fix(auth): make diagnostics bounded and portable
This commit is contained in:
@@ -0,0 +1,19 @@
|
||||
export const AUTHENTICATION_SECRET_LIMITS = Object.freeze({
|
||||
THT_OIDC_CLIENT_SECRET: 4096,
|
||||
THT_AUTHENTIK_API_TOKEN: 16 * 1024,
|
||||
} as const);
|
||||
|
||||
export type AuthenticationSecretReference = keyof typeof AUTHENTICATION_SECRET_LIMITS;
|
||||
|
||||
export function isAuthenticationSecretReference(value: string): value is AuthenticationSecretReference {
|
||||
return Object.prototype.hasOwnProperty.call(AUTHENTICATION_SECRET_LIMITS, value);
|
||||
}
|
||||
|
||||
/** One policy shared by bundle loading, runtime adapters, and static diagnostics. */
|
||||
export function isUsableAuthenticationSecret(
|
||||
name: AuthenticationSecretReference,
|
||||
value: unknown,
|
||||
): value is string {
|
||||
return typeof value === "string" && value.length > 0
|
||||
&& value.length <= AUTHENTICATION_SECRET_LIMITS[name] && !/\p{Cc}/u.test(value);
|
||||
}
|
||||
Reference in New Issue
Block a user