Summary
SourceCoopRegistry::list_buckets is unimplemented!(), which panics rather than returning an error. It is reachable from a non-GET request to /.
Evidence
https://github.com/source-cooperative/data.source.coop/blob/main/src/source_api/registry.rs#L82-L88
async fn list_buckets(
&self,
_identity: &ResolvedIdentity,
) -> Result<Vec<BucketEntry>, ProxyError> {
unimplemented!("Bucket listing is not supported")
}
The signature already returns Result<_, ProxyError>, so a panic is avoidable at no cost.
Reachability: multistore dispatches ListBuckets for a request to / (multistore-0.7.2/src/proxy.rs:874). IndexHandler intercepts / but only claims GET:
// src/handlers.rs
if req.method == http::Method::GET {
Some(ProxyResult::json(200, format!("Source Cooperative Data Proxy v{}", VERSION)))
} else {
None // falls through to the gateway
}
So e.g. HEAD / or POST / falls through to the gateway and reaches list_buckets.
Impact
A panic in a Worker aborts the isolate and returns an opaque error to the caller, with no structured S3 error body. It is trivially reachable by an unauthenticated request. Not a data-integrity or disclosure risk, but it is an unauthenticated remote panic and it produces useless diagnostics.
Suggested fix
Return a proper S3 error instead of panicking — ProxyError::AccessDenied, or a NotImplemented-style error if one is a better fit for the S3 surface. Optionally have IndexHandler claim all methods on / so the fall-through cannot happen.
Note that implementing real bucket listing is a separate, larger question (it depends on the Role-ceiling work in the ADR set); this issue is only about not panicking.
Notes
Found while auditing the ADRs in #115 against the implementation.
Summary
SourceCoopRegistry::list_bucketsisunimplemented!(), which panics rather than returning an error. It is reachable from a non-GET request to/.Evidence
https://github.com/source-cooperative/data.source.coop/blob/main/src/source_api/registry.rs#L82-L88
The signature already returns
Result<_, ProxyError>, so a panic is avoidable at no cost.Reachability: multistore dispatches
ListBucketsfor a request to/(multistore-0.7.2/src/proxy.rs:874).IndexHandlerintercepts/but only claimsGET:So e.g.
HEAD /orPOST /falls through to the gateway and reacheslist_buckets.Impact
A panic in a Worker aborts the isolate and returns an opaque error to the caller, with no structured S3 error body. It is trivially reachable by an unauthenticated request. Not a data-integrity or disclosure risk, but it is an unauthenticated remote panic and it produces useless diagnostics.
Suggested fix
Return a proper S3 error instead of panicking —
ProxyError::AccessDenied, or aNotImplemented-style error if one is a better fit for the S3 surface. Optionally haveIndexHandlerclaim all methods on/so the fall-through cannot happen.Note that implementing real bucket listing is a separate, larger question (it depends on the Role-ceiling work in the ADR set); this issue is only about not panicking.
Notes
Found while auditing the ADRs in #115 against the implementation.