Check url parsing error

This commit is contained in:
Fang-Pen Lin
2025-11-12 09:12:21 -08:00
parent 37fc100ff7
commit ebc041ad9d
5 changed files with 63 additions and 58 deletions
@@ -3,7 +3,6 @@ Feature: Authorization
Scenario: Get authorization Scenario: Get authorization
Given I have an ACME cert profile as "acme_profile" Given I have an ACME cert profile as "acme_profile"
When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory
# # TODO: make it I have an account already instead?
Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account
When I create certificate signing request as csr When I create certificate signing request as csr
Then I add names to certificate signing request csr Then I add names to certificate signing request csr
@@ -41,7 +41,6 @@ import {
AcmeMalformedError, AcmeMalformedError,
AcmeOrderNotReadyError, AcmeOrderNotReadyError,
AcmeServerInternalError, AcmeServerInternalError,
AcmeUnauthorizedError,
AcmeUnsupportedIdentifierError AcmeUnsupportedIdentifierError
} from "./pki-acme-errors"; } from "./pki-acme-errors";
import { buildUrl, extractAccountIdFromKid } from "./pki-acme-fns"; import { buildUrl, extractAccountIdFromKid } from "./pki-acme-fns";
@@ -171,9 +170,16 @@ export const pkiAcmeServiceFactory = ({
const { protectedHeader: rawProtectedHeader, payload: rawPayload } = result; const { protectedHeader: rawProtectedHeader, payload: rawPayload } = result;
try { try {
const protectedHeader = ProtectedHeaderSchema.parse(rawProtectedHeader); const protectedHeader = ProtectedHeaderSchema.parse(rawProtectedHeader);
const parsedUrl = (() => {
try {
return new URL(protectedHeader.url);
} catch (error) {
throw new AcmeMalformedError({ message: "Invalid URL in the protected header" });
}
})();
// Validate the URL // Validate the URL
if (new URL(protectedHeader.url).href !== url.href) { if (parsedUrl.href !== url.href) {
throw new AcmeUnauthorizedError({ message: "URL mismatch in the protected header" }); throw new AcmeMalformedError({ message: "URL mismatch in the protected header" });
} }
// Consume the nonce // Consume the nonce
if (!protectedHeader.nonce) { if (!protectedHeader.nonce) {