mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Review fixes
This commit is contained in:
@@ -41,7 +41,10 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi
|
||||
SignatureMethod: z.enum(["HMAC-SHA1"]).describe(ALICLOUD_AUTH.LOGIN.SignatureMethod),
|
||||
Timestamp: z
|
||||
.string()
|
||||
.refine((val) => new RE2("^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}Z$").test(val), {
|
||||
.datetime({
|
||||
message: "Timestamp must be in YYYY-MM-DDTHH:mm:ssZ format"
|
||||
})
|
||||
.refine((val) => val.endsWith("Z"), {
|
||||
message: "Timestamp must be in YYYY-MM-DDTHH:mm:ssZ format"
|
||||
})
|
||||
.describe(ALICLOUD_AUTH.LOGIN.Timestamp),
|
||||
|
||||
@@ -64,16 +64,16 @@ export const identityAliCloudAuthServiceFactory = ({
|
||||
identityId: identityAliCloudAuth.identityId
|
||||
});
|
||||
|
||||
const queryString = Object.keys(params)
|
||||
.map((key) => `${encodeURIComponent(key)}=${encodeURIComponent((params as Record<string, string>)[key])}`)
|
||||
.join("&");
|
||||
const requestUrl = new URL("https://sts.aliyuncs.com");
|
||||
|
||||
const { data } = await request
|
||||
.get<TAliCloudGetUserResponse>(`https://sts.aliyuncs.com/?${queryString}`)
|
||||
.catch((err: AxiosError) => {
|
||||
logger.error(err.response, "AliCloudIdentityLogin: Failed to authenticate with Alibaba Cloud");
|
||||
throw err;
|
||||
});
|
||||
for (const key of Object.keys(params)) {
|
||||
requestUrl.searchParams.set(key, (params as Record<string, string>)[key]);
|
||||
}
|
||||
|
||||
const { data } = await request.get<TAliCloudGetUserResponse>(requestUrl.toString()).catch((err: AxiosError) => {
|
||||
logger.error(err.response, "AliCloudIdentityLogin: Failed to authenticate with Alibaba Cloud");
|
||||
throw err;
|
||||
});
|
||||
|
||||
if (identityAliCloudAuth.allowedArns) {
|
||||
// In the future we could do partial checks for role ARNs
|
||||
|
||||
@@ -148,7 +148,7 @@ const params: { [key: string]: string } = {
|
||||
Version: "2015-04-01",
|
||||
AccessKeyId: ALICLOUD_ACCESS_KEY_ID,
|
||||
SignatureMethod: "HMAC-SHA1",
|
||||
Timestamp: new Date().toISOString().replace(/\.\d{3}Z$/, "Z"),
|
||||
Timestamp: new Date().toISOString(),
|
||||
SignatureVersion: "1.0",
|
||||
SignatureNonce: crypto.randomBytes(16).toString("hex"),
|
||||
};
|
||||
|
||||
Reference in New Issue
Block a user