Only send X-Amz-Target for the awsJson protocols - #2009
Merged
kubukoz merged 2 commits intoSep 29, 2026
Merged
Conversation
The signer added X-Amz-Target to every request. Only awsJson routes on it; restJson1 and restXml route on the method and path, the query protocols on the Action parameter. A server that routes on the header first (fakecloud) therefore rejected every SES v2 call with UnknownOperationException. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
kubukoz
marked this pull request as ready for review
September 29, 2026 00:57
Member
Author
|
End-to-end check against real AWS, with this branch's
So on real AWS this is about correctness, not a failure: the header is meaningless for restJson1. The visible break is in emulators that route the way the awsJson spec says they should. |
lewisjkl
approved these changes
Sep 29, 2026
Contributor
|
This pull request does not currently match the merge queue conditions, so it cannot be queued from here. The box comes back if it matches again. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to #1596, same family of SES v2 breakage.
Problem
AwsSigningaddsX-Amz-Target: <Service>.<Operation>to every request it signs, whatever the service's protocol. Only awsJson 1.0/1.1 uses that header, because every awsJson request goes toPOST /. restJson1 and restXml route on the method and path, and the query protocols route onAction.It isn't harmless on those protocols. A server that routes on the header first takes the request for awsJson and rejects it. fakecloud does exactly that, so with 0.19.13 every SES v2 (restJson1)
SendEmailcomes back as:The header is also signed, so a user can't strip it in a middleware without invalidating the signature.
Fix
transformClientresolves the protocol from the service hints (AwsProtocol, the same resolutionAwsClientuses to pick codecs). It passessigningFunctionanamzTarget: Option[String], which isSomeonly for awsJson1_0/1_1. The header stays in the fixed, ordered list of signed headers when it's present, so awsJson canonical requests are byte-for-byte unchanged.Tests
RestJsonSesfixture inaws_example.smithy, mirroring SES v2 in full (restJson1,endpointPrefix: email, sigv4ses), with regenerated bootstrapped code.AwsEndpointAndSigningNameTest:X-Amz-Targetis neither sent nor listed inSignedHeaders. Fails without the fix (checked by stashing the signer change).DynamoDB_20120810.ListTables, so this can't regress the protocols that need it.AwsSignatureTestparity test against the AWS SDK signer passesSome(target), so it checks the same thing as before.aws-http4s/testandaws-http4s3/testboth pass: 698/698 each.Found via kubukoz/invoicer#11, where it's the last blocker for moving SES onto the generated client.
🤖 Generated with Claude Code