mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 19:28:16 +00:00
Merge pull request #4742 from Infisical/fix/gov-cloud-arn-validation
fix: support GovCloud (US) ARNs
This commit is contained in:
@@ -83,9 +83,11 @@ export const extractPrincipalArnEntity = (arn: string, formatAsIamRole: boolean
|
|||||||
* Extracts the identity ARN from the GetCallerIdentity response to one of the following formats:
|
* Extracts the identity ARN from the GetCallerIdentity response to one of the following formats:
|
||||||
* - arn:aws:iam::123456789012:user/MyUserName
|
* - arn:aws:iam::123456789012:user/MyUserName
|
||||||
* - arn:aws:iam::123456789012:role/MyRoleName
|
* - arn:aws:iam::123456789012:role/MyRoleName
|
||||||
|
* - arn:aws-us-gov:iam::123456789012:user/MyUserName (GovCloud)
|
||||||
|
* - arn:aws-us-gov:iam::123456789012:role/MyRoleName (GovCloud)
|
||||||
*/
|
*/
|
||||||
export const extractPrincipalArn = (arn: string, formatAsIamRole: boolean = false) => {
|
export const extractPrincipalArn = (arn: string, formatAsIamRole: boolean = false) => {
|
||||||
const entity = extractPrincipalArnEntity(arn, formatAsIamRole);
|
const entity = extractPrincipalArnEntity(arn, formatAsIamRole);
|
||||||
|
|
||||||
return `arn:aws:${formatAsIamRole ? "iam" : entity.Service}::${entity.AccountNumber}:${entity.Type}/${entity.FriendlyName}`;
|
return `arn:${entity.Partition}:${formatAsIamRole ? "iam" : entity.Service}::${entity.AccountNumber}:${entity.Type}/${entity.FriendlyName}`;
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ const twelveDigitRegex = new RE2(/^\d{12}$/);
|
|||||||
// akhilmhdh: change this to a normal function later. Checked no redosable at the moment
|
// akhilmhdh: change this to a normal function later. Checked no redosable at the moment
|
||||||
|
|
||||||
const arnRegex = new RE2(
|
const arnRegex = new RE2(
|
||||||
/^arn:aws:(iam|sts)::\d{12}:(user\/[a-zA-Z0-9_.@+*/-]+|role\/[a-zA-Z0-9_.@+*/-]+|assumed-role\/[a-zA-Z0-9_.@+*/-]+|\*)$/
|
/^arn:aws(?:-us-gov)?:(iam|sts)::\d{12}:(user\/[a-zA-Z0-9_.@+*/-]+|role\/[a-zA-Z0-9_.@+*/-]+|assumed-role\/[a-zA-Z0-9_.@+*/-]+|\*)$/
|
||||||
);
|
);
|
||||||
|
|
||||||
export const validateAccountIds = z
|
export const validateAccountIds = z
|
||||||
@@ -55,7 +55,7 @@ export const validatePrincipalArns = z
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
message:
|
message:
|
||||||
"Each ARN must be in the format of 'arn:aws:iam::123456789012:user/UserName', 'arn:aws:iam::123456789012:role/RoleName', or 'arn:aws:iam::123456789012:*', 'arn:aws:sts::123456789012:assumed-role/RoleName'."
|
"Each ARN must be in the format of 'arn:aws:iam::123456789012:user/UserName', 'arn:aws:iam::123456789012:role/RoleName', or 'arn:aws:iam::123456789012:*', 'arn:aws:sts::123456789012:assumed-role/RoleName'. GovCloud ARNs (arn:aws-us-gov:...) are also supported."
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
// Transform to normalize the spaces around commas
|
// Transform to normalize the spaces around commas
|
||||||
|
|||||||
Reference in New Issue
Block a user