fix: improve error handling in AWS IAM role assumption methods

- Added try-catch blocks to handle errors during role assumption in both assumePamRole and assumeTargetRole functions.
- Enhanced error messages to include specific details about the failure, improving debugging and user feedback.
- Updated console URL generation to directly use the SigninToken from the token response, ensuring correct URL formation.
This commit is contained in:
Victor Santos
2025-12-07 20:48:15 -03:00
parent 3e77c33532
commit a0718321e7
@@ -63,25 +63,34 @@ const assumePamRole = async ({
}): Promise<Credentials | null> => { }): Promise<Credentials | null> => {
const stsClient = createStsClient(); const stsClient = createStsClient();
const result = await stsClient.send( try {
new AssumeRoleCommand({ const result = await stsClient.send(
RoleArn: connectionDetails.roleArn, new AssumeRoleCommand({
RoleSessionName: `infisical-pam-${sessionNameSuffix}-${Date.now()}`, RoleArn: connectionDetails.roleArn,
DurationSeconds: sessionDuration, RoleSessionName: `infisical-pam-${sessionNameSuffix}-${Date.now()}`,
ExternalId: projectId DurationSeconds: sessionDuration,
}) ExternalId: projectId
); })
);
if (!result.Credentials) { if (!result.Credentials) {
if (throwOnError) {
throw new InternalServerError({
message: "Failed to assume PAM role - AWS STS did not return credentials"
});
}
return null;
}
return result.Credentials;
} catch (error) {
if (throwOnError) { if (throwOnError) {
throw new InternalServerError({ throw new InternalServerError({
message: "Failed to assume PAM role - AWS STS did not return credentials" message: `Failed to assume PAM role - AWS STS did not return credentials: ${error instanceof Error ? error.message : "Unknown error"}`
}); });
} }
return null; return null;
} }
return result.Credentials;
}; };
/** /**
@@ -105,25 +114,34 @@ const assumeTargetRole = async ({
}): Promise<Credentials | null> => { }): Promise<Credentials | null> => {
const chainedStsClient = createStsClient(pamCredentials); const chainedStsClient = createStsClient(pamCredentials);
const result = await chainedStsClient.send( try {
new AssumeRoleCommand({ const result = await chainedStsClient.send(
RoleArn: targetRoleArn, new AssumeRoleCommand({
RoleSessionName: roleSessionName, RoleArn: targetRoleArn,
DurationSeconds: sessionDuration, RoleSessionName: roleSessionName,
ExternalId: projectId DurationSeconds: sessionDuration,
}) ExternalId: projectId
); })
);
if (!result.Credentials) { if (!result.Credentials) {
if (throwOnError) {
throw new BadRequestError({
message: "Failed to assume target role - verify the target role trust policy allows the PAM role to assume it"
});
}
return null;
}
return result.Credentials;
} catch (error) {
if (throwOnError) { if (throwOnError) {
throw new BadRequestError({ throw new InternalServerError({
message: "Failed to assume target role - verify the target role trust policy allows the PAM role to assume it" message: `Failed to assume target role - AWS STS did not return credentials: ${error instanceof Error ? error.message : "Unknown error"}`
}); });
} }
return null; return null;
} }
return result.Credentials;
}; };
export const validatePamRoleConnection = async ( export const validatePamRoleConnection = async (
@@ -217,16 +235,8 @@ export const generateConsoleFederationUrl = async ({
}); });
} }
const tokenData = tokenResponse.data;
if (!tokenData.SigninToken) {
throw new InternalServerError({
message: `AWS federation endpoint did not return a SigninToken: ${JSON.stringify(tokenResponse.data).substring(0, 200)}`
});
}
const consoleDestination = `https://console.aws.amazon.com/`; const consoleDestination = `https://console.aws.amazon.com/`;
const consoleUrl = `${federationEndpoint}?Action=login&SigninToken=${encodeURIComponent(tokenData.SigninToken)}&Destination=${encodeURIComponent(consoleDestination)}`; const consoleUrl = `${federationEndpoint}?Action=login&SigninToken=${encodeURIComponent(tokenResponse.data.SigninToken)}&Destination=${encodeURIComponent(consoleDestination)}`;
return { return {
consoleUrl, consoleUrl,