fix: enforce allowed-account-ids when the list contains empty entries

An empty first element previously short-circuited the allowed account
check. Empty entries are now filtered out and validation applies
whenever any non-empty entry exists.
This commit is contained in:
Tom Keller
2026-08-31 11:57:50 -07:00
parent 7fdbbb8968
commit ed5da29eb9
2 changed files with 20 additions and 3 deletions
+4 -3
View File
@@ -167,14 +167,15 @@ export function exportAccountId(identity: { Account: string; Arn: string }, mask
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
// `allowed-account-ids` input.
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
if (!expectedAccountIds || expectedAccountIds.length === 0 || expectedAccountIds[0] === '') {
const allowedAccountIds = expectedAccountIds?.filter((id) => id !== '') ?? [];
if (allowedAccountIds.length === 0) {
return;
}
if (!account || !expectedAccountIds.includes(account)) {
if (!account || !allowedAccountIds.includes(account)) {
throw new Error(
`The account ID of the provided credentials (${
account ?? 'unknown'
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
}) does not match any of the expected account IDs: ${allowedAccountIds.join(', ')}`,
);
}
}