{"record":{"id":"4f39aa042ca9a846","repo":"apache/iceberg","slug":"pre-signing-not-allowed","errorCode":null,"errorMessage":"Pre-signing not allowed.","messagePattern":"Pre-signing not allowed\\.","errorType":"exception","errorClass":"UnsupportedOperationException","httpStatus":null,"severity":"error","filePath":"aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java","lineNumber":283,"sourceCode":"      SdkHttpFullRequest.Builder mutableRequest,\n      byte[] signature,\n      byte[] signingKey,\n      Aws4SignerRequestParams signerRequestParams,\n      AwsS3V4SignerParams signerParams,\n      SdkChecksum sdkChecksum) {\n    checkSignerParams(signerParams);\n  }\n\n  @Override\n  protected String calculateContentHashPresign(\n      SdkHttpFullRequest.Builder mutableRequest, Aws4PresignerParams signerParams) {\n    return UNSIGNED_PAYLOAD;\n  }\n\n  @Override\n  public SdkHttpFullRequest presign(\n      SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {\n    throw new UnsupportedOperationException(\"Pre-signing not allowed.\");\n  }\n\n  @Override\n  public SdkHttpFullRequest sign(\n      SdkHttpFullRequest request, ExecutionAttributes executionAttributes) {\n    AwsS3V4SignerParams signerParams =\n        extractSignerParams(AwsS3V4SignerParams.builder(), executionAttributes).build();\n\n    RemoteSignRequest remoteSigningRequest =\n        ImmutableRemoteSignRequest.builder()\n            .method(request.method().name())\n            .region(signerParams.signingRegion().id())\n            .uri(request.getUri())\n            .headers(request.headers())\n            .properties(requestPropertiesSupplier().get())\n            .body(bodyAsString(request))\n            .provider(S3_PROVIDER)\n            .build();","sourceCodeStart":265,"sourceCodeEnd":301,"githubUrl":"https://github.com/apache/iceberg/blob/86d9c8fc543e7c56c9f624eb725f76c9baff9570/aws/src/main/java/org/apache/iceberg/aws/s3/signer/S3V4RestSignerClient.java#L265-L301","documentation":"S3V4RestSignerClient.presign() unconditionally throws UnsupportedOperationException. This remote signer only supports signing request headers/payload after credential refresh; it never pre-signs full requests, and the AWS SDK must not ask it to.","triggerScenarios":"Configuring the S3 Access Grants/remote signing auth scheme in a mode that requests presigned URLs, or an SDK version/configuration invoking presign() on this signer.","commonSituations":"Client misconfiguration selecting 'presigning' auth for the REST-backed S3 signer; using an SDK option (e.g. enablePresigning) incompatible with remote signing.","solutions":["Remove presigning-related SDK options so the signer is used in normal (sign) mode.","Configure the S3FileIO/catalog to use the remote signer's default auth scheme.","If you need presigned URLs, generate them separately (e.g. S3Presigner) rather than via this client.","Check SDK version compatibility for S3 Access Grants remote signing."],"exampleFix":"// before\nS3Client.builder().requestSignerVersion(mySigner).build(); // triggers presign path\n// after\nS3FileIOProperties props = new S3FileIOProperties();\nprops.setRemoteSigningEnabled(true); // normal sign path, no presigning","handlingStrategy":"validation","validationCode":"// Java\n// ensure remote signing mode, not presigning, is configured\nboolean remoteSigning = props.isRemoteSigningEnabled();\nif (!remoteSigning) {\n  throw new IllegalStateException(\"Use remote signing mode with S3V4RestSignerClient\");\n}","typeGuard":null,"tryCatchPattern":"// Java\ntry {\n  io.newInputFile(s3Path).newStream();\n} catch (UnsupportedOperationException e) {\n  if (e.getMessage().contains(\"Pre-signing\")) {\n    LOG.error(\"Disable presigning in SDK/auth config when using the REST S3 signer\");\n  }\n}","preventionTips":["Never enable SDK presigning options alongside the remote signer","Use S3Presigner separately if presigned URLs are actually needed","Keep SDK versions aligned with the Iceberg remote-signing support matrix"],"tags":["s3","signer","rest-catalog","unsupported"],"backgroundTag":"method-not-implemented","analyzedSha":"86d9c8fc543e7c56c9f624eb725f76c9baff9570","analyzedAt":"2026-09-12T00:46:39.097Z","contentChangedAt":"2026-09-12T00:46:39.097Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}