Skip to content

[Feature] Add dev-mode option to ignore or widen the 15 minute SigV4 clock skew window #359

Description

@jgaul3

Problem or use case

While trying to migrate to extenddb from dynalite, I encountered unit test failures in tests which froze time outside the SigV4 clock skew window. I believe this is due to validate_timestamp rejecting any request whose X-Amz-Date is more than 15 minutes from the server's clock (see crates/auth/src/sigv4/verify.rs:18).

Since there is no way to change or disable this check even in dev-mode, test suites that time travel can't be migrated properly. Mocking time is a fairly common requirement for unit testing and I'm sure others have encountered this issue.

This can be reproduced via:

docker run -d -p 127.0.0.1:18080:18080 \
  -e EXTENDDB__STORAGE__SQLITE__PATH=:memory: extenddb/extenddb-dev:0.1.11
import boto3, time_machine
db = boto3.client("dynamodb", endpoint_url="http://127.0.0.1:18080",
                              region_name="us-east-1",
                              aws_access_key_id="AKIAIOSFODNN7EXAMPLE",
                              aws_secret_access_key="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY")
db.list_tables()  # ok
with time_machine.travel("2021-01-01"):
    db.list_tables()  # UnrecognizedClientException

Proposed solution

I would expect a dev-mode-only setting to widen or disable the skew window e.g. EXTENDDB_DEV_MAX_CLOCK_SKEW_SECS with a value which explicitly means "don't check." If this value is unset I would expect the default behavior.

Alternatives considered

Some of the tests which failed could be rewritten, but doing so for the sake of the emulator seems wrong.

DynamoDB API reference

N/A

Additional context

Thank you for your time and attention.

Checklist

  • I have searched existing issues and the roadmap for duplicates
  • I have described the use case, not just the desired implementation

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions