mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 14:28:20 +00:00
Review fixes
This commit is contained in:
@@ -41,7 +41,10 @@ export const registerIdentityAliCloudAuthRouter = async (server: FastifyZodProvi
|
|||||||
SignatureMethod: z.enum(["HMAC-SHA1"]).describe(ALICLOUD_AUTH.LOGIN.SignatureMethod),
|
SignatureMethod: z.enum(["HMAC-SHA1"]).describe(ALICLOUD_AUTH.LOGIN.SignatureMethod),
|
||||||
Timestamp: z
|
Timestamp: z
|
||||||
.string()
|
.string()
|
||||||
.refine((val) => new RE2("^\\d{4}-\\d{2}-\\d{2}T\\d{2}:\\d{2}:\\d{2}Z$").test(val), {
|
.datetime({
|
||||||
|
message: "Timestamp must be in YYYY-MM-DDTHH:mm:ssZ format"
|
||||||
|
})
|
||||||
|
.refine((val) => val.endsWith("Z"), {
|
||||||
message: "Timestamp must be in YYYY-MM-DDTHH:mm:ssZ format"
|
message: "Timestamp must be in YYYY-MM-DDTHH:mm:ssZ format"
|
||||||
})
|
})
|
||||||
.describe(ALICLOUD_AUTH.LOGIN.Timestamp),
|
.describe(ALICLOUD_AUTH.LOGIN.Timestamp),
|
||||||
|
|||||||
@@ -64,16 +64,16 @@ export const identityAliCloudAuthServiceFactory = ({
|
|||||||
identityId: identityAliCloudAuth.identityId
|
identityId: identityAliCloudAuth.identityId
|
||||||
});
|
});
|
||||||
|
|
||||||
const queryString = Object.keys(params)
|
const requestUrl = new URL("https://sts.aliyuncs.com");
|
||||||
.map((key) => `${encodeURIComponent(key)}=${encodeURIComponent((params as Record<string, string>)[key])}`)
|
|
||||||
.join("&");
|
|
||||||
|
|
||||||
const { data } = await request
|
for (const key of Object.keys(params)) {
|
||||||
.get<TAliCloudGetUserResponse>(`https://sts.aliyuncs.com/?${queryString}`)
|
requestUrl.searchParams.set(key, (params as Record<string, string>)[key]);
|
||||||
.catch((err: AxiosError) => {
|
}
|
||||||
logger.error(err.response, "AliCloudIdentityLogin: Failed to authenticate with Alibaba Cloud");
|
|
||||||
throw err;
|
const { data } = await request.get<TAliCloudGetUserResponse>(requestUrl.toString()).catch((err: AxiosError) => {
|
||||||
});
|
logger.error(err.response, "AliCloudIdentityLogin: Failed to authenticate with Alibaba Cloud");
|
||||||
|
throw err;
|
||||||
|
});
|
||||||
|
|
||||||
if (identityAliCloudAuth.allowedArns) {
|
if (identityAliCloudAuth.allowedArns) {
|
||||||
// In the future we could do partial checks for role ARNs
|
// In the future we could do partial checks for role ARNs
|
||||||
|
|||||||
@@ -148,7 +148,7 @@ const params: { [key: string]: string } = {
|
|||||||
Version: "2015-04-01",
|
Version: "2015-04-01",
|
||||||
AccessKeyId: ALICLOUD_ACCESS_KEY_ID,
|
AccessKeyId: ALICLOUD_ACCESS_KEY_ID,
|
||||||
SignatureMethod: "HMAC-SHA1",
|
SignatureMethod: "HMAC-SHA1",
|
||||||
Timestamp: new Date().toISOString().replace(/\.\d{3}Z$/, "Z"),
|
Timestamp: new Date().toISOString(),
|
||||||
SignatureVersion: "1.0",
|
SignatureVersion: "1.0",
|
||||||
SignatureNonce: crypto.randomBytes(16).toString("hex"),
|
SignatureNonce: crypto.randomBytes(16).toString("hex"),
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user