diff --git a/backend/src/ee/services/pam-account/pam-account-service.ts b/backend/src/ee/services/pam-account/pam-account-service.ts index ceced9ca2..302fd006f 100644 --- a/backend/src/ee/services/pam-account/pam-account-service.ts +++ b/backend/src/ee/services/pam-account/pam-account-service.ts @@ -290,7 +290,8 @@ export const pamAccountServiceFactory = ({ return decryptAccount(account, account.projectId, kmsService); } - const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc); + try { + const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc); return { ...(await decryptAccount(updatedAccount, account.projectId, kmsService)), @@ -301,6 +302,15 @@ export const pamAccountServiceFactory = ({ rotationCredentialsConfigured: !!resource.encryptedRotationAccountCredentials } }; + } catch (err) { + if (err instanceof DatabaseError && (err.error as { code: string })?.code === DatabaseErrorCode.UniqueViolation) { + throw new BadRequestError({ + message: `Account with name '${name}' already exists for this path` + }); + } + + throw err; + } }; const deleteById = async (id: string, actor: OrgServiceActor) => { diff --git a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts index 9167b4e5d..1a72ac2e7 100644 --- a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts +++ b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts @@ -67,7 +67,9 @@ export const AwsIamAccountSchema = BasePamAccountSchema.extend({ }); export const CreateAwsIamAccountSchema = BaseCreatePamAccountSchema.extend({ - credentials: AwsIamAccountCredentialsSchema + credentials: AwsIamAccountCredentialsSchema, + // AWS IAM accounts don't support credential rotation - they use role assumption + rotationEnabled: z.boolean().default(false) }); export const UpdateAwsIamAccountSchema = BaseUpdatePamAccountSchema.extend({ diff --git a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts index 4e288df4e..732355371 100644 --- a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts +++ b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts @@ -13,4 +13,4 @@ export type TAwsIamResourceConnectionDetails = z.infer; -export type TAwsIamAccountCredentials = z.infer; \ No newline at end of file +export type TAwsIamAccountCredentials = z.infer;