diff --git a/backend/src/ee/services/pki-acme/pki-acme-challenge-service.ts b/backend/src/ee/services/pki-acme/pki-acme-challenge-service.ts index 9567072a1..f266aef98 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-challenge-service.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-challenge-service.ts @@ -86,7 +86,7 @@ export const pkiAcmeChallengeServiceFactory = ({ const { cause } = exp; let errors: Error[] = []; if (cause instanceof AggregateError) { - errors = cause.errors; + errors = cause.errors as Error[]; } else if (cause instanceof Error) { errors = [cause]; } @@ -97,6 +97,8 @@ export const pkiAcmeChallengeServiceFactory = ({ return new AcmeConnectionError({ message: "Connection refused" }); } else if (fetchError.code === "ENOTFOUND" || fetchError.message.includes("ENOTFOUND")) { return new AcmeDnsFailureError({ message: "Hostname could not be resolved (DNS failure)" }); + } else { + return new AcmeServerInternalError({ message: "Unknown error validating ACME challenge response" }); } } } else if (exp instanceof Error) { diff --git a/backend/src/ee/services/pki-acme/pki-acme-service.ts b/backend/src/ee/services/pki-acme/pki-acme-service.ts index 91e444e8d..dfde68891 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-service.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-service.ts @@ -222,6 +222,7 @@ export const pkiAcmeServiceFactory = ({ }; const validateExistingAccountJwsPayload = async < + // eslint-disable-next-line @typescript-eslint/no-explicit-any TSchema extends z.ZodSchema | undefined = undefined, T = TSchema extends z.ZodSchema ? R : string >({ @@ -385,7 +386,7 @@ export const pkiAcmeServiceFactory = ({ // Make sure the JWK in the EAB payload matches the one provided in the outer JWS payload const decoder = new TextDecoder(); const decodedEabPayload = decoder.decode(eabPayload); - const eabJWK = JSON.parse(decodedEabPayload); + const eabJWK = JSON.parse(decodedEabPayload) as JsonWebKey; const eabPayloadJwkThumbprint = await calculateJwkThumbprint(eabJWK, "sha256"); if (eabPayloadJwkThumbprint !== publicKeyThumbprint) { throw new AcmeBadPublicKeyError({