mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-05 00:26:24 +00:00
fix: enhance error messaging and improve resource selection in PAM components
- Updated error message in AWS IAM resource factory to include the PAM role ARN for better debugging. - Added functionality to clear the search input when a value is selected in the ResourceSelect component, improving user experience. - Refactored AwsIamAccountForm to fetch PAM resource details based on account or provided resourceId and resourceType, ensuring accurate role ARN usage in trust policy.
This commit is contained in:
@@ -62,8 +62,7 @@ export const awsIamResourceFactory: TPamResourceFactory<TAwsIamResourceConnectio
|
|||||||
|
|
||||||
if (!isValid) {
|
if (!isValid) {
|
||||||
throw new BadRequestError({
|
throw new BadRequestError({
|
||||||
message:
|
message: `Unable to assume the target role. Verify the target role ARN and ensure the PAM role (ARN: ${connectionDetails.roleArn}) has permission to assume it.`
|
||||||
"Unable to assume the target role. Verify the target role ARN and ensure the PAM role has permission to assume it."
|
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
+24
-12
@@ -16,7 +16,12 @@ import {
|
|||||||
} from "@app/components/v2";
|
} from "@app/components/v2";
|
||||||
import { CopyButton } from "@app/components/v2/CopyButton";
|
import { CopyButton } from "@app/components/v2/CopyButton";
|
||||||
import { useProject } from "@app/context";
|
import { useProject } from "@app/context";
|
||||||
import { PamResourceType, TAwsIamAccount } from "@app/hooks/api/pam";
|
import {
|
||||||
|
PamResourceType,
|
||||||
|
TAwsIamAccount,
|
||||||
|
TAwsIamResource,
|
||||||
|
useGetPamResourceById
|
||||||
|
} from "@app/hooks/api/pam";
|
||||||
|
|
||||||
import { GenericAccountFields, genericAccountFieldsSchema } from "./GenericAccountFields";
|
import { GenericAccountFields, genericAccountFieldsSchema } from "./GenericAccountFields";
|
||||||
|
|
||||||
@@ -51,16 +56,27 @@ const formSchema = genericAccountFieldsSchema.extend({
|
|||||||
|
|
||||||
type FormData = z.infer<typeof formSchema>;
|
type FormData = z.infer<typeof formSchema>;
|
||||||
|
|
||||||
export const AwsIamAccountForm = ({ account, onSubmit }: Props) => {
|
export const AwsIamAccountForm = ({ account, resourceId, resourceType, onSubmit }: Props) => {
|
||||||
const isUpdate = Boolean(account);
|
const isUpdate = Boolean(account);
|
||||||
const { projectId } = useProject();
|
const { projectId } = useProject();
|
||||||
|
|
||||||
|
const resourceIdToFetch = account?.resourceId || resourceId;
|
||||||
|
const resourceTypeToFetch = account?.resource?.resourceType || resourceType;
|
||||||
|
const { data: resource } = useGetPamResourceById(resourceTypeToFetch, resourceIdToFetch, {
|
||||||
|
enabled: !!resourceIdToFetch && !!resourceTypeToFetch
|
||||||
|
});
|
||||||
|
|
||||||
|
const pamRoleArn =
|
||||||
|
(resource?.resourceType === PamResourceType.AwsIam &&
|
||||||
|
(resource as TAwsIamResource).connectionDetails?.roleArn) ||
|
||||||
|
"arn:aws:iam::<YOUR_ACCOUNT_ID>:role/<YOUR_PAM_ROLE_NAME>";
|
||||||
|
|
||||||
const targetRoleTrustPolicy = `{
|
const targetRoleTrustPolicy = `{
|
||||||
"Version": "2012-10-17",
|
"Version": "2012-10-17",
|
||||||
"Statement": [{
|
"Statement": [{
|
||||||
"Effect": "Allow",
|
"Effect": "Allow",
|
||||||
"Principal": {
|
"Principal": {
|
||||||
"AWS": "arn:aws:iam::<YOUR_ACCOUNT_ID>:role/<YOUR_PAM_ROLE_NAME>"
|
"AWS": "${pamRoleArn}"
|
||||||
},
|
},
|
||||||
"Action": "sts:AssumeRole",
|
"Action": "sts:AssumeRole",
|
||||||
"Condition": {
|
"Condition": {
|
||||||
@@ -166,16 +182,12 @@ export const AwsIamAccountForm = ({ account, onSubmit }: Props) => {
|
|||||||
</pre>
|
</pre>
|
||||||
</div>
|
</div>
|
||||||
<p className="text-xs text-mineshaft-400">
|
<p className="text-xs text-mineshaft-400">
|
||||||
<strong>Note:</strong> Replace{" "}
|
<strong>Note:</strong> The Principal role ARN shown above is from the PAM Resource
|
||||||
<code className="rounded bg-mineshaft-700 px-1"><YOUR_ACCOUNT_ID></code> with
|
selected for this account. The External ID{" "}
|
||||||
your AWS account ID and{" "}
|
|
||||||
<code className="rounded bg-mineshaft-700 px-1"><YOUR_PAM_ROLE_NAME></code>{" "}
|
|
||||||
with the name of the PAM role you created in the "Resources" tab. The
|
|
||||||
External ID{" "}
|
|
||||||
<code className="rounded bg-mineshaft-700 px-1 font-bold">{projectId}</code> is your
|
<code className="rounded bg-mineshaft-700 px-1 font-bold">{projectId}</code> is your
|
||||||
current project ID. If this target role name doesn't match the wildcard pattern
|
current project ID. If your target role name doesn't match the wildcard pattern
|
||||||
in your PAM role's permissions policy, you'll need to update that policy
|
in your PAM Resource's role's permissions policy, you'll need to
|
||||||
to include this role's ARN.
|
update that policy to include this role's ARN.
|
||||||
</p>
|
</p>
|
||||||
</AccordionContent>
|
</AccordionContent>
|
||||||
</AccordionItem>
|
</AccordionItem>
|
||||||
|
|||||||
@@ -80,6 +80,8 @@ export const ResourceSelect = ({ onSubmit, projectId }: Props) => {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Clear search when a value is selected so the selected label is shown
|
||||||
|
setSearch("");
|
||||||
onChange(newValue);
|
onChange(newValue);
|
||||||
}}
|
}}
|
||||||
isLoading={isPending}
|
isLoading={isPending}
|
||||||
|
|||||||
Reference in New Issue
Block a user