diff --git a/apps/api/src/cert-manager/cert-manager.service.ts b/apps/api/src/cert-manager/cert-manager.service.ts index 0b033c4..ab65b4b 100644 --- a/apps/api/src/cert-manager/cert-manager.service.ts +++ b/apps/api/src/cert-manager/cert-manager.service.ts @@ -481,13 +481,17 @@ export class CertManagerService { // certBag decoder). No entry may be silently dropped (D-04) — check // every bag and reject the whole file, naming it, before returning. const bagCerts = bags.map((bag) => bag.cert); - const missingCertIndex = bagCerts.findIndex((c) => c === null); + // @types/node-forge declares Bag.cert as `Certificate | undefined`, + // but node-forge's own runtime sets it to `null` for an unreadable + // bag (lib/pkcs12.js certBag decoder) — check both, not just `=== + // undefined`, so the guard actually catches what the library does. + const missingCertIndex = bagCerts.findIndex((c) => c === undefined || c === null); if (missingCertIndex !== -1) { throw new BadRequestException( `Certificate bag in "${file.originalname as string}" does not contain a readable X.509 certificate`, ); } - return bagCerts.filter((c): c is forge.pki.Certificate => c !== null); + return bagCerts.filter((c): c is forge.pki.Certificate => c !== undefined && c !== null); } else { // P7B/PKCS7 — PEM-wrapped or binary DER (Pitfall 4) const isPemP7b = (file.buffer as Buffer)