<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>CopyObject on SILO</title>
    <link>https://silo.pgsty.com/zh/tags/copyobject/</link>
    <description>Recent content in CopyObject on SILO</description>
    <generator>Hugo</generator>
    <language>zh-CN</language>
    
    
    
      <lastBuildDate>Sun, 13 Sep 2026 10:59:52 +0800</lastBuildDate>
    
    
      <atom:link href="https://silo.pgsty.com/zh/tags/copyobject/index.xml" rel="self" type="application/rss+xml" />
    
    <item>
        <title>未签名的 Header 不属于请求</title>
        <link>https://silo.pgsty.com/zh/blog/design/signed-header-coverage/</link>
        <pubDate>Wed, 09 Sep 2026 00:00:00 +0000</pubDate>
        
        <guid>https://silo.pgsty.com/zh/blog/design/signed-header-coverage/</guid>
        <description>一个只授权写单个对象的 presigned/签名 PUT，可被转化为读取签名密钥可及的任意对象的服务端复制——因为 SigV4 验签只遍历&amp;quot;签名头名单&amp;quot;，从不检查真正到达的 x-amz-* 头，而路由又仅凭一个未签名的 x-amz-copy-source 头就派发到 CopyObject。本文记录 SILO 的未签名头拒绝边界、载荷哈希豁免与可信签名年龄的计算、PutObjectTagging 注入时序调整、跨签名模式的适用范围与发布前证据。</description>
      </item>
    
  </channel>
</rss>
