Merge pull request #542 from fkautz/pr_out_make_minio_work_with_curl_and_browsers_again

This commit is contained in:
Frederick F. Kautz IV 2015-04-29 20:21:38 -07:00
commit a521309b78
2 changed files with 19 additions and 22 deletions

View File

@ -72,22 +72,25 @@ func (h timeHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) {
return return
} }
// Verify if date headers are set, if not reject the request // Verify if date headers are set, if not reject the request
if r.Header.Get("x-amz-date") == "" && r.Header.Get("Date") == "" {
// there is no way to knowing if this is a valid request, could be a attack reject such clients if r.Header.Get("Authorization") != "" {
writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path) if r.Header.Get("x-amz-date") == "" && r.Header.Get("Date") == "" {
return // there is no way to knowing if this is a valid request, could be a attack reject such clients
} writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path)
date, err := getDate(r) return
if err != nil { }
// there is no way to knowing if this is a valid request, could be a attack reject such clients date, err := getDate(r)
writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path) if err != nil {
return // there is no way to knowing if this is a valid request, could be a attack reject such clients
} writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path)
duration := time.Since(date) return
minutes := time.Duration(5) * time.Minute }
if duration.Minutes() > minutes.Minutes() { duration := time.Since(date)
writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path) minutes := time.Duration(5) * time.Minute
return if duration.Minutes() > minutes.Minutes() {
writeErrorResponse(w, r, RequestTimeTooSkewed, acceptsContentType, r.URL.Path)
return
}
} }
h.handler.ServeHTTP(w, r) h.handler.ServeHTTP(w, r)
} }

View File

@ -32,12 +32,6 @@ func getContentType(req *http.Request) contentType {
switch { switch {
case acceptHeader == "application/json": case acceptHeader == "application/json":
return jsonContentType return jsonContentType
case acceptHeader == "application/xml":
return xmlContentType
case acceptHeader == "*/*":
return xmlContentType
case acceptHeader != "":
return unknownContentType
default: default:
return xmlContentType return xmlContentType
} }