mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 19:28:09 +00:00
98 lines
3.2 KiB
TypeScript
98 lines
3.2 KiB
TypeScript
import { z } from "zod";
|
|
|
|
import { PkiSync } from "@app/hooks/api/pkiSyncs";
|
|
|
|
import { BasePkiSyncSchema } from "./base-pki-sync-schema";
|
|
|
|
const AwsSecretsManagerFieldMappingsSchema = z.object({
|
|
certificate: z.string().min(1, "Certificate field name is required").default("certificate"),
|
|
privateKey: z.string().min(1, "Private key field name is required").default("private_key"),
|
|
certificateChain: z
|
|
.string()
|
|
.min(1, "Certificate chain field name is required")
|
|
.default("certificate_chain"),
|
|
caCertificate: z
|
|
.string()
|
|
.min(1, "CA certificate field name is required")
|
|
.default("ca_certificate")
|
|
});
|
|
|
|
const AwsSecretsManagerSyncOptionsSchema = z.object({
|
|
canImportCertificates: z.boolean().default(false),
|
|
canRemoveCertificates: z.boolean().default(true),
|
|
preserveSecretOnRenewal: z.boolean().default(true),
|
|
updateExistingCertificates: z.boolean().default(true),
|
|
certificateNameSchema: z
|
|
.string()
|
|
.optional()
|
|
.refine(
|
|
(val) => {
|
|
if (!val) return true;
|
|
|
|
const allowedOptionalPlaceholders = [
|
|
"{{environment}}",
|
|
"{{profileId}}",
|
|
"{{commonName}}",
|
|
"{{friendlyName}}"
|
|
];
|
|
|
|
const allowedPlaceholdersRegexPart = ["{{certificateId}}", ...allowedOptionalPlaceholders]
|
|
.map((p) => p.replace(/[-/\\^$*+?.()|[\]{}]/g, "\\$&"))
|
|
.join("|");
|
|
|
|
const allowedContentRegex = new RegExp(
|
|
`^([a-zA-Z0-9_\\-]|${allowedPlaceholdersRegexPart})*$`
|
|
);
|
|
const contentIsValid = allowedContentRegex.test(val);
|
|
|
|
if (val.trim()) {
|
|
const certificateIdRegex = /\{\{certificateId\}\}/;
|
|
const certificateIdIsPresent = certificateIdRegex.test(val);
|
|
return contentIsValid && certificateIdIsPresent;
|
|
}
|
|
|
|
return contentIsValid;
|
|
},
|
|
{
|
|
message:
|
|
"Certificate name schema must include exactly one {{certificateId}} placeholder. It can also include {{environment}}, {{profileId}}, {{commonName}}, or {{friendlyName}} placeholders. Only alphanumeric characters (a-z, A-Z, 0-9), hyphens (-), and underscores (_) are allowed besides the placeholders."
|
|
}
|
|
),
|
|
fieldMappings: AwsSecretsManagerFieldMappingsSchema.optional().default({
|
|
certificate: "certificate",
|
|
privateKey: "private_key",
|
|
certificateChain: "certificate_chain",
|
|
caCertificate: "ca_certificate"
|
|
})
|
|
});
|
|
|
|
export const AwsSecretsManagerPkiSyncDestinationSchema = BasePkiSyncSchema(
|
|
AwsSecretsManagerSyncOptionsSchema
|
|
).merge(
|
|
z.object({
|
|
destination: z.literal(PkiSync.AwsSecretsManager),
|
|
destinationConfig: z.object({
|
|
region: z.string().min(1, "AWS region is required")
|
|
})
|
|
})
|
|
);
|
|
|
|
export const UpdateAwsSecretsManagerPkiSyncDestinationSchema =
|
|
AwsSecretsManagerPkiSyncDestinationSchema.partial().merge(
|
|
z.object({
|
|
name: z
|
|
.string()
|
|
.trim()
|
|
.min(1, "Name is required")
|
|
.max(255, "Name must be less than 255 characters"),
|
|
destination: z.literal(PkiSync.AwsSecretsManager),
|
|
connection: z.object({
|
|
id: z.string().uuid("Invalid connection ID format"),
|
|
name: z
|
|
.string()
|
|
.min(1, "Connection name is required")
|
|
.max(255, "Connection name must be less than 255 characters")
|
|
})
|
|
})
|
|
);
|