Improve requested user/host validation for ssh certificate template

This commit is contained in:
Tuan Dang
2024-12-03 23:22:04 -08:00
parent 00ce755996
commit 8edfa9ad0b
2 changed files with 54 additions and 18 deletions
@@ -130,7 +130,7 @@ export const sshCertificateTemplateServiceFactory = ({
if (name) { if (name) {
const existingTemplate = await sshCertificateTemplateDAL.getByName(name, actorOrgId); const existingTemplate = await sshCertificateTemplateDAL.getByName(name, actorOrgId);
if (existingTemplate) { if (existingTemplate && existingTemplate.id !== id) {
throw new BadRequestError({ throw new BadRequestError({
message: `SSH certificate template with name ${name} already exists` message: `SSH certificate template with name ${name} already exists`
}); });
@@ -122,34 +122,70 @@ export const validateSshCertificatePrincipals = (
) => { ) => {
switch (certType) { switch (certType) {
case SshCertType.USER: { case SshCertType.USER: {
const allowsAllUsers = template.allowedUsers?.includes("*") ?? false; if (template.allowedUsers.length === 0) {
return principals.every((principal) => { throw new BadRequestError({
if (principal === "*") return false; message: "No allowed users are configured in the SSH certificate template."
if (allowsAllUsers) return isValidUserPattern(principal); });
return template.allowedUsers?.includes(principal); }
const allowsAllUsers = template.allowedUsers.includes("*") ?? false;
principals.forEach((principal) => {
if (principal === "*") {
throw new BadRequestError({
message: `Principal '*' is not allowed for user certificates.`
});
}
if (allowsAllUsers && !isValidUserPattern(principal)) {
throw new BadRequestError({
message: `Principal '${principal}' does not match a valid user pattern.`
});
}
if (!allowsAllUsers && !template.allowedUsers.includes(principal)) {
throw new BadRequestError({
message: `Principal '${principal}' is not in the list of allowed users.`
});
}
}); });
break;
} }
case SshCertType.HOST: { case SshCertType.HOST: {
const allowsAllHosts = template.allowedHosts?.includes("*") ?? false; if (template.allowedHosts.length === 0) {
return principals.every((principal) => { throw new BadRequestError({
if (principal.includes("*")) return false; message: "No allowed hosts are configured in the SSH certificate template."
if (allowsAllHosts) return isValidHostPattern(principal); });
}
// Validate against allowed domains const allowsAllHosts = template.allowedHosts.includes("*") ?? false;
return (
isValidHostPattern(principal) && principals.forEach((principal) => {
template.allowedHosts?.some((allowedHost) => { if (principal.includes("*")) {
throw new BadRequestError({
message: `Principal '${principal}' with wildcards is not allowed for host certificates.`
});
}
if (allowsAllHosts && !isValidHostPattern(principal)) {
throw new BadRequestError({
message: `Principal '${principal}' does not match a valid host pattern.`
});
}
if (
!allowsAllHosts &&
!template.allowedHosts.some((allowedHost) => {
if (allowedHost.startsWith("*.")) { if (allowedHost.startsWith("*.")) {
// Match subdomains of a wildcard domain
const baseDomain = allowedHost.slice(2); // Remove the leading "*." const baseDomain = allowedHost.slice(2); // Remove the leading "*."
return principal.endsWith(`.${baseDomain}`); return principal.endsWith(`.${baseDomain}`);
} }
// Exact match for non-wildcard domains
return principal === allowedHost; return principal === allowedHost;
}) })
); ) {
throw new BadRequestError({
message: `Principal '${principal}' is not in the list of allowed hosts or domains.`
});
}
}); });
break;
} }
default: default:
throw new BadRequestError({ throw new BadRequestError({