Skip to content

Turn IAM off for imports with an invalid region or service type - #2390

Open
kmcginnes wants to merge 5 commits into
mainfrom
safer-connection-import-and-types
Open

kmcginnes wants to merge 5 commits into
mainfrom
safer-connection-import-and-types

Conversation

@kmcginnes

@kmcginnes kmcginnes commented Oct 8, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Importing a connection file with an unrecognized serviceType (or a non-string awsRegion) quietly dropped the value but left IAM on, so requests were then signed for the neptune-db default, a service the file never named. This PR also tightens a few connection types along the way.

 parseConnectionFile(file)
   connection
-    awsRegion:   string, .catch(undefined)
-    serviceType: enum,   .catch(undefined)
+    awsRegion:   unknown
+    serviceType: unknown
+    .transform(disableIamForInvalidSigningTarget)
+      parse awsRegion and serviceType, drop an invalid value
+      if either was dropped and IAM was on
+        awsAuthEnabled = false
+        logger.warn(...)
  • The import still succeeds. A missing field stays missing, and valid values are unchanged.
  • mapToConnection returns SavedConnection & { connection: ConnectionConfig }, so the as SavedConnection cast is gone. fetchDefaultConnection now declares Promise<SavedConnection[]> as its return type.
  • queryEngineSelector only falls back to "gremlin" when there is no active connection, because normalizeConnection already guarantees a query engine.

Evidence

Before: a file with awsAuthEnabled: true and serviceType: "not-a-real-service-type" imported with IAM still on and no serviceType.
After: new tests in parseConnectionFile.test.ts:

invalid serviceType, IAM on  -> serviceType dropped, awsAuthEnabled false, one warning
invalid awsRegion,   IAM on  -> awsRegion dropped,   awsAuthEnabled false, one warning
invalid serviceType, IAM off -> serviceType dropped, no warning
valid or absent values       -> IAM stays on, no warning

The same cases run against the legacy url shapes older builds wrote (url only, and url + graphDbUrl, both with proxyConnection: true), and url and proxyConnection survive.

New golden imports in connectionFileGoldenFiles.test.ts pin connection files with IAM fields as shipped builds wrote them:

  • connection-file-v1.5-iam-without-service-type.json: written before serviceType existed. IAM stays on, because an absent field is not an invalid one.
  • connection-file-v3.2.2-iam-proxy.json: a v3.2.2 proxy connection with IAM. Everything is kept.
  • connection-file-v3.2.2-proxy-iam-off.json: v3.2.2 form defaults (awsRegion: "", serviceType: "neptune-db", IAM off). An empty region is not treated as invalid.

Verified live: imported connection files through the UI in Safari, then checked the stored connection in IndexedDB. A bad service type or a numeric region imported with IAM off and logged the warning. Valid and missing values imported unchanged, and a file with no endpoint still showed the "Invalid File" toast.

Merge Danger

Door: two-way

Impact: narrow

Only imports whose awsRegion or serviceType fails validation change, and those now come in with IAM off. Files that Graph Explorer exported always contain valid values, the existing golden-file and backward-compatibility tests pass unchanged, and new golden files pin the IAM shapes v1.5 and v3.2.2 wrote.

Related

@kmcginnes
kmcginnes force-pushed the safer-connection-import-and-types branch from 7c7c0c6 to 76dccbe Compare October 9, 2026 17:40

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant