Fix DNS validation. Using re2 instead

This commit is contained in:
Fang-Pen Lin
2025-11-07 09:30:52 -08:00
parent d2c8904e8f
commit b0bdc01b1e

View File

@@ -1,3 +1,4 @@
import RE2 from "re2";
import { z } from "zod";
export enum AcmeIdentifierType {
@@ -88,9 +89,12 @@ export const CreateAcmeOrderBodySchema = z.object({
identifiers: z.array(
z.object({
type: z.enum(Object.values(AcmeIdentifierType) as [string, ...string[]]),
value: z
.string()
.regex(/^(?!-)[A-Za-z0-9-]{1,63}(?<!-)(\.(?!-)[A-Za-z0-9-]{1,63}(?<!-))*$/, "Invalid DNS identifier")
value: z.string().refine((val) => {
// DNS label pattern: 1-63 chars, alphanumeric or hyphen, but not starting or ending with hyphen
const labelPattern = new RE2(/^[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?$/);
const labels = val.split(".");
return labels.every((label) => label.length >= 1 && label.length <= 63 && labelPattern.test(label));
}, "Invalid DNS identifier")
})
),
notBefore: z.string().optional(),