mirror of
https://github.com/awatertrevi/infisical.git
synced 2026-10-09 08:28:22 +00:00
move catch outside of the TX
This commit is contained in:
@@ -578,10 +578,10 @@ export const pamAccountServiceFactory = ({
|
|||||||
for (let i = 0; i < accounts.length; i += ROTATION_CONCURRENCY_LIMIT) {
|
for (let i = 0; i < accounts.length; i += ROTATION_CONCURRENCY_LIMIT) {
|
||||||
const batch = accounts.slice(i, i + ROTATION_CONCURRENCY_LIMIT);
|
const batch = accounts.slice(i, i + ROTATION_CONCURRENCY_LIMIT);
|
||||||
|
|
||||||
const rotationPromises = batch.map(async (account) =>
|
const rotationPromises = batch.map(async (account) => {
|
||||||
pamAccountDAL.transaction(async (tx) => {
|
let logResourceType = "unknown";
|
||||||
let logResourceType = "unknown";
|
try {
|
||||||
try {
|
await pamAccountDAL.transaction(async (tx) => {
|
||||||
const resource = await pamResourceDAL.findById(account.resourceId, tx);
|
const resource = await pamResourceDAL.findById(account.resourceId, tx);
|
||||||
if (!resource || !resource.encryptedRotationAccountCredentials) return;
|
if (!resource || !resource.encryptedRotationAccountCredentials) return;
|
||||||
logResourceType = resource.resourceType;
|
logResourceType = resource.resourceType;
|
||||||
@@ -645,51 +645,45 @@ export const pamAccountServiceFactory = ({
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
} catch (error) {
|
});
|
||||||
logger.error(error, `Failed to rotate credentials for account [accountId=${account.id}]`);
|
} catch (error) {
|
||||||
|
logger.error(error, `Failed to rotate credentials for account [accountId=${account.id}]`);
|
||||||
|
|
||||||
const errorMessage = error instanceof Error ? error.message : "An unknown error occurred";
|
const errorMessage = error instanceof Error ? error.message : "An unknown error occurred";
|
||||||
|
|
||||||
const { encryptor } = await kmsService.createCipherPairWithDataKey({
|
const { encryptor } = await kmsService.createCipherPairWithDataKey({
|
||||||
type: KmsDataKey.SecretManager,
|
type: KmsDataKey.SecretManager,
|
||||||
projectId: account.projectId
|
projectId: account.projectId
|
||||||
});
|
});
|
||||||
|
|
||||||
const { cipherTextBlob: encryptedMessage } = encryptor({
|
const { cipherTextBlob: encryptedMessage } = encryptor({
|
||||||
plainText: Buffer.from(errorMessage)
|
plainText: Buffer.from(errorMessage)
|
||||||
});
|
});
|
||||||
|
|
||||||
await pamAccountDAL.updateById(
|
await pamAccountDAL.updateById(account.id, {
|
||||||
account.id,
|
rotationStatus: "failed",
|
||||||
{
|
encryptedLastRotationMessage: encryptedMessage
|
||||||
rotationStatus: "failed",
|
});
|
||||||
encryptedLastRotationMessage: encryptedMessage
|
|
||||||
},
|
|
||||||
tx
|
|
||||||
);
|
|
||||||
|
|
||||||
await auditLogService.createAuditLog({
|
await auditLogService.createAuditLog({
|
||||||
projectId: account.projectId,
|
projectId: account.projectId,
|
||||||
actor: {
|
actor: {
|
||||||
type: ActorType.PLATFORM,
|
type: ActorType.PLATFORM,
|
||||||
metadata: {}
|
metadata: {}
|
||||||
},
|
},
|
||||||
event: {
|
event: {
|
||||||
type: EventType.PAM_ACCOUNT_CREDENTIAL_ROTATION_FAILED,
|
type: EventType.PAM_ACCOUNT_CREDENTIAL_ROTATION_FAILED,
|
||||||
metadata: {
|
metadata: {
|
||||||
accountId: account.id,
|
accountId: account.id,
|
||||||
accountName: account.name,
|
accountName: account.name,
|
||||||
resourceId: account.resourceId,
|
resourceId: account.resourceId,
|
||||||
resourceType: logResourceType,
|
resourceType: logResourceType,
|
||||||
errorMessage
|
errorMessage
|
||||||
}
|
|
||||||
}
|
}
|
||||||
});
|
}
|
||||||
|
});
|
||||||
throw error;
|
}
|
||||||
}
|
});
|
||||||
})
|
|
||||||
);
|
|
||||||
|
|
||||||
// eslint-disable-next-line no-await-in-loop
|
// eslint-disable-next-line no-await-in-loop
|
||||||
await Promise.all(rotationPromises);
|
await Promise.all(rotationPromises);
|
||||||
|
|||||||
Reference in New Issue
Block a user