justinmclean opened a new issue, #4214:
URL: https://github.com/apache/iggy/issues/4214
### Bug description
`web/src/lib/api/ApiSchema.ts` is a hand-written list of the HTTP routes the
Web UI calls, and three entries don't match the server's HTTP API
(`core/server/src/http.rs` and `core/server/src/http/handlers.rs`):
- Logout is declared as `POST /users/logout`. The server route is `DELETE
/users/logout`.
- There is a `GET /users/{id}` entry with a request body of `username`,
`status` and `permissions`. The server's update route is `PUT /users/{id}`, and
its body (`UpdateUser`) takes `username`, `status` and `options`. `permissions`
is ignored; permissions are changed with `PUT /users/{id}/permissions`.
- The `PUT /users/{id}/permissions` entry makes `permissions` required. The
server accepts it as null or missing, which removes all of the user's
permissions.
The logout route moved from `POST` to `DELETE` in #889 (April 2024), a year
before the Web UI was brought into this repo in #1739, and the type list was
never updated. None of these entries is used yet: the Edit user modal is a
placeholder, and nothing calls logout or the permissions route. They would fail
once user editing is built on them.
Separately, the Web UI's logout (`authStore.logout()` in
`web/src/lib/auth/authStore.svelte.ts`) only clears the token cookie and never
calls the server, so the server-side session stays open. The server's logout
ends the session but doesn't revoke the token, which stays valid until it
expires. Is calling `DELETE /users/logout` on logout wanted?
This should wait until #4212 is merged. It adds `core/server/openapi.json`,
a description of every HTTP route that is kept in step with the server by a
test, so the fix can check the Web UI's entries against it, or generate them
from it, rather than reading the Rust code.
### Affected area / component
Web UI
### Deployment
Not applicable
### Versions
The current default branch.
### Reproduction
Compare the entries in `web/src/lib/api/ApiSchema.ts` with the routes in
`core/server/src/http.rs` and the request types in
`core/common/src/http/users/`.
### Contribution
- [ ] I'm willing to submit a pull request to fix this bug
### Good first issue
- [x] I think this could be a good first issue for a new contributor
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]