mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 02:27:39 +00:00
added more validation to region
This commit is contained in:
@@ -68,6 +68,18 @@ const awsRegionFromHeader = (authorizationHeader: string): string | null => {
|
|||||||
return null;
|
return null;
|
||||||
};
|
};
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
function isValidAwsRegion(region: (string | null)): boolean {
|
||||||
|
const validRegionPattern = new RE2('^[a-z0-9-]+$');
|
||||||
|
if (typeof region !== 'string' || region.length === 0 || region.length > 20) {
|
||||||
|
return false;
|
||||||
|
}
|
||||||
|
|
||||||
|
return validRegionPattern.test(region);
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
export const identityAwsAuthServiceFactory = ({
|
export const identityAwsAuthServiceFactory = ({
|
||||||
identityAccessTokenDAL,
|
identityAccessTokenDAL,
|
||||||
identityAwsAuthDAL,
|
identityAwsAuthDAL,
|
||||||
@@ -85,8 +97,12 @@ export const identityAwsAuthServiceFactory = ({
|
|||||||
|
|
||||||
const headers: TAwsGetCallerIdentityHeaders = JSON.parse(Buffer.from(iamRequestHeaders, "base64").toString());
|
const headers: TAwsGetCallerIdentityHeaders = JSON.parse(Buffer.from(iamRequestHeaders, "base64").toString());
|
||||||
const body: string = Buffer.from(iamRequestBody, "base64").toString();
|
const body: string = Buffer.from(iamRequestBody, "base64").toString();
|
||||||
|
|
||||||
const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null;
|
const region = headers.Authorization ? awsRegionFromHeader(headers.Authorization) : null;
|
||||||
|
|
||||||
|
if (!isValidAwsRegion(region)) {
|
||||||
|
throw new BadRequestError({message: "Invalid AWS region"});
|
||||||
|
}
|
||||||
|
|
||||||
const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint;
|
const url = region ? `https://sts.${region}.amazonaws.com` : identityAwsAuth.stsEndpoint;
|
||||||
|
|
||||||
const {
|
const {
|
||||||
|
|||||||
Reference in New Issue
Block a user