mirror of
https://github.com/aws-actions/configure-aws-credentials.git
synced 2026-09-05 06:25:08 +09:00
fix: enforce allowed-account-ids when the list contains empty entries
An empty first element previously short-circuited the allowed account check. Empty entries are now filtered out and validation applies whenever any non-empty entry exists.
This commit is contained in:
+4
-3
@@ -167,14 +167,15 @@ export function exportAccountId(identity: { Account: string; Arn: string }, mask
|
|||||||
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
|
// Validates that the account of the already-resolved caller identity is in the allow-list provided via the
|
||||||
// `allowed-account-ids` input.
|
// `allowed-account-ids` input.
|
||||||
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
|
export function validateAccountId(expectedAccountIds: string[] | undefined, account: string | undefined): void {
|
||||||
if (!expectedAccountIds || expectedAccountIds.length === 0 || expectedAccountIds[0] === '') {
|
const allowedAccountIds = expectedAccountIds?.filter((id) => id !== '') ?? [];
|
||||||
|
if (allowedAccountIds.length === 0) {
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
if (!account || !expectedAccountIds.includes(account)) {
|
if (!account || !allowedAccountIds.includes(account)) {
|
||||||
throw new Error(
|
throw new Error(
|
||||||
`The account ID of the provided credentials (${
|
`The account ID of the provided credentials (${
|
||||||
account ?? 'unknown'
|
account ?? 'unknown'
|
||||||
}) does not match any of the expected account IDs: ${expectedAccountIds.join(', ')}`,
|
}) does not match any of the expected account IDs: ${allowedAccountIds.join(', ')}`,
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -126,6 +126,22 @@ describe('Configure AWS Credentials helpers', {}, () => {
|
|||||||
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
|
expect(core.exportVariable).toHaveBeenCalledWith('AWS_SESSION_TOKEN', '');
|
||||||
});
|
});
|
||||||
|
|
||||||
|
describe('validateAccountId', {}, () => {
|
||||||
|
it('enforces the allow-list even when the first element is empty', {}, () => {
|
||||||
|
expect(() => helpers.validateAccountId(['', '999999999999'], '111111111111')).toThrow(/does not match/);
|
||||||
|
});
|
||||||
|
|
||||||
|
it('passes an allowed account despite empty entries in the list', {}, () => {
|
||||||
|
expect(() => helpers.validateAccountId(['', '111111111111'], '111111111111')).not.toThrow();
|
||||||
|
});
|
||||||
|
|
||||||
|
it('skips validation only when no non-empty entries exist', {}, () => {
|
||||||
|
expect(() => helpers.validateAccountId(undefined, '111111111111')).not.toThrow();
|
||||||
|
expect(() => helpers.validateAccountId([], '111111111111')).not.toThrow();
|
||||||
|
expect(() => helpers.validateAccountId([''], '111111111111')).not.toThrow();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
describe('filesystem helpers', {}, () => {
|
describe('filesystem helpers', {}, () => {
|
||||||
describe('isSymlink', {}, () => {
|
describe('isSymlink', {}, () => {
|
||||||
it('returns true for a symlink', {}, () => {
|
it('returns true for a symlink', {}, () => {
|
||||||
|
|||||||
Reference in New Issue
Block a user