mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-04 23:26:20 +00:00
Merge pull request #2972 from Infisical/misc/suppot-array-value-for-oidc-aud-field
misc: add support for array values in OIDC aud field
This commit is contained in:
@@ -2,3 +2,11 @@ import picomatch from "picomatch";
|
|||||||
|
|
||||||
export const doesFieldValueMatchOidcPolicy = (fieldValue: string, policyValue: string) =>
|
export const doesFieldValueMatchOidcPolicy = (fieldValue: string, policyValue: string) =>
|
||||||
policyValue === fieldValue || picomatch.isMatch(fieldValue, policyValue);
|
policyValue === fieldValue || picomatch.isMatch(fieldValue, policyValue);
|
||||||
|
|
||||||
|
export const doesAudValueMatchOidcPolicy = (fieldValue: string | string[], policyValue: string) => {
|
||||||
|
if (Array.isArray(fieldValue)) {
|
||||||
|
return fieldValue.some((entry) => entry === policyValue || picomatch.isMatch(entry, policyValue));
|
||||||
|
}
|
||||||
|
|
||||||
|
return policyValue === fieldValue || picomatch.isMatch(fieldValue, policyValue);
|
||||||
|
};
|
||||||
|
|||||||
@@ -27,7 +27,7 @@ import { TIdentityAccessTokenDALFactory } from "../identity-access-token/identit
|
|||||||
import { TIdentityAccessTokenJwtPayload } from "../identity-access-token/identity-access-token-types";
|
import { TIdentityAccessTokenJwtPayload } from "../identity-access-token/identity-access-token-types";
|
||||||
import { TOrgBotDALFactory } from "../org/org-bot-dal";
|
import { TOrgBotDALFactory } from "../org/org-bot-dal";
|
||||||
import { TIdentityOidcAuthDALFactory } from "./identity-oidc-auth-dal";
|
import { TIdentityOidcAuthDALFactory } from "./identity-oidc-auth-dal";
|
||||||
import { doesFieldValueMatchOidcPolicy } from "./identity-oidc-auth-fns";
|
import { doesAudValueMatchOidcPolicy, doesFieldValueMatchOidcPolicy } from "./identity-oidc-auth-fns";
|
||||||
import {
|
import {
|
||||||
TAttachOidcAuthDTO,
|
TAttachOidcAuthDTO,
|
||||||
TGetOidcAuthDTO,
|
TGetOidcAuthDTO,
|
||||||
@@ -148,7 +148,7 @@ export const identityOidcAuthServiceFactory = ({
|
|||||||
if (
|
if (
|
||||||
!identityOidcAuth.boundAudiences
|
!identityOidcAuth.boundAudiences
|
||||||
.split(", ")
|
.split(", ")
|
||||||
.some((policyValue) => doesFieldValueMatchOidcPolicy(tokenData.aud, policyValue))
|
.some((policyValue) => doesAudValueMatchOidcPolicy(tokenData.aud, policyValue))
|
||||||
) {
|
) {
|
||||||
throw new UnauthorizedError({
|
throw new UnauthorizedError({
|
||||||
message: "Access denied: OIDC audience not allowed."
|
message: "Access denied: OIDC audience not allowed."
|
||||||
|
|||||||
Reference in New Issue
Block a user