mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 14:27:30 +00:00
Fix DNS validation. Using re2 instead
This commit is contained in:
@@ -1,3 +1,4 @@
|
|||||||
|
import RE2 from "re2";
|
||||||
import { z } from "zod";
|
import { z } from "zod";
|
||||||
|
|
||||||
export enum AcmeIdentifierType {
|
export enum AcmeIdentifierType {
|
||||||
@@ -88,9 +89,12 @@ export const CreateAcmeOrderBodySchema = z.object({
|
|||||||
identifiers: z.array(
|
identifiers: z.array(
|
||||||
z.object({
|
z.object({
|
||||||
type: z.enum(Object.values(AcmeIdentifierType) as [string, ...string[]]),
|
type: z.enum(Object.values(AcmeIdentifierType) as [string, ...string[]]),
|
||||||
value: z
|
value: z.string().refine((val) => {
|
||||||
.string()
|
// DNS label pattern: 1-63 chars, alphanumeric or hyphen, but not starting or ending with hyphen
|
||||||
.regex(/^(?!-)[A-Za-z0-9-]{1,63}(?<!-)(\.(?!-)[A-Za-z0-9-]{1,63}(?<!-))*$/, "Invalid DNS identifier")
|
const labelPattern = new RE2(/^[A-Za-z0-9](?:[A-Za-z0-9-]{0,61}[A-Za-z0-9])?$/);
|
||||||
|
const labels = val.split(".");
|
||||||
|
return labels.every((label) => label.length >= 1 && label.length <= 63 && labelPattern.test(label));
|
||||||
|
}, "Invalid DNS identifier")
|
||||||
})
|
})
|
||||||
),
|
),
|
||||||
notBefore: z.string().optional(),
|
notBefore: z.string().optional(),
|
||||||
|
|||||||
Reference in New Issue
Block a user