Skip to content

fix(amplify-category-auth): reject empty apple private key payloads - #14994

Open
mehuljariwala wants to merge 1 commit into
aws-amplify:devfrom
mehuljariwala:category-auth/13065-empty-apple-key
Open

mehuljariwala wants to merge 1 commit into
aws-amplify:devfrom
mehuljariwala:category-auth/13065-empty-apple-key

Conversation

@mehuljariwala

Copy link
Copy Markdown

Description of changes

Sign in with Apple setup currently accepts a private key containing only spaces or tabs between its PEM markers. The later extraction step removes that whitespace, leaving marker text to be submitted as the key. Require non-whitespace content between the markers at the prompt validation boundary, while preserving populated single-line keys with surrounding or embedded spaces/tabs.

The change is limited to input-shape validation. It does not attempt cryptographic validation or change key extraction, public APIs, or AWS resources. Regression tests use the actual Cognito input definition and cover empty/whitespace-only payloads and populated controls.

Issue #, if available

Fixes #13065.

Description of how you validated changes

  • yarn install --immutable completed with existing dependency/TypeScript patch warnings; lockfile unchanged.
  • yarn lerna run build --scope @aws-amplify/amplify-category-auth --include-dependencies --concurrency 2 passed for the auth package and its dependency graph.
  • From packages/amplify-category-auth, yarn test --runInBand passed: 31 suites, 139 tests, 45 snapshots. The new cases were first run against the original code, where five whitespace-only cases failed.
  • Scoped ESLint and Prettier checks passed; ESLint emits existing schema-reference warnings.
  • git diff --check passed.
  • Repository pre-commit and commit-message hooks passed, including git-secrets scanning. No hooks were bypassed.

Verified on macOS arm64 with Node 26.8.1 and repository-pinned Yarn 3.5.0. Validation used synthetic key content, never live credentials. No AWS resources were provisioned; a complete amplify add auth deployment and cloud E2E suite were not run. The existing package hint still describes the required PEM shape; no corresponding auth documentation file exists in the repository's docs/ tree.

AI assistance: OpenAI Codex assisted with source tracing, implementation, tests, and submission. No independent human review is claimed; the commit author is explicitly marked (AI) as required by AGENTS.md.

Checklist

  • PR description included
  • Auth package yarn test passes
  • Regression tests added
  • No new AWS SDK calls or CloudFormation actions
  • Maintainer review and applicable repository labels

Require non-whitespace key content between the PEM markers while
preserving spaces and tabs around populated single-line input.
Add regression tests against the actual Cognito prompt definition.

Auth package build, all package tests, formatting and scoped lint passed.
No AWS resources were provisioned.
---
Prompt: can you please open more PR's againts all differents repos and
area you should not stop

Assisted-by: OpenAI Codex
@mehuljariwala
mehuljariwala requested a review from a team as a code owner October 3, 2026 10:41
@mehuljariwala

mehuljariwala commented Oct 5, 2026 •

Copy link
Copy Markdown
Author

Update (2026-10-05): a query by the exact head commit c0c005e found three upstream GitHub Actions runs awaiting maintainer approval. The earlier branch-filtered lookup missed these runs, so the CI-status statement in the original version of this comment was incomplete.

Could a maintainer review whether these workflows can be approved to run when appropriate?

If the separate AmplifyCLI-PR-Testing CodeBuild path is also required, please advise. Local validation is recorded in the PR description; it is not being treated as upstream CI success.

AI assistance disclosure: this is an AI-assisted maintenance follow-up.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

improve validation on sign in with apple private key

1 participant