mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-08 01:27:31 +00:00
fix: improve error handling in AWS IAM role assumption methods
- Added try-catch blocks to handle errors during role assumption in both assumePamRole and assumeTargetRole functions. - Enhanced error messages to include specific details about the failure, improving debugging and user feedback. - Updated console URL generation to directly use the SigninToken from the token response, ensuring correct URL formation.
This commit is contained in:
@@ -63,25 +63,34 @@ const assumePamRole = async ({
|
|||||||
}): Promise<Credentials | null> => {
|
}): Promise<Credentials | null> => {
|
||||||
const stsClient = createStsClient();
|
const stsClient = createStsClient();
|
||||||
|
|
||||||
const result = await stsClient.send(
|
try {
|
||||||
new AssumeRoleCommand({
|
const result = await stsClient.send(
|
||||||
RoleArn: connectionDetails.roleArn,
|
new AssumeRoleCommand({
|
||||||
RoleSessionName: `infisical-pam-${sessionNameSuffix}-${Date.now()}`,
|
RoleArn: connectionDetails.roleArn,
|
||||||
DurationSeconds: sessionDuration,
|
RoleSessionName: `infisical-pam-${sessionNameSuffix}-${Date.now()}`,
|
||||||
ExternalId: projectId
|
DurationSeconds: sessionDuration,
|
||||||
})
|
ExternalId: projectId
|
||||||
);
|
})
|
||||||
|
);
|
||||||
|
|
||||||
if (!result.Credentials) {
|
if (!result.Credentials) {
|
||||||
|
if (throwOnError) {
|
||||||
|
throw new InternalServerError({
|
||||||
|
message: "Failed to assume PAM role - AWS STS did not return credentials"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return result.Credentials;
|
||||||
|
} catch (error) {
|
||||||
if (throwOnError) {
|
if (throwOnError) {
|
||||||
throw new InternalServerError({
|
throw new InternalServerError({
|
||||||
message: "Failed to assume PAM role - AWS STS did not return credentials"
|
message: `Failed to assume PAM role - AWS STS did not return credentials: ${error instanceof Error ? error.message : "Unknown error"}`
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
return result.Credentials;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -105,25 +114,34 @@ const assumeTargetRole = async ({
|
|||||||
}): Promise<Credentials | null> => {
|
}): Promise<Credentials | null> => {
|
||||||
const chainedStsClient = createStsClient(pamCredentials);
|
const chainedStsClient = createStsClient(pamCredentials);
|
||||||
|
|
||||||
const result = await chainedStsClient.send(
|
try {
|
||||||
new AssumeRoleCommand({
|
const result = await chainedStsClient.send(
|
||||||
RoleArn: targetRoleArn,
|
new AssumeRoleCommand({
|
||||||
RoleSessionName: roleSessionName,
|
RoleArn: targetRoleArn,
|
||||||
DurationSeconds: sessionDuration,
|
RoleSessionName: roleSessionName,
|
||||||
ExternalId: projectId
|
DurationSeconds: sessionDuration,
|
||||||
})
|
ExternalId: projectId
|
||||||
);
|
})
|
||||||
|
);
|
||||||
|
|
||||||
if (!result.Credentials) {
|
if (!result.Credentials) {
|
||||||
|
if (throwOnError) {
|
||||||
|
throw new BadRequestError({
|
||||||
|
message: "Failed to assume target role - verify the target role trust policy allows the PAM role to assume it"
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
|
||||||
|
return result.Credentials;
|
||||||
|
} catch (error) {
|
||||||
if (throwOnError) {
|
if (throwOnError) {
|
||||||
throw new BadRequestError({
|
throw new InternalServerError({
|
||||||
message: "Failed to assume target role - verify the target role trust policy allows the PAM role to assume it"
|
message: `Failed to assume target role - AWS STS did not return credentials: ${error instanceof Error ? error.message : "Unknown error"}`
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
return null;
|
return null;
|
||||||
}
|
}
|
||||||
|
|
||||||
return result.Credentials;
|
|
||||||
};
|
};
|
||||||
|
|
||||||
export const validatePamRoleConnection = async (
|
export const validatePamRoleConnection = async (
|
||||||
@@ -217,16 +235,8 @@ export const generateConsoleFederationUrl = async ({
|
|||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
const tokenData = tokenResponse.data;
|
|
||||||
|
|
||||||
if (!tokenData.SigninToken) {
|
|
||||||
throw new InternalServerError({
|
|
||||||
message: `AWS federation endpoint did not return a SigninToken: ${JSON.stringify(tokenResponse.data).substring(0, 200)}`
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
const consoleDestination = `https://console.aws.amazon.com/`;
|
const consoleDestination = `https://console.aws.amazon.com/`;
|
||||||
const consoleUrl = `${federationEndpoint}?Action=login&SigninToken=${encodeURIComponent(tokenData.SigninToken)}&Destination=${encodeURIComponent(consoleDestination)}`;
|
const consoleUrl = `${federationEndpoint}?Action=login&SigninToken=${encodeURIComponent(tokenResponse.data.SigninToken)}&Destination=${encodeURIComponent(consoleDestination)}`;
|
||||||
|
|
||||||
return {
|
return {
|
||||||
consoleUrl,
|
consoleUrl,
|
||||||
|
|||||||
Reference in New Issue
Block a user