mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
fix(aws-auth): better error logging
This commit is contained in:
@@ -21,6 +21,7 @@ import {
|
|||||||
UnauthorizedError
|
UnauthorizedError
|
||||||
} from "@app/lib/errors";
|
} from "@app/lib/errors";
|
||||||
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
import { extractIPDetails, isValidIpOrCidr } from "@app/lib/ip";
|
||||||
|
import { logger } from "@app/lib/logger";
|
||||||
|
|
||||||
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
import { ActorType, AuthTokenType } from "../auth/auth-type";
|
||||||
import { TIdentityDALFactory } from "../identity/identity-dal";
|
import { TIdentityDALFactory } from "../identity/identity-dal";
|
||||||
@@ -147,6 +148,8 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
if (identityAwsAuth.allowedPrincipalArns) {
|
if (identityAwsAuth.allowedPrincipalArns) {
|
||||||
// validate if Arn is in the list of allowed Principal ARNs
|
// validate if Arn is in the list of allowed Principal ARNs
|
||||||
|
|
||||||
|
const formattedArn = extractPrincipalArn(Arn);
|
||||||
|
|
||||||
const isArnAllowed = identityAwsAuth.allowedPrincipalArns
|
const isArnAllowed = identityAwsAuth.allowedPrincipalArns
|
||||||
.split(",")
|
.split(",")
|
||||||
.map((principalArn) => principalArn.trim())
|
.map((principalArn) => principalArn.trim())
|
||||||
@@ -155,13 +158,16 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
// considers exact matches + wildcard matches
|
// considers exact matches + wildcard matches
|
||||||
// heavily validated in router
|
// heavily validated in router
|
||||||
const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`);
|
const regex = new RE2(`^${principalArn.replaceAll("*", ".*")}$`);
|
||||||
return regex.test(extractPrincipalArn(Arn));
|
return regex.test(formattedArn);
|
||||||
});
|
});
|
||||||
|
|
||||||
if (!isArnAllowed)
|
if (!isArnAllowed) {
|
||||||
|
logger.info({ formattedArn, rawArn: Arn }, "Access denied: AWS principal ARN not allowed");
|
||||||
|
|
||||||
throw new UnauthorizedError({
|
throw new UnauthorizedError({
|
||||||
message: "Access denied: AWS principal ARN not allowed."
|
message: `Access denied: AWS principal ARN not allowed. [principal-arn=${formattedArn}]`
|
||||||
});
|
});
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => {
|
const identityAccessToken = await identityAwsAuthDAL.transaction(async (tx) => {
|
||||||
|
|||||||
Reference in New Issue
Block a user