mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Fix sa validation without ns
This commit is contained in:
@@ -127,7 +127,10 @@ export const kubernetesResourceFactory: TPamResourceFactory<
|
|||||||
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
if (authMethod === KubernetesAuthMethod.ServiceAccountToken) {
|
||||||
// Validate service account token by making an authenticated API call
|
// Validate service account token by making an authenticated API call
|
||||||
try {
|
try {
|
||||||
await axios.get(`${baseUrl}/api/v1/namespaces/${connectionDetails.namespace}`, {
|
// TODO: is this the best API endpoint to use for validation?
|
||||||
|
// the SA may not have access to list ns
|
||||||
|
// maybe we should use a more specific API endpoint?
|
||||||
|
await axios.get(`${baseUrl}/api/v1/namespaces`, {
|
||||||
headers: {
|
headers: {
|
||||||
"Content-Type": "application/json",
|
"Content-Type": "application/json",
|
||||||
Authorization: `Bearer ${credentials.serviceAccountToken}`
|
Authorization: `Bearer ${credentials.serviceAccountToken}`
|
||||||
@@ -137,10 +140,7 @@ export const kubernetesResourceFactory: TPamResourceFactory<
|
|||||||
timeout: EXTERNAL_REQUEST_TIMEOUT
|
timeout: EXTERNAL_REQUEST_TIMEOUT
|
||||||
});
|
});
|
||||||
|
|
||||||
logger.info(
|
logger.info("[Kubernetes Resource Factory] Kubernetes service account token authentication successful");
|
||||||
{ namespace: connectionDetails.namespace },
|
|
||||||
"[Kubernetes Resource Factory] Kubernetes service account token authentication successful"
|
|
||||||
);
|
|
||||||
} catch (error) {
|
} catch (error) {
|
||||||
if (error instanceof AxiosError) {
|
if (error instanceof AxiosError) {
|
||||||
if (error.response?.status === 401 || error.response?.status === 403) {
|
if (error.response?.status === 401 || error.response?.status === 403) {
|
||||||
|
|||||||
Reference in New Issue
Block a user