Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 22 additions & 0 deletions server/service/certificate_templates_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -165,6 +165,15 @@ func TestCreateCertificateTemplate(t *testing.T) {
})
}
})

t.Run("Empty or whitespace-only subject name", func(t *testing.T) {
whitespaceSubjectNames := []string{"", " ", " \t\n "}
for _, subjectName := range whitespaceSubjectNames {
_, err := svc.CreateCertificateTemplate(ctx, "my template", TeamID, uint(ValidCATypeID), subjectName)
require.Error(t, err)
require.Contains(t, err.Error(), "Certificate template subject name is required")
}
})
}

func TestApplyCertificateTemplateSpecs(t *testing.T) {
Expand Down Expand Up @@ -365,4 +374,17 @@ func TestApplyCertificateTemplateSpecs(t *testing.T) {
require.Error(t, err)
require.Contains(t, err.Error(), "Certificate template name is too long")
})

t.Run("Whitespace-only subject name", func(t *testing.T) {
err := svc.ApplyCertificateTemplateSpecs(ctx, []*fleet.CertificateRequestSpec{
{
Name: "Template 2",
CertificateAuthorityId: 1,
SubjectName: " ",
},
})
require.Error(t, err)
require.Contains(t, err.Error(), "Certificate template subject name is required")
require.Contains(t, err.Error(), "Template 2")
})
}
15 changes: 15 additions & 0 deletions server/service/certificates.go
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,13 @@ const (
// certificateTemplateNameRegex allows only letters, numbers, spaces, dashes, and underscores
var certificateTemplateNameRegex = regexp.MustCompile(`^[a-zA-Z0-9 \-_]+$`)

func validateCertificateTemplateSubjectName(subjectName string) error {
if strings.TrimSpace(subjectName) == "" {
return &fleet.BadRequestError{Message: "Certificate template subject name is required."}
}
return nil
}

// validateCertificateTemplateName validates the certificate template name.
// Returns a BadRequestError if validation fails.
func validateCertificateTemplateName(name string) error {
Expand Down Expand Up @@ -80,6 +87,10 @@ func (svc *Service) CreateCertificateTemplate(ctx context.Context, name string,
return nil, err
}

if err := validateCertificateTemplateSubjectName(subjectName); err != nil {
return nil, err
}

if err := validateCertificateTemplateFleetVariables(subjectName); err != nil {
return nil, &fleet.BadRequestError{Message: err.Error()}
}
Expand Down Expand Up @@ -425,6 +436,10 @@ func (svc *Service) ApplyCertificateTemplateSpecs(ctx context.Context, specs []*
return err
}

if err := validateCertificateTemplateSubjectName(spec.SubjectName); err != nil {
return &fleet.BadRequestError{Message: fmt.Sprintf("%s (certificate %s)", err.Error(), spec.Name)}
}

// Get the CA to validate its existence and type.
ca, ok := casByID[spec.CertificateAuthorityId]
if !ok {
Expand Down
Loading