Repository navigation
feat(storage): support copying CSEK-encrypted files to non-CSEK destinations - #8771
Conversation
There was a problem hiding this comment.
Code Review
This pull request introduces support for setting a File's encryption key to null, enabling the copying of a Customer-Supplied Encryption Key (CSEK) encrypted file to a standard non-CSEK destination. Feedback on the changes highlights a critical async bug and race condition in the copy method, where this.getRequestInterceptors is temporarily overridden synchronously around an asynchronous request. Because the request pipeline runs asynchronously, the synchronous restoration happens too early, and concurrent operations on the same File instance will interfere with each other. The reviewer recommends isolating custom interceptors using request-scoped configuration instead of modifying the shared instance.
76c3932 to
ea8daaa
Compare
a74b4bf to
657755f
Compare
c916584 to
6cb250f
Compare
887f9a6 to
849cd96
Compare
29b9064 to
049fec0
Compare
87933ac to
d769196
Compare
| this.encryptionKey !== null && | ||
| newFile.encryptionKey === undefined | ||
| ) { | ||
| newFile.setEncryptionKey(this.encryptionKey); |
There was a problem hiding this comment.
If a user is trying to copy the file to switch to a KMS key, will this block will still accidentally copy the old CSEK key and skip the KMS logic below ?
There was a problem hiding this comment.
The new !destinationKmsKeyName check added to the if condition prevents this. It safely skips the CSEK block and falls through to the KMS logic below.
d769196 to
7bea76e
Compare
165b855 to
659fe3a
Compare
…SEK and fix copy behavior for non-encrypted destinations
…r conflicts during file copy operations
…t instead of file request
…d fix system test service account binding
…riority during copy operations
…of file request overrides
df1244d to
b51b3cd
Compare
🤖 I have created a release *beep* *boop* --- ## [8.1.0](storage-v8.0.1...storage-v8.1.0) (2026-09-08) ### Features * **storage:** Add IpFilter support to bucket metadata ([#8623](#8623)) ([30c91c8](30c91c8)) * **storage:** Add x-goog-gcs-idempotency-token header ([#8837](#8837)) ([0df2e55](0df2e55)) * **storage:** Support copying CSEK-encrypted files to non-CSEK destinations ([#8771](#8771)) ([953328f](953328f)) ### Bug Fixes * **storage:** Resolve strict linter and TypeScript errors ([#9198](#9198)) ([cee5338](cee5338)) --- This PR was generated with [Release Please](https://github.com/googleapis/release-please). See [documentation](https://github.com/googleapis/release-please#release-please). Co-authored-by: release-please[bot] <55107282+release-please[bot]@users.noreply.github.com>
Thank you for opening a Pull Request! Before submitting your PR, there are a few things you can do to make sure it goes smoothly:
Fixes #7351