From a755b5bfa08b12bb987e6fb2954d134771c3b42d Mon Sep 17 00:00:00 2001 From: Victor Santos Date: Fri, 5 Dec 2025 01:14:28 -0300 Subject: [PATCH] feat: improve PAM account update handling with enhanced error management - Added try-catch block to handle potential database errors during account updates. - Implemented specific error handling for unique constraint violations, providing clearer feedback for duplicate account names. - Updated AWS IAM account schema to indicate that credential rotation is not supported, defaulting to false. --- .../ee/services/pam-account/pam-account-service.ts | 12 +++++++++++- .../pam-resource/aws-iam/aws-iam-resource-schemas.ts | 4 +++- .../pam-resource/aws-iam/aws-iam-resource-types.ts | 2 +- 3 files changed, 15 insertions(+), 3 deletions(-) diff --git a/backend/src/ee/services/pam-account/pam-account-service.ts b/backend/src/ee/services/pam-account/pam-account-service.ts index ceced9ca2..302fd006f 100644 --- a/backend/src/ee/services/pam-account/pam-account-service.ts +++ b/backend/src/ee/services/pam-account/pam-account-service.ts @@ -290,7 +290,8 @@ export const pamAccountServiceFactory = ({ return decryptAccount(account, account.projectId, kmsService); } - const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc); + try { + const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc); return { ...(await decryptAccount(updatedAccount, account.projectId, kmsService)), @@ -301,6 +302,15 @@ export const pamAccountServiceFactory = ({ rotationCredentialsConfigured: !!resource.encryptedRotationAccountCredentials } }; + } catch (err) { + if (err instanceof DatabaseError && (err.error as { code: string })?.code === DatabaseErrorCode.UniqueViolation) { + throw new BadRequestError({ + message: `Account with name '${name}' already exists for this path` + }); + } + + throw err; + } }; const deleteById = async (id: string, actor: OrgServiceActor) => { diff --git a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts index 9167b4e5d..1a72ac2e7 100644 --- a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts +++ b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-schemas.ts @@ -67,7 +67,9 @@ export const AwsIamAccountSchema = BasePamAccountSchema.extend({ }); export const CreateAwsIamAccountSchema = BaseCreatePamAccountSchema.extend({ - credentials: AwsIamAccountCredentialsSchema + credentials: AwsIamAccountCredentialsSchema, + // AWS IAM accounts don't support credential rotation - they use role assumption + rotationEnabled: z.boolean().default(false) }); export const UpdateAwsIamAccountSchema = BaseUpdatePamAccountSchema.extend({ diff --git a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts index 4e288df4e..732355371 100644 --- a/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts +++ b/backend/src/ee/services/pam-resource/aws-iam/aws-iam-resource-types.ts @@ -13,4 +13,4 @@ export type TAwsIamResourceConnectionDetails = z.infer; -export type TAwsIamAccountCredentials = z.infer; \ No newline at end of file +export type TAwsIamAccountCredentials = z.infer;