fix: enforce allowed-account-ids when the list contains empty entries

An empty first element previously short-circuited the allowed account
check. Empty entries are now filtered out and validation applies
whenever any non-empty entry exists.
This commit is contained in:
Tom Keller
2026-08-31 11:57:50 -07:00
parent 7fdbbb8968
commit ed5da29eb9
2 changed files with 20 additions and 3 deletions
+4 -3
View File
@@ -167,14 +167,15 @@ export function exportAccountId(identity: { Account: string; Arn: string }, mask
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
// `allowed-account-ids` input.
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
if (!expectedAccountIds || expectedAccountIds.length === 0 || expectedAccountIds[0] === '') {
const allowedAccountIds = expectedAccountIds?.filter((id) => id !== '') ?? [];
if (allowedAccountIds.length === 0) {
return;
}
if (!account || !expectedAccountIds.includes(account)) {
if (!account || !allowedAccountIds.includes(account)) {
throw new Error(
`The account ID of the provided credentials (${
account ?? 'unknown'
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
}) does not match any of the expected account IDs: ${allowedAccountIds.join(', ')}`,
);
}
}
+16
View File
@@ -126,6 +126,22 @@ describe('Configure AWS Credentials helpers', {}, () => {
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
});
describe('validateAccountId', {}, () => {
it('enforces the allow-list even when the first element is empty', {}, () => {
expect(() => helpers.validateAccountId(['', '999999999999'], '111111111111')).toThrow(/does not match/);
});
it('passes an allowed account despite empty entries in the list', {}, () => {
expect(() => helpers.validateAccountId(['', '111111111111'], '111111111111')).not.toThrow();
});
it('skips validation only when no non-empty entries exist', {}, () => {
expect(() => helpers.validateAccountId(undefined, '111111111111')).not.toThrow();
expect(() => helpers.validateAccountId([], '111111111111')).not.toThrow();
expect(() => helpers.validateAccountId([''], '111111111111')).not.toThrow();
});
});
describe('filesystem helpers', {}, () => {
describe('isSymlink', {}, () => {
it('returns true for a symlink', {}, () => {