Skip to content

feat(storage): support copying CSEK-encrypted files to non-CSEK destinations - #8771

Merged
Dhriti07 merged 8 commits into
googleapis:mainfrom
thiyaguk09:feat/7351-copy-csek-to-unencrypted
Aug 28, 2026
Merged

Dhriti07 merged 8 commits into
googleapis:mainfrom
thiyaguk09:feat/7351-copy-csek-to-unencrypted

Conversation

@thiyaguk09

Copy link
Copy Markdown
Contributor

Thank you for opening a Pull Request! Before submitting your PR, there are a few things you can do to make sure it goes smoothly:

  • Make sure to open an issue as a bug/issue before writing your code! That way we can discuss the change, evaluate designs, and agree on the general idea
  • Ensure the tests and linter pass
  • Code coverage does not decrease (if any source code was changed)
  • Appropriate docs were updated (if necessary)

Fixes #7351

@product-auto-label product-auto-label Bot added the api: storage Issues related to the Cloud Storage API. label Jun 29, 2026

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces support for setting a File's encryption key to null, enabling the copying of a Customer-Supplied Encryption Key (CSEK) encrypted file to a standard non-CSEK destination. Feedback on the changes highlights a critical async bug and race condition in the copy method, where this.getRequestInterceptors is temporarily overridden synchronously around an asynchronous request. Because the request pipeline runs asynchronously, the synchronous restoration happens too early, and concurrent operations on the same File instance will interfere with each other. The reviewer recommends isolating custom interceptors using request-scoped configuration instead of modifying the shared instance.

Comment thread handwritten/storage/src/file.ts Outdated
Comment thread handwritten/storage/src/file.ts Outdated
@thiyaguk09
thiyaguk09 marked this pull request as ready for review June 29, 2026 14:16
@thiyaguk09
thiyaguk09 requested a review from a team as a code owner June 29, 2026 14:16
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 2 times, most recently from 76c3932 to ea8daaa Compare July 10, 2026 12:30
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 5 times, most recently from a74b4bf to 657755f Compare July 27, 2026 06:48
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 7 times, most recently from c916584 to 6cb250f Compare August 4, 2026 06:08
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 8 times, most recently from 887f9a6 to 849cd96 Compare August 11, 2026 05:22
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 4 times, most recently from 29b9064 to 049fec0 Compare August 17, 2026 04:31
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 2 times, most recently from 87933ac to d769196 Compare August 19, 2026 04:43
this.encryptionKey !== null &&
newFile.encryptionKey === undefined
) {
newFile.setEncryptionKey(this.encryptionKey);

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

If a user is trying to copy the file to switch to a KMS key, will this block will still accidentally copy the old CSEK key and skip the KMS logic below ?

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The new !destinationKmsKeyName check added to the if condition prevents this. It safely skips the CSEK block and falls through to the KMS logic below.

@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch from d769196 to 7bea76e Compare August 20, 2026 02:43
Comment thread handwritten/storage/test/file.ts Outdated
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch 2 times, most recently from 165b855 to 659fe3a Compare August 25, 2026 09:27
@thiyaguk09
thiyaguk09 force-pushed the feat/7351-copy-csek-to-unencrypted branch from df1244d to b51b3cd Compare August 27, 2026 05:26
@Dhriti07
Dhriti07 merged commit 953328f into googleapis:main Aug 28, 2026
51 checks passed
danieljbruce pushed a commit that referenced this pull request Sep 8, 2026
🤖 I have created a release *beep* *boop*
---


##
[8.1.0](storage-v8.0.1...storage-v8.1.0)
(2026-09-08)


### Features

* **storage:** Add IpFilter support to bucket metadata
([#8623](#8623))
([30c91c8](30c91c8))
* **storage:** Add x-goog-gcs-idempotency-token header
([#8837](#8837))
([0df2e55](0df2e55))
* **storage:** Support copying CSEK-encrypted files to non-CSEK
destinations
([#8771](#8771))
([953328f](953328f))


### Bug Fixes

* **storage:** Resolve strict linter and TypeScript errors
([#9198](#9198))
([cee5338](cee5338))

---
This PR was generated with [Release
Please](https://github.com/googleapis/release-please). See
[documentation](https://github.com/googleapis/release-please#release-please).

Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
@thiyaguk09
thiyaguk09 deleted the feat/7351-copy-csek-to-unencrypted branch September 15, 2026 09:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

api: storage Issues related to the Cloud Storage API.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Ability to copy a file encrypted with customer-supplied key to a file without customer-supplied key

2 participants