github cloudlena/s3manager v0.11.0

4 hours ago

Security

  • CSRF protection: All requests now go through Go's http.CrossOriginProtection. Cross-origin state-changing requests (uploads, deletes, policy changes) are rejected.
  • Safer object serving: Downloads always get Content-Disposition: attachment, application/octet-stream and X-Content-Type-Options: nosniff. Objects opened inline use the content type stored in S3 and never one sniffed from the body. Filenames in Content-Disposition are now properly escaped.
  • SHOW_VERSIONS now applies to the metadata endpoint too: With versions turned off, old versions can no longer be read through /metadata?versionId=….

Bug fixes

  • Listing large prefixes on older Ceph RGW (#10): Some providers mark a ListObjects V2 page as truncated but send no continuation token. When that happens, the bucket view, bulk delete and bulk ZIP download now fall back to ListObjects V1. Bulk operations resume from the last key they processed, so no object is handled twice.
  • SSE-C objects can be read back: The configured SSE-C key is now sent with downloads, inline views, metadata lookups and bulk ZIP downloads, not only with uploads. Presigned and public links still don't carry the key, so they don't work for SSE-C objects.
  • An invalid SSE_TYPE/SSE_KEY now fails at start-up instead of on the first upload.
  • An object that can't be read now returns a proper error status. Previously the response could start before the error was known.
  • S3 errors are mapped to status codes and messages by their S3 error code instead of by matching message text, so 404s and "access denied" hints work across providers.
  • "Last modified" in the metadata dialog now uses the same format and time zone (TZ) as the bucket view.
  • The "Delete bucket" action only shows when ALLOW_DELETE is on and you're on the unsearched top level of an empty bucket. It now asks for confirmation.
  • Version IDs in open/download links are URL-escaped.
  • File icons: extension matching is case-insensitive, and .jpeg is recognized.

Breaking changes

  • FORCE_DOWNLOAD has been removed. "Download" always downloads and "Open" always opens inline.
  • Removed API endpoints:
    • DELETE /{instance}/api/buckets/{bucket}/objects/{key}: use POST …/objects/bulk-delete instead, which also handles folders.
    • GET /api/s3-instances
  • POST …/objects/bulk-delete now returns 204 No Content instead of 200 with {"success": true}.

Packaging & development

  • Multi-arch container images: Release images are built for linux/amd64 and linux/arm64 (GoReleaser v2 dockers_v2). The latest tag is no longer pushed by the release workflow.
  • CI only logs in to Docker Hub and pushes images on push events, not on pull requests.
  • The CI Go version is read from go.mod.
  • The local compose.yaml setup uses RustFS instead of MinIO.
  • moq is pinned as a Go tool (go tool moq).
  • README: clarified ALLOW_DELETE, BUCKET_NAME (a display filter, not an access restriction), SSE_TYPE/SSE_KEY and the reverse-proxy guidance.

Don't miss a new s3manager release

NewReleases is sending notifications on new releases.