Fix linter error

This commit is contained in:
Fang-Pen Lin
2025-11-21 10:30:57 -08:00
parent 7c477ef027
commit 2b19425cc7
@@ -1719,15 +1719,17 @@ export const internalCertificateAuthorityServiceFactory = ({
const dn = parseDistinguishedName(csrObj.subject); const dn = parseDistinguishedName(csrObj.subject);
let cn = commonName || dn.commonName; let cn = commonName || dn.commonName;
if ((allowEmptyCommonName ?? false) && !cn) { if (!cn) {
// Notice: for modern TLS certificates, the CN is deprecated, many ACME clients will generate CSRs with without a CN if (allowEmptyCommonName ?? false) {
// we allow empty CN here to support ACME clients mostly. Since it's unclear what's the side effect of // Notice: for modern TLS certificates, the CN is deprecated, many ACME clients will generate CSRs with without a CN
// allowing empty CN for legacy PKI code, let's only do it if a true allowEmptyCommonName value is provided. // we allow empty CN here to support ACME clients mostly. Since it's unclear what's the side effect of
cn = ""; // allowing empty CN for legacy PKI code, let's only do it if a true allowEmptyCommonName value is provided.
} else if (!cn) { cn = "";
throw new BadRequestError({ } else {
message: "A common name (CN) is required in the CSR or as a parameter to this endpoint" throw new BadRequestError({
}); message: "A common name (CN) is required in the CSR or as a parameter to this endpoint"
});
}
} }
const { caPrivateKey, caSecret } = await getCaCredentials({ const { caPrivateKey, caSecret } = await getCaCredentials({
@@ -1946,7 +1948,7 @@ export const internalCertificateAuthorityServiceFactory = ({
certificateTemplateId: certificateTemplate?.id, certificateTemplateId: certificateTemplate?.id,
status: CertStatus.ACTIVE, status: CertStatus.ACTIVE,
friendlyName: friendlyName || csrObj.subject, friendlyName: friendlyName || csrObj.subject,
commonName: cn, commonName: cn!,
altNames: altNamesFromCsr || altNames, altNames: altNamesFromCsr || altNames,
serialNumber, serialNumber,
notBefore: notBeforeDate, notBefore: notBeforeDate,