mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
improvements: address feedback
This commit is contained in:
@@ -1,4 +1,3 @@
|
|||||||
import RE2 from "re2";
|
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { LdapPasswordRotationMethod } from "@app/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types";
|
import { LdapPasswordRotationMethod } from "@app/ee/services/secret-rotation-v2/ldap-password/ldap-password-rotation-types";
|
||||||
@@ -28,7 +27,7 @@ const LdapPasswordRotationParametersSchema = z.object({
|
|||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
.min(1, "DN/UPN required")
|
.min(1, "DN/UPN required")
|
||||||
.refine((value) => new RE2(DistinguishedNameRegex).test(value) || new RE2(UserPrincipalNameRegex).test(value), {
|
.refine((value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), {
|
||||||
message: "Invalid DN/UPN format"
|
message: "Invalid DN/UPN format"
|
||||||
})
|
})
|
||||||
.describe(SecretRotations.PARAMETERS.LDAP_PASSWORD.dn),
|
.describe(SecretRotations.PARAMETERS.LDAP_PASSWORD.dn),
|
||||||
|
|||||||
@@ -1,5 +1,11 @@
|
|||||||
|
import RE2 from "re2";
|
||||||
|
|
||||||
export const DistinguishedNameRegex =
|
export const DistinguishedNameRegex =
|
||||||
// DN format, ie; CN=user,OU=users,DC=example,DC=com
|
// DN format, ie; CN=user,OU=users,DC=example,DC=com
|
||||||
/^(?:(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*)(?:,(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*))*)?$/;
|
new RE2(
|
||||||
|
/^(?:(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*)(?:,(?:[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)(?:(?:\\+[a-zA-Z0-9]+=[^,+="<>#;\\\\]+)*))*)?$/
|
||||||
|
);
|
||||||
|
|
||||||
export const UserPrincipalNameRegex = /^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}$/;
|
export const UserPrincipalNameRegex = new RE2(/^[a-zA-Z0-9._%+-]+@[a-zA-Z0-9._-]+\.[a-zA-Z]{2,}$/);
|
||||||
|
|
||||||
|
export const LdapUrlRegex = new RE2(/^ldaps?:\/\//);
|
||||||
|
|||||||
@@ -1,8 +1,7 @@
|
|||||||
import RE2 from "re2";
|
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
import { AppConnections } from "@app/lib/api-docs";
|
import { AppConnections } from "@app/lib/api-docs";
|
||||||
import { DistinguishedNameRegex, UserPrincipalNameRegex } from "@app/lib/regex";
|
import { DistinguishedNameRegex, LdapUrlRegex, UserPrincipalNameRegex } from "@app/lib/regex";
|
||||||
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
import { AppConnection } from "@app/services/app-connection/app-connection-enums";
|
||||||
import {
|
import {
|
||||||
BaseAppConnectionSchema,
|
BaseAppConnectionSchema,
|
||||||
@@ -14,17 +13,12 @@ import { LdapConnectionMethod, LdapProvider } from "./ldap-connection-enums";
|
|||||||
|
|
||||||
export const LdapConnectionSimpleBindCredentialsSchema = z.object({
|
export const LdapConnectionSimpleBindCredentialsSchema = z.object({
|
||||||
provider: z.nativeEnum(LdapProvider).describe(AppConnections.CREDENTIALS.LDAP.provider),
|
provider: z.nativeEnum(LdapProvider).describe(AppConnections.CREDENTIALS.LDAP.provider),
|
||||||
url: z
|
url: z.string().trim().min(1, "URL required").regex(LdapUrlRegex).describe(AppConnections.CREDENTIALS.LDAP.url),
|
||||||
.string()
|
|
||||||
.trim()
|
|
||||||
.min(1, "URL required")
|
|
||||||
.regex(new RE2(/^ldaps?:\/\//))
|
|
||||||
.describe(AppConnections.CREDENTIALS.LDAP.url),
|
|
||||||
dn: z
|
dn: z
|
||||||
.string()
|
.string()
|
||||||
.trim()
|
.trim()
|
||||||
.min(1, "DN/UPN required")
|
.min(1, "DN/UPN required")
|
||||||
.refine((value) => new RE2(DistinguishedNameRegex).test(value) || new RE2(UserPrincipalNameRegex).test(value), {
|
.refine((value) => DistinguishedNameRegex.test(value) || UserPrincipalNameRegex.test(value), {
|
||||||
message: "Invalid DN/UPN format"
|
message: "Invalid DN/UPN format"
|
||||||
})
|
})
|
||||||
.describe(AppConnections.CREDENTIALS.LDAP.dn),
|
.describe(AppConnections.CREDENTIALS.LDAP.dn),
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ import { Controller, useFormContext } from "react-hook-form";
|
|||||||
|
|
||||||
import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas";
|
import { TSecretRotationV2Form } from "@app/components/secret-rotations-v2/forms/schemas";
|
||||||
import { DEFAULT_PASSWORD_REQUIREMENTS } from "@app/components/secret-rotations-v2/forms/schemas/shared";
|
import { DEFAULT_PASSWORD_REQUIREMENTS } from "@app/components/secret-rotations-v2/forms/schemas/shared";
|
||||||
import { FormControl, Input, Select, SelectItem } from "@app/components/v2";
|
import { FormControl, Input, SecretInput, Select, SelectItem } from "@app/components/v2";
|
||||||
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
import { SecretRotation } from "@app/hooks/api/secretRotationsV2";
|
||||||
import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation";
|
import { LdapPasswordRotationMethod } from "@app/hooks/api/secretRotationsV2/types/ldap-password-rotation";
|
||||||
|
|
||||||
@@ -84,7 +84,7 @@ export const LdapPasswordRotationParametersFields = () => {
|
|||||||
isError={Boolean(error)}
|
isError={Boolean(error)}
|
||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
label="Target Principal's DN/UPN"
|
label="Target Principal's DN/UPN"
|
||||||
tooltipText="The DN/UPN of the principal that you want to peform password rotation on."
|
tooltipText="The DN/UPN of the principal that you want to perform password rotation on."
|
||||||
tooltipClassName="max-w-sm"
|
tooltipClassName="max-w-sm"
|
||||||
helperText={isUpdate ? "Cannot be updated." : undefined}
|
helperText={isUpdate ? "Cannot be updated." : undefined}
|
||||||
>
|
>
|
||||||
@@ -108,7 +108,11 @@ export const LdapPasswordRotationParametersFields = () => {
|
|||||||
errorText={error?.message}
|
errorText={error?.message}
|
||||||
label="Target Principal's Password"
|
label="Target Principal's Password"
|
||||||
>
|
>
|
||||||
<Input value={value} onChange={onChange} placeholder="***********************" />
|
<SecretInput
|
||||||
|
containerClassName="text-gray-400 group-focus-within:!border-primary-400/50 border border-mineshaft-500 bg-mineshaft-900 px-2.5 py-1.5"
|
||||||
|
value={value}
|
||||||
|
onChange={(e) => onChange(e.target.value)}
|
||||||
|
/>
|
||||||
</FormControl>
|
</FormControl>
|
||||||
)}
|
)}
|
||||||
/>
|
/>
|
||||||
|
|||||||
@@ -15,7 +15,7 @@ export type TLdapPasswordRotation = TSecretRotationV2Base & {
|
|||||||
type: SecretRotation.LdapPassword;
|
type: SecretRotation.LdapPassword;
|
||||||
parameters: {
|
parameters: {
|
||||||
dn: string;
|
dn: string;
|
||||||
method?: LdapPasswordRotationMethod;
|
rotationMethod?: LdapPasswordRotationMethod;
|
||||||
passwordRequirements?: TPasswordRequirements;
|
passwordRequirements?: TPasswordRequirements;
|
||||||
};
|
};
|
||||||
secretsMapping: {
|
secretsMapping: {
|
||||||
|
|||||||
Reference in New Issue
Block a user