You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用Dotnet 8.0 SDK对接GarageHQ时出现无效负载签名错误

解决AWSSDK.S3对接GarageHQ时的"Invalid payload signature"错误

从GarageHQ的日志可以看到,请求使用了STREAMING-AWS4-HMAC-SHA256-PAYLOAD-TRAILER流式签名模式,而GarageHQ对这种签名的支持存在兼容性问题,导致返回Invalid payload signature错误。AWS CLI能正常工作是因为它默认使用完整payload哈希签名,而非流式签名。

以下是几种可行的解决方案:

方案1:禁用分块编码与自动校验和

修改S3客户端配置,强制使用非流式签名方式,同时关闭自动添加的校验和头:

using Amazon.Runtime;
using Amazon.S3;
using Amazon.S3.Model;

[HttpPost]
public async Task<IActionResult> UploadFile(IFormFile file)
{
    await using var memoryStream = new MemoryStream();
    await file.CopyToAsync(memoryStream);
    memoryStream.Position = 0; // 手动重置流位置,确保读取正确

    var s3Config = new AmazonS3Config()
    {
        ServiceURL = "http://localhost:3900",
        ForcePathStyle = true,
        AuthenticationRegion = "garage",
        UseChunkedEncoding = false, // 禁用分块编码,避免流式签名
        ChecksumAlgorithm = null, // 关闭自动校验和,移除trailer相关头
        SignatureVersion = SignatureVersion.V4 // 明确指定V4签名版本
    };

    using var client = new AmazonS3Client(
        new BasicAWSCredentials("my_access_key", "my_secret_key"),
        s3Config
    );

    var uploadRequest = new PutObjectRequest()
    {
        BucketName = "my_bucket",
        InputStream = memoryStream,
        Key = file.FileName,
        CannedACL = S3CannedACL.PublicRead,
        ContentType = "image/png",
    };

    await client.PutObjectAsync(uploadRequest);
    return Ok();
}

方案2:手动计算内容哈希

预先计算文件内容的SHA256哈希并设置到请求中,让SDK使用完整payload签名:

using Amazon.Runtime;
using Amazon.S3;
using Amazon.S3.Model;
using System.Security.Cryptography;

[HttpPost]
public async Task<IActionResult> UploadFile(IFormFile file)
{
    await using var memoryStream = new MemoryStream();
    await file.CopyToAsync(memoryStream);
    
    // 计算内容SHA256哈希
    memoryStream.Position = 0;
    var sha256 = SHA256.Create();
    var contentHash = Convert.ToBase64String(sha256.ComputeHash(memoryStream));
    memoryStream.Position = 0;

    var client = new AmazonS3Client(
        new BasicAWSCredentials("my_access_key", "my_secret_key"),
        new AmazonS3Config()
        {
            ServiceURL = "http://localhost:3900",
            ForcePathStyle = true,
            AuthenticationRegion = "garage",
        }
    );

    var uploadRequest = new PutObjectRequest()
    {
        BucketName = "my_bucket",
        InputStream = memoryStream,
        Key = file.FileName,
        CannedACL = S3CannedACL.PublicRead,
        ContentType = "image/png",
        ContentSHA256 = contentHash // 设置预先计算的哈希
    };

    await client.PutObjectAsync(uploadRequest);
    return Ok();
}

关键说明

  • UseChunkedEncoding = false:禁用分块编码后,SDK会一次性计算整个payload的哈希,而非流式分段签名,这与AWS CLI的行为一致,GarageHQ能正确验证。
  • 手动设置ContentSHA256:强制SDK使用预先计算的完整哈希,避免触发流式签名逻辑。
  • 确保流位置重置:无论是自动还是手动,都要保证InputStream的位置在起始处,否则会导致哈希计算错误或文件上传不完整。

内容的提问来源于stack exchange,提问作者Izak Joubert

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 06:08:18