<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Presigned on SILO</title>
    <link>https://silo.pgsty.com/tags/presigned/</link>
    <description>Recent content in Presigned on SILO</description>
    <generator>Hugo</generator>
    <language>en</language>
    
    
    
      <lastBuildDate>Sun, 13 Sep 2026 10:59:52 +0800</lastBuildDate>
    
    
      <atom:link href="https://silo.pgsty.com/tags/presigned/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>An Unsigned Header Is Not Part of the Request</title>
        <link>https://silo.pgsty.com/blog/design/signed-header-coverage/</link>
        <pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate>
        
        <guid>https://silo.pgsty.com/blog/design/signed-header-coverage/</guid>
        <description>A presigned or signed PUT authorized for one object could be turned into a server-side copy of any object the signing key can read, because SigV4 verification only walked the list of signed header names and never the x-amz-* headers that actually arrived, while the router selects CopyObject from an unsigned x-amz-copy-source header. This record defines SILO&amp;rsquo;s unsigned-header rejection boundary, the payload-hash exception and trusted signature-age derivation, the PutObjectTagging injection reorder, the scope across signature modes, and the release evidence.</description>
      </item>
    
  </channel>
</rss>
