Browse Source

Updated validation for akeyless to catch invalid URLs and emtpy accessID name and keys

Signed-off-by: Idowu Emehinola <hydeenoble39@gmail.com>
Idowu Emehinola 4 years ago
parent
commit
3e3120669d
2 changed files with 12 additions and 9 deletions
  1. 11 8
      pkg/provider/akeyless/akeyless.go
  2. 1 1
      pkg/provider/akeyless/akeyless_test.go

+ 11 - 8
pkg/provider/akeyless/akeyless.go

@@ -82,19 +82,22 @@ func (p *Provider) ValidateStore(store esv1beta1.GenericStore) error {
 	storeSpec := store.GetSpec()
 	akeylessSpec := storeSpec.Provider.Akeyless
 
-	akeylessGWApiURL := akeylessSpec.AkeylessGWApiURL
+	akeylessGWApiURL := *akeylessSpec.AkeylessGWApiURL
 
-	url, err := url.Parse(*akeylessGWApiURL)
-	if err != nil {
-		return fmt.Errorf(errInvalidAkeylessURL)
-	}
+	if akeylessGWApiURL != "" {
 
-	if url.Host == "" {
-		return fmt.Errorf(errInvalidAkeylessURL)
+		url, err := url.Parse(akeylessGWApiURL)
+		if err != nil {
+			return fmt.Errorf(errInvalidAkeylessURL)
+		}
+
+		if url.Host == "" {
+			return fmt.Errorf(errInvalidAkeylessURL)
+		}
 	}
 
 	accessID := akeylessSpec.Auth.SecretRef.AccessID
-	err = utils.ValidateSecretSelector(store, accessID)
+	err := utils.ValidateSecretSelector(store, accessID)
 	if err != nil {
 		return err
 	}

+ 1 - 1
pkg/provider/akeyless/akeyless_test.go

@@ -128,7 +128,7 @@ func TestAkeylessGetSecret(t *testing.T) {
 func TestValidateStore(t *testing.T) {
 	provider := Provider{}
 
-	akeylessGWApiURL := "http://gwapi.akeyless"
+	akeylessGWApiURL := ""
 
 	store := &esv1beta1.SecretStore{
 		Spec: esv1beta1.SecretStoreSpec{