Repository navigation
fix(amplify-category-auth): reject empty apple private key payloads - #14994
Open
mehuljariwala wants to merge 1 commit into
Open
mehuljariwala wants to merge 1 commit into
mehuljariwala wants to merge 1 commit into
Conversation
Require non-whitespace key content between the PEM markers while preserving spaces and tabs around populated single-line input. Add regression tests against the actual Cognito prompt definition. Auth package build, all package tests, formatting and scoped lint passed. No AWS resources were provisioned. --- Prompt: can you please open more PR's againts all differents repos and area you should not stop Assisted-by: OpenAI Codex
Author
|
Update (2026-10-05): a query by the exact head commit c0c005e found three upstream GitHub Actions runs awaiting maintainer approval. The earlier branch-filtered lookup missed these runs, so the CI-status statement in the original version of this comment was incomplete. Could a maintainer review whether these workflows can be approved to run when appropriate?
If the separate AmplifyCLI-PR-Testing CodeBuild path is also required, please advise. Local validation is recorded in the PR description; it is not being treated as upstream CI success. AI assistance disclosure: this is an AI-assisted maintenance follow-up. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of changes
Sign in with Apple setup currently accepts a private key containing only spaces or tabs between its PEM markers. The later extraction step removes that whitespace, leaving marker text to be submitted as the key. Require non-whitespace content between the markers at the prompt validation boundary, while preserving populated single-line keys with surrounding or embedded spaces/tabs.
The change is limited to input-shape validation. It does not attempt cryptographic validation or change key extraction, public APIs, or AWS resources. Regression tests use the actual Cognito input definition and cover empty/whitespace-only payloads and populated controls.
Issue #, if available
Fixes #13065.
Description of how you validated changes
yarn install --immutablecompleted with existing dependency/TypeScript patch warnings; lockfile unchanged.yarn lerna run build --scope @aws-amplify/amplify-category-auth --include-dependencies --concurrency 2passed for the auth package and its dependency graph.packages/amplify-category-auth,yarn test --runInBandpassed: 31 suites, 139 tests, 45 snapshots. The new cases were first run against the original code, where five whitespace-only cases failed.git diff --checkpassed.Verified on macOS arm64 with Node 26.8.1 and repository-pinned Yarn 3.5.0. Validation used synthetic key content, never live credentials. No AWS resources were provisioned; a complete
amplify add authdeployment and cloud E2E suite were not run. The existing package hint still describes the required PEM shape; no corresponding auth documentation file exists in the repository'sdocs/tree.AI assistance: OpenAI Codex assisted with source tracing, implementation, tests, and submission. No independent human review is claimed; the commit author is explicitly marked
(AI)as required by AGENTS.md.Checklist
yarn testpasses