Merge pull request #4735 from Infisical/daniel/aws-arn-validation-fix

fix: backwards compatibility for assumed roles as role formatting
This commit is contained in:
Daniel Hougaard
2025-10-23 22:23:08 +04:00
committed by GitHub
2 changed files with 6 additions and 6 deletions
@@ -8,7 +8,7 @@ interface PrincipalArnEntity {
SessionInfo: string; // Only populated for assumed-role SessionInfo: string; // Only populated for assumed-role
} }
export const extractPrincipalArnEntity = (arn: string): PrincipalArnEntity => { export const extractPrincipalArnEntity = (arn: string, formatAsIamRole: boolean = false): PrincipalArnEntity => {
// split the ARN into parts using ":" as the delimiter // split the ARN into parts using ":" as the delimiter
const fullParts = arn.split(":"); const fullParts = arn.split(":");
if (fullParts.length !== 6) { if (fullParts.length !== 6) {
@@ -49,7 +49,7 @@ export const extractPrincipalArnEntity = (arn: string): PrincipalArnEntity => {
} }
// assumed roles use a special format where the friendly name is the role name // assumed roles use a special format where the friendly name is the role name
const [roleName, sessionId] = rest; const [roleName, sessionId] = rest;
finalType = "assumed-role"; finalType = formatAsIamRole ? "role" : "assumed-role";
friendlyName = roleName; friendlyName = roleName;
sessionInfo = sessionId; sessionInfo = sessionId;
break; break;
@@ -84,8 +84,8 @@ export const extractPrincipalArnEntity = (arn: string): PrincipalArnEntity => {
* - arn:aws:iam::123456789012:user/MyUserName * - arn:aws:iam::123456789012:user/MyUserName
* - arn:aws:iam::123456789012:role/MyRoleName * - arn:aws:iam::123456789012:role/MyRoleName
*/ */
export const extractPrincipalArn = (arn: string) => { export const extractPrincipalArn = (arn: string, formatAsIamRole: boolean = false) => {
const entity = extractPrincipalArnEntity(arn); const entity = extractPrincipalArnEntity(arn, formatAsIamRole);
return `arn:aws:${entity.Service}::${entity.AccountNumber}:${entity.Type}/${entity.FriendlyName}`; return `arn:aws:${formatAsIamRole ? "iam" : entity.Service}::${entity.AccountNumber}:${entity.Type}/${entity.FriendlyName}`;
}; };
@@ -158,7 +158,7 @@ export const identityAwsAuthServiceFactory = ({
// considers exact matches + wildcard matches // considers exact matches + wildcard matches
// heavily validated in router // heavily validated in router
const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`); const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`);
return regex.test(formattedArn); return regex.test(formattedArn) || regex.test(extractPrincipalArn(Arn, true));
}); });
if (!isArnAllowed) { if (!isArnAllowed) {