mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 00:27:30 +00:00
feat: enhance AWS IAM resource support with refined validation and response structure
- Updated AWS IAM resource response schema to include distinct object structures for Postgres, MySQL, and SSH resource types. - Improved validation for project ID to ensure it is a valid UUID. - Adjusted console URL expiration handling to default to a calculated date if not provided. - Modified regex for ARN role validation to accommodate additional characters.
This commit is contained in:
@@ -126,11 +126,37 @@ export const registerPamAccountRouter = async (server: FastifyZodProvider) => {
|
|||||||
})
|
})
|
||||||
}),
|
}),
|
||||||
response: {
|
response: {
|
||||||
200: z.union([
|
200: z.discriminatedUnion("resourceType", [
|
||||||
// Gateway-based resources (Postgres, MySQL, SSH)
|
// Gateway-based resources (Postgres)
|
||||||
z.object({
|
z.object({
|
||||||
sessionId: z.string(),
|
sessionId: z.string(),
|
||||||
resourceType: z.nativeEnum(PamResource),
|
resourceType: z.literal(PamResource.Postgres),
|
||||||
|
relayClientCertificate: z.string(),
|
||||||
|
relayClientPrivateKey: z.string(),
|
||||||
|
relayServerCertificateChain: z.string(),
|
||||||
|
gatewayClientCertificate: z.string(),
|
||||||
|
gatewayClientPrivateKey: z.string(),
|
||||||
|
gatewayServerCertificateChain: z.string(),
|
||||||
|
relayHost: z.string(),
|
||||||
|
metadata: z.record(z.string(), z.string().optional()).optional()
|
||||||
|
}),
|
||||||
|
// Gateway-based resources (MySQL)
|
||||||
|
z.object({
|
||||||
|
sessionId: z.string(),
|
||||||
|
resourceType: z.literal(PamResource.MySQL),
|
||||||
|
relayClientCertificate: z.string(),
|
||||||
|
relayClientPrivateKey: z.string(),
|
||||||
|
relayServerCertificateChain: z.string(),
|
||||||
|
gatewayClientCertificate: z.string(),
|
||||||
|
gatewayClientPrivateKey: z.string(),
|
||||||
|
gatewayServerCertificateChain: z.string(),
|
||||||
|
relayHost: z.string(),
|
||||||
|
metadata: z.record(z.string(), z.string().optional()).optional()
|
||||||
|
}),
|
||||||
|
// Gateway-based resources (SSH)
|
||||||
|
z.object({
|
||||||
|
sessionId: z.string(),
|
||||||
|
resourceType: z.literal(PamResource.SSH),
|
||||||
relayClientCertificate: z.string(),
|
relayClientCertificate: z.string(),
|
||||||
relayClientPrivateKey: z.string(),
|
relayClientPrivateKey: z.string(),
|
||||||
relayServerCertificateChain: z.string(),
|
relayServerCertificateChain: z.string(),
|
||||||
@@ -145,7 +171,7 @@ export const registerPamAccountRouter = async (server: FastifyZodProvider) => {
|
|||||||
sessionId: z.string(),
|
sessionId: z.string(),
|
||||||
resourceType: z.literal(PamResource.AwsIam),
|
resourceType: z.literal(PamResource.AwsIam),
|
||||||
consoleUrl: z.string().url(),
|
consoleUrl: z.string().url(),
|
||||||
projectId: z.string(),
|
projectId: z.string().uuid(),
|
||||||
metadata: z.record(z.string(), z.string().optional()).optional()
|
metadata: z.record(z.string(), z.string().optional()).optional()
|
||||||
})
|
})
|
||||||
])
|
])
|
||||||
|
|||||||
@@ -204,6 +204,6 @@ export const generateConsoleFederationUrl = async ({
|
|||||||
|
|
||||||
return {
|
return {
|
||||||
consoleUrl,
|
consoleUrl,
|
||||||
expiresAt: Expiration
|
expiresAt: Expiration ?? new Date(Date.now() + sessionDuration * 1000)
|
||||||
};
|
};
|
||||||
};
|
};
|
||||||
|
|||||||
+1
-1
@@ -24,7 +24,7 @@ type Props = {
|
|||||||
onSubmit: (formData: FormData) => Promise<void>;
|
onSubmit: (formData: FormData) => Promise<void>;
|
||||||
};
|
};
|
||||||
|
|
||||||
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@-]+$/;
|
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@/-]+$/;
|
||||||
|
|
||||||
const AwsIamCredentialsSchema = z.object({
|
const AwsIamCredentialsSchema = z.object({
|
||||||
targetRoleArn: z
|
targetRoleArn: z
|
||||||
|
|||||||
+1
-1
@@ -21,7 +21,7 @@ type Props = {
|
|||||||
onSubmit: (formData: FormData) => Promise<void>;
|
onSubmit: (formData: FormData) => Promise<void>;
|
||||||
};
|
};
|
||||||
|
|
||||||
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@-]+$/;
|
const arnRoleRegex = /^arn:aws:iam::\d{12}:role\/[\w+=,.@/-]+$/;
|
||||||
|
|
||||||
const AwsIamConnectionDetailsSchema = z.object({
|
const AwsIamConnectionDetailsSchema = z.object({
|
||||||
region: z.string().trim().min(1, "Region is required"),
|
region: z.string().trim().min(1, "Region is required"),
|
||||||
|
|||||||
Reference in New Issue
Block a user