- {KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR} + {KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR}
)} > diff --git a/ui/types/formSchemas.test.ts b/ui/types/formSchemas.test.ts index 8206ed3311..c9b443a0bb 100644 --- a/ui/types/formSchemas.test.ts +++ b/ui/types/formSchemas.test.ts @@ -7,7 +7,7 @@ import { addCredentialsFormSchema, addCredentialsRoleFormSchema, addProviderFormSchema, - KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR, + KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR, roleFormSchema, samlConfigFormSchema, } from "./formSchemas"; @@ -222,7 +222,7 @@ users: expect(result.error.issues).toContainEqual( expect.objectContaining({ path: [ProviderCredentialFields.KUBECONFIG_CONTENT], - message: KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR, + message: KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR, }), ); }); @@ -249,17 +249,42 @@ users: expect(result.error.issues).toContainEqual( expect.objectContaining({ path: [ProviderCredentialFields.KUBECONFIG_CONTENT], - message: KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR, + message: KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR, }), ); }); - it("accepts kubeconfig auth-provider without cmd-path", () => { - const schema = addCredentialsFormSchema("kubernetes"); - - const result = schema.safeParse({ - ...BASE_KUBERNETES_VALUES, - [ProviderCredentialFields.KUBECONFIG_CONTENT]: `apiVersion: v1 + it.each([ + [ + "user tokenFile", + `apiVersion: v1 +kind: Config +users: + - name: test-user + user: + tokenFile: /etc/passwd`, + ], + [ + "user client-certificate", + `apiVersion: v1 +kind: Config +users: + - name: test-user + user: + client-certificate: /etc/ssl/cert.pem`, + ], + [ + "user client-key", + `apiVersion: v1 +kind: Config +users: + - name: test-user + user: + client-key: /etc/ssl/key.pem`, + ], + [ + "user auth-provider directives", + `apiVersion: v1 kind: Config users: - name: test-user @@ -268,6 +293,85 @@ users: name: oidc config: client-id: prowler`, + ], + [ + "unknown user key", + `apiVersion: v1 +kind: Config +users: + - name: test-user + user: + bogus: value`, + ], + [ + "cluster certificate-authority", + `apiVersion: v1 +kind: Config +clusters: + - name: test-cluster + cluster: + server: https://example.test + certificate-authority: /etc/ssl/ca.pem`, + ], + [ + "cluster proxy-url", + `apiVersion: v1 +kind: Config +clusters: + - name: test-cluster + cluster: + server: https://example.test + proxy-url: http://proxy.evil.test`, + ], + [ + "unknown cluster key", + `apiVersion: v1 +kind: Config +clusters: + - name: test-cluster + cluster: + server: https://example.test + bogus: /etc/ssl/ca.pem`, + ], + ])( + "rejects kubeconfig with %s on kubeconfig_content field", + (_label, kubeconfigContent) => { + const schema = addCredentialsFormSchema("kubernetes"); + + const result = schema.safeParse({ + ...BASE_KUBERNETES_VALUES, + [ProviderCredentialFields.KUBECONFIG_CONTENT]: kubeconfigContent, + }); + + expect(result.success).toBe(false); + if (result.success) return; + + expect(result.error.issues).toContainEqual( + expect.objectContaining({ + path: [ProviderCredentialFields.KUBECONFIG_CONTENT], + message: KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR, + }), + ); + }, + ); + + it("accepts kubeconfig with only inline credentials", () => { + const schema = addCredentialsFormSchema("kubernetes"); + + const result = schema.safeParse({ + ...BASE_KUBERNETES_VALUES, + [ProviderCredentialFields.KUBECONFIG_CONTENT]: `apiVersion: v1 +kind: Config +clusters: + - name: test-cluster + cluster: + server: https://example.test + certificate-authority-data: Zm9v +users: + - name: test-user + user: + client-certificate-data: Zm9v + client-key-data: YmFy`, }); expect(result.success).toBe(true); diff --git a/ui/types/formSchemas.ts b/ui/types/formSchemas.ts index 11c8bef03e..93101f074c 100644 --- a/ui/types/formSchemas.ts +++ b/ui/types/formSchemas.ts @@ -8,42 +8,75 @@ import { MAX_SAML_ADDITIONAL_EMAIL_DOMAINS } from "@/types/saml"; import { isKnownProviderType, PROVIDER_TYPES, ProviderType } from "./providers"; -export const KUBECONFIG_UNSUPPORTED_COMMAND_AUTHENTICATION_ERROR = - "Kubernetes kubeconfig command-based authentication is not supported in Prowler Cloud for security reasons."; +export const KUBECONFIG_NON_INLINE_CREDENTIALS_ERROR = + "Only inline Kubernetes credentials are supported. For user authentication use token, username/password, or client-certificate-data with client-key-data; clusters may use certificate-authority-data. File-path fields (tokenFile, client-certificate, client-key, certificate-authority), command-based authentication (exec, cmd-path), auth-provider directives, and proxy URLs are not supported."; const isRecord = (value: unknown): value is Record