWED_FIELDS = new HashSet<>(Arrays.asList(
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

How do we keep these allowlists up to date over time (ie, if/when there are service model updates that add new fields)? The PutObject to UploadPart translation uses an ignore list instead of allow list - is there a reason we choose allow rather than ignore for this?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Based on offline discussion, I think the allow list here makes sense so I'm good moving forward with it.

}
}

private static void validateRequestFields(SdkPojo sourceObject, SdkPojo targetBuilder, Set<String> allowedFields) {
Copy link
Contributor

@alextwoods alextwoods Aug 26, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Can we add some test cases for this?

Copy link
Contributor Author

@Fred1155 Fred1155 Aug 26, 2025

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

To preserve backward compatibility, all current fields are on the the allow list. I can do a local test by changing the model and see if it fails


if (!invalidFields.isEmpty()) {
throw SdkClientException.create(
String.format("The following fields are not allowed: %s",
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Are there currently any fields not on the allow list and do we know if any of them have different default values? IE - is there a risk of now raising an exception for cases that was previously working for customers?

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All current fields are on the allow list so there shouldn't be cases that raise exception. The existing unit test for SdkPojoConversionUtils should already covered that.

Copy link

Quality Gate Failed Quality Gate failed

Failed conditions
68.0% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

@Fred1155 Fred1155 added this pull request to the merge queue Aug 26, 2025
Merged via the queue into master with commit 1c0b19f Aug 26, 2025
37 of 38 checks passed
Copy link

This pull request has been closed and the conversation has been locked. Comments on closed PRs are hard for our team to see. If you need more assistance, please open a new issue that references this one.

@github-actions github-actions bot locked as resolved and limited conversation to collaborators Aug 26, 2025
@Fred1155 Fred1155 deleted the bole/add-allowlist-copy-upload branch August 27, 2025 19:27
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants