mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
Update identity-azure-auth-fns.ts
This commit is contained in:
@@ -17,6 +17,7 @@ export const validateAzureIdentity = async ({
|
|||||||
const jwksUri = `https://login.microsoftonline.com/${tenantId}/discovery/keys`;
|
const jwksUri = `https://login.microsoftonline.com/${tenantId}/discovery/keys`;
|
||||||
|
|
||||||
const decodedJwt = jwt.decode(azureJwt, { complete: true }) as TDecodedAzureAuthJwt;
|
const decodedJwt = jwt.decode(azureJwt, { complete: true }) as TDecodedAzureAuthJwt;
|
||||||
|
|
||||||
const { kid } = decodedJwt.header;
|
const { kid } = decodedJwt.header;
|
||||||
|
|
||||||
const { data }: { data: TAzureJwksUriResponse } = await axios.get(jwksUri);
|
const { data }: { data: TAzureJwksUriResponse } = await axios.get(jwksUri);
|
||||||
@@ -27,6 +28,13 @@ export const validateAzureIdentity = async ({
|
|||||||
|
|
||||||
const publicKey = `-----BEGIN CERTIFICATE-----\n${signingKey.x5c[0]}\n-----END CERTIFICATE-----`;
|
const publicKey = `-----BEGIN CERTIFICATE-----\n${signingKey.x5c[0]}\n-----END CERTIFICATE-----`;
|
||||||
|
|
||||||
|
// Case: This can happen when the user uses a custom resource (such as https://management.azure.com&client_id=value).
|
||||||
|
// In this case, the audience in the decoded JWT will not have a trailing slash, but the resource will.
|
||||||
|
if (!decodedJwt.payload.aud.endsWith("/") && resource.endsWith("/")) {
|
||||||
|
// eslint-disable-next-line no-param-reassign
|
||||||
|
resource = resource.slice(0, -1);
|
||||||
|
}
|
||||||
|
|
||||||
return jwt.verify(azureJwt, publicKey, {
|
return jwt.verify(azureJwt, publicKey, {
|
||||||
audience: resource,
|
audience: resource,
|
||||||
issuer: `https://sts.windows.net/${tenantId}/`
|
issuer: `https://sts.windows.net/${tenantId}/`
|
||||||
|
|||||||
Reference in New Issue
Block a user