mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-07 11:27:32 +00:00
pam: allow account credentials to be fetched more than once
This commit is contained in:
@@ -668,11 +668,6 @@ export const pamAccountServiceFactory = ({
|
|||||||
throw new BadRequestError({ message: "Session has ended or expired" });
|
throw new BadRequestError({ message: "Session has ended or expired" });
|
||||||
}
|
}
|
||||||
|
|
||||||
// Verify that the session has not already had credentials fetched
|
|
||||||
if (session.status !== PamSessionStatus.Starting) {
|
|
||||||
throw new BadRequestError({ message: "Session has already been started" });
|
|
||||||
}
|
|
||||||
|
|
||||||
const account = await pamAccountDAL.findById(session.accountId);
|
const account = await pamAccountDAL.findById(session.accountId);
|
||||||
if (!account) throw new NotFoundError({ message: `Account with ID '${session.accountId}' not found` });
|
if (!account) throw new NotFoundError({ message: `Account with ID '${session.accountId}' not found` });
|
||||||
|
|
||||||
@@ -690,10 +685,12 @@ export const pamAccountServiceFactory = ({
|
|||||||
const decryptedResource = await decryptResource(resource, session.projectId, kmsService);
|
const decryptedResource = await decryptResource(resource, session.projectId, kmsService);
|
||||||
|
|
||||||
// Mark session as started
|
// Mark session as started
|
||||||
await pamSessionDAL.updateById(sessionId, {
|
if (session.status === PamSessionStatus.Starting) {
|
||||||
status: PamSessionStatus.Active,
|
await pamSessionDAL.updateById(sessionId, {
|
||||||
startedAt: new Date()
|
status: PamSessionStatus.Active,
|
||||||
});
|
startedAt: new Date()
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
credentials: {
|
credentials: {
|
||||||
|
|||||||
Reference in New Issue
Block a user