mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-09-22 13:39:35 +00:00
feat: improve PAM account update handling with enhanced error management
- Added try-catch block to handle potential database errors during account updates. - Implemented specific error handling for unique constraint violations, providing clearer feedback for duplicate account names. - Updated AWS IAM account schema to indicate that credential rotation is not supported, defaulting to false.
This commit is contained in:
@@ -290,7 +290,8 @@ export const pamAccountServiceFactory = ({
|
||||
return decryptAccount(account, account.projectId, kmsService);
|
||||
}
|
||||
|
||||
const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc);
|
||||
try {
|
||||
const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc);
|
||||
|
||||
return {
|
||||
...(await decryptAccount(updatedAccount, account.projectId, kmsService)),
|
||||
@@ -301,6 +302,15 @@ export const pamAccountServiceFactory = ({
|
||||
rotationCredentialsConfigured: !!resource.encryptedRotationAccountCredentials
|
||||
}
|
||||
};
|
||||
} catch (err) {
|
||||
if (err instanceof DatabaseError && (err.error as { code: string })?.code === DatabaseErrorCode.UniqueViolation) {
|
||||
throw new BadRequestError({
|
||||
message: `Account with name '${name}' already exists for this path`
|
||||
});
|
||||
}
|
||||
|
||||
throw err;
|
||||
}
|
||||
};
|
||||
|
||||
const deleteById = async (id: string, actor: OrgServiceActor) => {
|
||||
|
||||
@@ -67,7 +67,9 @@ export const AwsIamAccountSchema = BasePamAccountSchema.extend({
|
||||
});
|
||||
|
||||
export const CreateAwsIamAccountSchema = BaseCreatePamAccountSchema.extend({
|
||||
credentials: AwsIamAccountCredentialsSchema
|
||||
credentials: AwsIamAccountCredentialsSchema,
|
||||
// AWS IAM accounts don't support credential rotation - they use role assumption
|
||||
rotationEnabled: z.boolean().default(false)
|
||||
});
|
||||
|
||||
export const UpdateAwsIamAccountSchema = BaseUpdatePamAccountSchema.extend({
|
||||
|
||||
@@ -13,4 +13,4 @@ export type TAwsIamResourceConnectionDetails = z.infer<typeof AwsIamResourceConn
|
||||
|
||||
// Accounts
|
||||
export type TAwsIamAccount = z.infer<typeof AwsIamAccountSchema>;
|
||||
export type TAwsIamAccountCredentials = z.infer<typeof AwsIamAccountCredentialsSchema>;
|
||||
export type TAwsIamAccountCredentials = z.infer<typeof AwsIamAccountCredentialsSchema>;
|
||||
|
||||
Reference in New Issue
Block a user