feat: improve PAM account update handling with enhanced error management

- Added try-catch block to handle potential database errors during account updates.
- Implemented specific error handling for unique constraint violations, providing clearer feedback for duplicate account names.
- Updated AWS IAM account schema to indicate that credential rotation is not supported, defaulting to false.
This commit is contained in:
Victor Santos
2025-12-05 01:14:28 -03:00
parent ac5c185f76
commit a755b5bfa0
3 changed files with 15 additions and 3 deletions
@@ -290,7 +290,8 @@ export const pamAccountServiceFactory = ({
return decryptAccount(account, account.projectId, kmsService); return decryptAccount(account, account.projectId, kmsService);
} }
const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc); try {
const updatedAccount = await pamAccountDAL.updateById(accountId, updateDoc);
return { return {
...(await decryptAccount(updatedAccount, account.projectId, kmsService)), ...(await decryptAccount(updatedAccount, account.projectId, kmsService)),
@@ -301,6 +302,15 @@ export const pamAccountServiceFactory = ({
rotationCredentialsConfigured: !!resource.encryptedRotationAccountCredentials rotationCredentialsConfigured: !!resource.encryptedRotationAccountCredentials
} }
}; };
} catch (err) {
if (err instanceof DatabaseError && (err.error as { code: string })?.code === DatabaseErrorCode.UniqueViolation) {
throw new BadRequestError({
message: `Account with name '${name}' already exists for this path`
});
}
throw err;
}
}; };
const deleteById = async (id: string, actor: OrgServiceActor) => { const deleteById = async (id: string, actor: OrgServiceActor) => {
@@ -67,7 +67,9 @@ export const AwsIamAccountSchema = BasePamAccountSchema.extend({
}); });
export const CreateAwsIamAccountSchema = BaseCreatePamAccountSchema.extend({ export const CreateAwsIamAccountSchema = BaseCreatePamAccountSchema.extend({
credentials: AwsIamAccountCredentialsSchema credentials: AwsIamAccountCredentialsSchema,
// AWS IAM accounts don't support credential rotation - they use role assumption
rotationEnabled: z.boolean().default(false)
}); });
export const UpdateAwsIamAccountSchema = BaseUpdatePamAccountSchema.extend({ export const UpdateAwsIamAccountSchema = BaseUpdatePamAccountSchema.extend({
@@ -13,4 +13,4 @@ export type TAwsIamResourceConnectionDetails = z.infer<typeof AwsIamResourceConn
// Accounts // Accounts
export type TAwsIamAccount = z.infer<typeof AwsIamAccountSchema>; export type TAwsIamAccount = z.infer<typeof AwsIamAccountSchema>;
export type TAwsIamAccountCredentials = z.infer<typeof AwsIamAccountCredentialsSchema>; export type TAwsIamAccountCredentials = z.infer<typeof AwsIamAccountCredentialsSchema>;