feat: enhance AWS IAM resource support with refined validation and response structure

- Updated AWS IAM resource response schema to include distinct object structures for Postgres, MySQL, and SSH resource types.
- Improved validation for project ID to ensure it is a valid UUID.
- Adjusted console URL expiration handling to default to a calculated date if not provided.
- Modified regex for ARN role validation to accommodate additional characters.
This commit is contained in:
Victor Santos
2025-12-04 23:54:24 -03:00
parent b589ab3be4
commit aac84e3952
4 changed files with 33 additions and 7 deletions

View File

@@ -126,11 +126,37 @@ export const registerPamAccountRouter = async (server: FastifyZodProvider) => {
})
}),
response: {
200: z.union([
// Gateway-based resources (Postgres, MySQL, SSH)
200: z.discriminatedUnion("resourceType", [
// Gateway-based resources (Postgres)
z.object({
sessionId: z.string(),
resourceType: z.nativeEnum(PamResource),
resourceType: z.literal(PamResource.Postgres),
relayClientCertificate: z.string(),
relayClientPrivateKey: z.string(),
relayServerCertificateChain: z.string(),
gatewayClientCertificate: z.string(),
gatewayClientPrivateKey: z.string(),
gatewayServerCertificateChain: z.string(),
relayHost: z.string(),
metadata: z.record(z.string(), z.string().optional()).optional()
}),
// Gateway-based resources (MySQL)
z.object({
sessionId: z.string(),
resourceType: z.literal(PamResource.MySQL),
relayClientCertificate: z.string(),
relayClientPrivateKey: z.string(),
relayServerCertificateChain: z.string(),
gatewayClientCertificate: z.string(),
gatewayClientPrivateKey: z.string(),
gatewayServerCertificateChain: z.string(),
relayHost: z.string(),
metadata: z.record(z.string(), z.string().optional()).optional()
}),
// Gateway-based resources (SSH)
z.object({
sessionId: z.string(),
resourceType: z.literal(PamResource.SSH),
relayClientCertificate: z.string(),
relayClientPrivateKey: z.string(),
relayServerCertificateChain: z.string(),
@@ -145,7 +171,7 @@ export const registerPamAccountRouter = async (server: FastifyZodProvider) => {
sessionId: z.string(),
resourceType: z.literal(PamResource.AwsIam),
consoleUrl: z.string().url(),
projectId: z.string(),
projectId: z.string().uuid(),
metadata: z.record(z.string(), z.string().optional()).optional()
})
])

View File

@@ -204,6 +204,6 @@ export const generateConsoleFederationUrl = async ({
return {
consoleUrl,
expiresAt: Expiration
expiresAt: Expiration ?? new Date(Date.now() + sessionDuration * 1000)
};
};

View File

@@ -24,7 +24,7 @@ type Props = {
onSubmit: (formData: FormData) => Promise<void>;
};
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@-]+$/;
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@/-]+$/;
const AwsIamCredentialsSchema = z.object({
targetRoleArn: z

View File

@@ -21,7 +21,7 @@ type Props = {
onSubmit: (formData: FormData) => Promise<void>;
};
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@-]+$/;
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@/-]+$/;
const AwsIamConnectionDetailsSchema = z.object({
region: z.string().trim().min(1, "Region is required"),