mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-06 22:27:22 +00:00
Improve requested user/host validation for ssh certificate template
This commit is contained in:
+1
-1
@@ -130,7 +130,7 @@ export const sshCertificateTemplateServiceFactory = ({
|
|||||||
|
|
||||||
if (name) {
|
if (name) {
|
||||||
const existingTemplate = await sshCertificateTemplateDAL.getByName(name, actorOrgId);
|
const existingTemplate = await sshCertificateTemplateDAL.getByName(name, actorOrgId);
|
||||||
if (existingTemplate) {
|
if (existingTemplate && existingTemplate.id !== id) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message: `SSH certificate template with name ${name} already exists`
|
message: `SSH certificate template with name ${name} already exists`
|
||||||
});
|
});
|
||||||
|
|||||||
@@ -122,34 +122,70 @@ export const validateSshCertificatePrincipals = (
|
|||||||
) => {
|
) => {
|
||||||
switch (certType) {
|
switch (certType) {
|
||||||
case SshCertType.USER: {
|
case SshCertType.USER: {
|
||||||
const allowsAllUsers = template.allowedUsers?.includes("*") ?? false;
|
if (template.allowedUsers.length === 0) {
|
||||||
return principals.every((principal) => {
|
throw new BadRequestError({
|
||||||
if (principal === "*") return false;
|
message: "No allowed users are configured in the SSH certificate template."
|
||||||
if (allowsAllUsers) return isValidUserPattern(principal);
|
});
|
||||||
return template.allowedUsers?.includes(principal);
|
}
|
||||||
|
|
||||||
|
const allowsAllUsers = template.allowedUsers.includes("*") ?? false;
|
||||||
|
|
||||||
|
principals.forEach((principal) => {
|
||||||
|
if (principal === "*") {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '*' is not allowed for user certificates.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (allowsAllUsers && !isValidUserPattern(principal)) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '${principal}' does not match a valid user pattern.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (!allowsAllUsers && !template.allowedUsers.includes(principal)) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '${principal}' is not in the list of allowed users.`
|
||||||
|
});
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
break;
|
||||||
}
|
}
|
||||||
case SshCertType.HOST: {
|
case SshCertType.HOST: {
|
||||||
const allowsAllHosts = template.allowedHosts?.includes("*") ?? false;
|
if (template.allowedHosts.length === 0) {
|
||||||
return principals.every((principal) => {
|
throw new BadRequestError({
|
||||||
if (principal.includes("*")) return false;
|
message: "No allowed hosts are configured in the SSH certificate template."
|
||||||
if (allowsAllHosts) return isValidHostPattern(principal);
|
});
|
||||||
|
}
|
||||||
|
|
||||||
// Validate against allowed domains
|
const allowsAllHosts = template.allowedHosts.includes("*") ?? false;
|
||||||
return (
|
|
||||||
isValidHostPattern(principal) &&
|
principals.forEach((principal) => {
|
||||||
template.allowedHosts?.some((allowedHost) => {
|
if (principal.includes("*")) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '${principal}' with wildcards is not allowed for host certificates.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
if (allowsAllHosts && !isValidHostPattern(principal)) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '${principal}' does not match a valid host pattern.`
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
if (
|
||||||
|
!allowsAllHosts &&
|
||||||
|
!template.allowedHosts.some((allowedHost) => {
|
||||||
if (allowedHost.startsWith("*.")) {
|
if (allowedHost.startsWith("*.")) {
|
||||||
// Match subdomains of a wildcard domain
|
|
||||||
const baseDomain = allowedHost.slice(2); // Remove the leading "*."
|
const baseDomain = allowedHost.slice(2); // Remove the leading "*."
|
||||||
return principal.endsWith(`.${baseDomain}`);
|
return principal.endsWith(`.${baseDomain}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Exact match for non-wildcard domains
|
|
||||||
return principal === allowedHost;
|
return principal === allowedHost;
|
||||||
})
|
})
|
||||||
);
|
) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: `Principal '${principal}' is not in the list of allowed hosts or domains.`
|
||||||
|
});
|
||||||
|
}
|
||||||
});
|
});
|
||||||
|
break;
|
||||||
}
|
}
|
||||||
default:
|
default:
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
|
|||||||
Reference in New Issue
Block a user