AWS managedservices: Fix SAML claim rule regex to match 12-digit account ID
Summary
Corrected the ADFS claim rule regular expression from [^d]{12} (any non-'d' char) to [\d]{12} (exactly 12 digits) in both the condition and the RegExReplace role ARN mapping.
Security assessment
The regex drives SAML federation role mapping to IAM role ARNs. The prior [^d]{12} pattern incorrectly matched any 12 non-'d' characters, which could mis-map or fail to map the account ID to the correct role; the fix ensures only valid 12-digit account IDs are matched. This is an authentication/authorization configuration correction, though not tied to a specific CVE.
Evidence
+ c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]
Diff
diff --git a/managedservices/latest/onboardingguide/apx-adfs-claim-rule-saml.md b/managedservices/latest/onboardingguide/apx-adfs-claim-rule-saml.md index de59e8514..5f42aadd6 100644 --- a//managedservices/latest/onboardingguide/apx-adfs-claim-rule-saml.md +++ b//managedservices/latest/onboardingguide/apx-adfs-claim-rule-saml.md @@ -46 +46 @@ The relying party trust and claims rules steps are taken from [ Enabling Federat - c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([^d]{12})-"] + c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"] @@ -49 +49 @@ The relying party trust and claims rules steps are taken from [ Enabling Federat - => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([^d]{12})-", "arn:aws:iam::$1:saml-provider/customer-readonly-saml,arn:aws:iam::$1:role/")); + => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([\d]{12})-", "arn:aws:iam::$1:saml-provider/customer-readonly-saml,arn:aws:iam::$1:role/"));