mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Merge pull request #3105 from Infisical/daniel/fix-secret-key
fix(api): disallow colon in secret name & allow updating malformed secret name
This commit is contained in:
@@ -36,11 +36,12 @@ const SecretReferenceNodeTree: z.ZodType<TSecretReferenceNode> = SecretReference
|
|||||||
children: z.lazy(() => SecretReferenceNodeTree.array())
|
children: z.lazy(() => SecretReferenceNodeTree.array())
|
||||||
});
|
});
|
||||||
|
|
||||||
const SecretNameSchema = z
|
const BaseSecretNameSchema = z.string().trim().min(1);
|
||||||
.string()
|
|
||||||
.trim()
|
const SecretNameSchema = BaseSecretNameSchema.refine(
|
||||||
.min(1)
|
(el) => !el.includes(" "),
|
||||||
.refine((el) => !el.includes(" "), "Secret name cannot contain spaces.");
|
"Secret name cannot contain spaces."
|
||||||
|
).refine((el) => !el.includes(":"), "Secret name cannot contain colon.");
|
||||||
|
|
||||||
export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
||||||
server.route({
|
server.route({
|
||||||
@@ -618,7 +619,7 @@ export const registerSecretRouter = async (server: FastifyZodProvider) => {
|
|||||||
}
|
}
|
||||||
],
|
],
|
||||||
params: z.object({
|
params: z.object({
|
||||||
secretName: SecretNameSchema.describe(RAW_SECRETS.UPDATE.secretName)
|
secretName: BaseSecretNameSchema.describe(RAW_SECRETS.UPDATE.secretName)
|
||||||
}),
|
}),
|
||||||
body: z.object({
|
body: z.object({
|
||||||
workspaceId: z.string().trim().describe(RAW_SECRETS.UPDATE.workspaceId),
|
workspaceId: z.string().trim().describe(RAW_SECRETS.UPDATE.workspaceId),
|
||||||
|
|||||||
Reference in New Issue
Block a user