diff --git a/backend/src/ee/services/pki-acme/pki-acme-schemas.ts b/backend/src/ee/services/pki-acme/pki-acme-schemas.ts index 1d2f95fdf..4c7d6c3c1 100644 --- a/backend/src/ee/services/pki-acme/pki-acme-schemas.ts +++ b/backend/src/ee/services/pki-acme/pki-acme-schemas.ts @@ -1,3 +1,4 @@ +import RE2 from "re2"; import { z } from "zod"; export enum AcmeIdentifierType { @@ -88,9 +89,12 @@ export const CreateAcmeOrderBodySchema = z.object({ identifiers: z.array( z.object({ type: z.enum(Object.values(AcmeIdentifierType) as [string, ...string[]]), - value: z - .string() - .regex(/^(?!-)[A-Za-z0-9-]{1,63}(? { + // DNS label pattern: 1-63 chars, alphanumeric or hyphen, but not starting or ending with hyphen + const labelPattern = new RE2(/^[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?$/); + const labels = val.split("."); + return labels.every((label) => label.length >= 1 && label.length <= 63 && labelPattern.test(label)); + }, "Invalid DNS identifier") }) ), notBefore: z.string().optional(),