move catch outside of the TX

This commit is contained in:
x032205
2025-10-28 05:32:24 -04:00
parent 3ee9c3ac7d
commit d468c668f2
@@ -578,10 +578,10 @@ export const pamAccountServiceFactory = ({
for (let i = 0; i < accounts.length; i += ROTATION_CONCURRENCY_LIMIT) { for (let i = 0; i < accounts.length; i += ROTATION_CONCURRENCY_LIMIT) {
const batch = accounts.slice(i, i + ROTATION_CONCURRENCY_LIMIT); const batch = accounts.slice(i, i + ROTATION_CONCURRENCY_LIMIT);
const rotationPromises = batch.map(async (account) => const rotationPromises = batch.map(async (account) => {
pamAccountDAL.transaction(async (tx) => { let logResourceType = "unknown";
let logResourceType = "unknown"; try {
try { await pamAccountDAL.transaction(async (tx) => {
const resource = await pamResourceDAL.findById(account.resourceId, tx); const resource = await pamResourceDAL.findById(account.resourceId, tx);
if (!resource || !resource.encryptedRotationAccountCredentials) return; if (!resource || !resource.encryptedRotationAccountCredentials) return;
logResourceType = resource.resourceType; logResourceType = resource.resourceType;
@@ -645,51 +645,45 @@ export const pamAccountServiceFactory = ({
} }
} }
}); });
} catch (error) { });
logger.error(error, `Failed to rotate credentials for account [accountId=${account.id}]`); } catch (error) {
logger.error(error, `Failed to rotate credentials for account [accountId=${account.id}]`);
const errorMessage = error instanceof Error ? error.message : "An unknown error occurred"; const errorMessage = error instanceof Error ? error.message : "An unknown error occurred";
const { encryptor } = await kmsService.createCipherPairWithDataKey({ const { encryptor } = await kmsService.createCipherPairWithDataKey({
type: KmsDataKey.SecretManager, type: KmsDataKey.SecretManager,
projectId: account.projectId projectId: account.projectId
}); });
const { cipherTextBlob: encryptedMessage } = encryptor({ const { cipherTextBlob: encryptedMessage } = encryptor({
plainText: Buffer.from(errorMessage) plainText: Buffer.from(errorMessage)
}); });
await pamAccountDAL.updateById( await pamAccountDAL.updateById(account.id, {
account.id, rotationStatus: "failed",
{ encryptedLastRotationMessage: encryptedMessage
rotationStatus: "failed", });
encryptedLastRotationMessage: encryptedMessage
},
tx
);
await auditLogService.createAuditLog({ await auditLogService.createAuditLog({
projectId: account.projectId, projectId: account.projectId,
actor: { actor: {
type: ActorType.PLATFORM, type: ActorType.PLATFORM,
metadata: {} metadata: {}
}, },
event: { event: {
type: EventType.PAM_ACCOUNT_CREDENTIAL_ROTATION_FAILED, type: EventType.PAM_ACCOUNT_CREDENTIAL_ROTATION_FAILED,
metadata: { metadata: {
accountId: account.id, accountId: account.id,
accountName: account.name, accountName: account.name,
resourceId: account.resourceId, resourceId: account.resourceId,
resourceType: logResourceType, resourceType: logResourceType,
errorMessage errorMessage
}
} }
}); }
});
throw error; }
} });
})
);
// eslint-disable-next-line no-await-in-loop // eslint-disable-next-line no-await-in-loop
await Promise.all(rotationPromises); await Promise.all(rotationPromises);