Issues

ZF-8671: Signature is invalid for all requests that have space in any of the signed query parameters

Issue Type: Bug Created: 2009-12-30T06:59:02.000+0000 Last Updated: 2009-12-30T07:31:43.000+0000 Status: Resolved Fix version(s): - 1.9.7 (11/Jan/10)

Reporter: Shahar Evron (shahar) Assignee: Jon Whitcraft (sidhighwind) Tags: - Zend_Service_Amazon_Ec2

Related issues: Attachments: - zf-amazon-ec2-rawurlencode.patch

Description

Using Amazon_Ec2 Query API requests will fail with the follwing exception:

<pre class="highlight">
exception 'Zend_Service_Amazon_Ec2_Exception' with message 'The request signature we calculated does not match the signature you provided. Check your AWS Secret Access Key and signing method. Consult the service documentation for details.'

If any of the signed parameters has space it in. This is due to usage of urlencode() instead of rawurlencode() when generating the string-to-sign, despite Amazon's explicit demand that spaces will be encoded as %20 (=rawurlencode()) and not as '+' (=urlencode()).

Comments

Posted by Shahar Evron (shahar) on 2009-12-30T06:59:50.000+0000

Patch against SVN rev. 19975 is attached.

Posted by Jon Whitcraft (sidhighwind) on 2009-12-30T07:31:43.000+0000

Strange enough I ran into this problem myself a few days ago and fixed it but I havn't had time to post file a bug and submit the patch. This was done with r19977 (trunk) and r19978 (release branch)

Have you found an issue?

See the Overview section for more details.

Copyright

© 2006-2016 by Zend, a Rogue Wave Company. Made with by awesome contributors.

This website is built using zend-expressive and it runs on PHP 7.

Contacts