AWS managedservices: Fix SAML claim rule regex to match 12-digit account ID
Summary
Corrected the ADFS claim rule regex from [^d]{12} to [\d]{12} in the condition and RegExReplace role ARN mapping for console federation.
Security assessment
Same SAML federation role-mapping regex fix; ensures the account ID is correctly parsed as 12 digits for IAM role ARN issuance. Authorization-relevant configuration correction, not a specific vulnerability.
Evidence
+ c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]
Diff
diff --git a/managedservices/latest/onboardingguide/fed-with-console.md b/managedservices/latest/onboardingguide/fed-with-console.md index 7e0295f61..8e642e853 100644 --- a//managedservices/latest/onboardingguide/fed-with-console.md +++ b//managedservices/latest/onboardingguide/fed-with-console.md @@ -42,2 +42,2 @@ After creating the relying party trust as per the blog post, configure the claim - c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([^d]{12})-"] - => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([^d]{12})-", + c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"] + => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([\d]{12})-",