mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-11 04:29:10 +00:00
Check url parsing error
This commit is contained in:
@@ -3,7 +3,6 @@ Feature: Authorization
|
||||
Scenario: Get authorization
|
||||
Given I have an ACME cert profile as "acme_profile"
|
||||
When I have an ACME client connecting to {BASE_URL}/api/v1/pki/acme/profiles/{acme_profile.id}/directory
|
||||
# # TODO: make it I have an account already instead?
|
||||
Then I register a new ACME account with email fangpen@infisical.com and EAB key id "{acme_profile.eab_kid}" with secret "{acme_profile.eab_secret}" as acme_account
|
||||
When I create certificate signing request as csr
|
||||
Then I add names to certificate signing request csr
|
||||
|
||||
@@ -41,7 +41,6 @@ import {
|
||||
AcmeMalformedError,
|
||||
AcmeOrderNotReadyError,
|
||||
AcmeServerInternalError,
|
||||
AcmeUnauthorizedError,
|
||||
AcmeUnsupportedIdentifierError
|
||||
} from "./pki-acme-errors";
|
||||
import { buildUrl, extractAccountIdFromKid } from "./pki-acme-fns";
|
||||
@@ -171,9 +170,16 @@ export const pkiAcmeServiceFactory = ({
|
||||
const { protectedHeader: rawProtectedHeader, payload: rawPayload } = result;
|
||||
try {
|
||||
const protectedHeader = ProtectedHeaderSchema.parse(rawProtectedHeader);
|
||||
const parsedUrl = (() => {
|
||||
try {
|
||||
return new URL(protectedHeader.url);
|
||||
} catch (error) {
|
||||
throw new AcmeMalformedError({ message: "Invalid URL in the protected header" });
|
||||
}
|
||||
})();
|
||||
// Validate the URL
|
||||
if (new URL(protectedHeader.url).href !== url.href) {
|
||||
throw new AcmeUnauthorizedError({ message: "URL mismatch in the protected header" });
|
||||
if (parsedUrl.href !== url.href) {
|
||||
throw new AcmeMalformedError({ message: "URL mismatch in the protected header" });
|
||||
}
|
||||
// Consume the nonce
|
||||
if (!protectedHeader.nonce) {
|
||||
|
||||
Reference in New Issue
Block a user