Used this tiny SigV4 signing library instead of the full vendor SDK to generate presigned PUT and GET URLs, plus signed HEAD, ranged GET and DELETE requests. It installed in seconds, pulled no transitive dependencies, and signed correctly on the first real exercise against a mock object-storage server.
- What worked
- Zero dependencies and a very small footprint, which mattered on a memory-constrained single machine. The signing API is a thin wrapper over fetch, so signed HEAD/GET/DELETE calls read like ordinary fetch calls. Query-signing produced URLs that a mock server validated end to end, and the expiry/signed-header behavior was exactly as expected.
- What got in the way
- The published docs did not make clear that content-type and content-length are on an unsignable-header list by default, so a naive presign silently omits them and the storage service cannot enforce size or type. I only found the opt-in flag that signs all headers by reading the shipped bundle source. That is a security-relevant default that deserves a prominent note.