Skip to content

v0.1.13

Choose a tag to compare

@github-actions github-actions released this 18 Aug 20:57
· 10 commits to main since this release
v0.1.13
f4ba4ca

v0.1.13 — find 支持 AK/SK/STS 凭证探测,可验证非匿名桶

新增 / 变更

  • find 支持凭证探测:配置了凭证(--ak/--sk,STS 加 --token;或 OSS_*/AWS_* 环境变量、--profile,与 ls/cp 相同)时,自动从匿名探测切换为 SigV4 签名探测,可验证非匿名桶;--anonymous 强制匿名
  • 防误报:凭证本身被拒(InvalidAccessKeyId、SignatureDoesNotMatch 等)判为「无法判断」;只有明确目标的探测(--provider 指定或完整桶 URL)才把普通 403 判为「存在·拒绝访问」
  • --provider 可把裸桶名的扇出收窄到指定厂商(对 minio/r2/b2 等无探针厂商会明确报错)
  • JSON 汇总行新增 "auth": "anonymous|signed";输出文案随模式区分(如「可列目录(凭证)」)

用法示例

oss find mybucket --provider aliyun --ak LTAI... --sk ...

v0.1.13 — find supports credentialed (AK/SK/STS) probing for non-anonymous buckets

  • find switches from anonymous to SigV4-signed probes when credentials are configured (--ak/--sk, --token for STS, OSS_*/AWS_* env vars or --profile — same as ls/cp), so non-anonymous buckets can be verified; --anonymous forces anonymous probing
  • No false positives: credential rejections (InvalidAccessKeyId, SignatureDoesNotMatch, ...) stay inconclusive; a plain 403 counts as "exists but denied" only for targeted probes (--provider or a full bucket URL)
  • --provider now also narrows the bare-name fan-out to that provider (providers without probes, e.g. minio/r2/b2, produce a clear error)
  • JSON summary gains "auth": "anonymous|signed"; wording adapts to the mode

Full Changelog: v0.1.12...v0.1.13