Fix match logic

This commit is contained in:
Fang-Pen Lin
2025-11-13 09:21:37 -08:00
parent 204bf59b22
commit d70fa8f406
@@ -680,15 +680,16 @@ export const pkiAcmeServiceFactory = ({
tx tx
))!; ))!;
const csrIdentifierValues = new Set( const csrIdentifierValues = new Set(
orderWithAuthorizations.authorizations (certificateRequest.subjectAlternativeNames ?? [])
.map((auth) => auth.identifierValue.toLowerCase()) .map((san) => san.value.toLowerCase())
.concat([certificateRequest.commonName!.toLowerCase()]) .concat([certificateRequest.commonName!.toLowerCase()])
); );
const expectedIdentifierValues = new Set(
orderWithAuthorizations.authorizations.map((auth) => auth.identifierValue.toLowerCase())
);
if ( if (
csrIdentifierValues.size !== orderWithAuthorizations.authorizations.length || csrIdentifierValues.size != expectedIdentifierValues.size ||
!orderWithAuthorizations.authorizations.every((auth) => !csrIdentifierValues.isSubsetOf(expectedIdentifierValues)
csrIdentifierValues.has(auth.identifierValue.toLowerCase())
)
) { ) {
throw new AcmeBadCSRError({ detail: "Invalid CSR: Common name + SANs mismatch with order identifiers" }); throw new AcmeBadCSRError({ detail: "Invalid CSR: Common name + SANs mismatch with order identifiers" });
} }