justinmclean opened a new issue, #4214:
URL: https://github.com/apache/iggy/issues/4214

   ### Bug description
   
   `web/src/lib/api/ApiSchema.ts` is a hand-written list of the HTTP routes the 
Web UI calls, and three entries don't match the server's HTTP API 
(`core/server/src/http.rs` and `core/server/src/http/handlers.rs`):
   
   - Logout is declared as `POST /users/logout`. The server route is `DELETE 
/users/logout`.
   - There is a `GET /users/{id}` entry with a request body of `username`, 
`status` and `permissions`. The server's update route is `PUT /users/{id}`, and 
its body (`UpdateUser`) takes `username`, `status` and `options`. `permissions` 
is ignored; permissions are changed with `PUT /users/{id}/permissions`.
   - The `PUT /users/{id}/permissions` entry makes `permissions` required. The 
server accepts it as null or missing, which removes all of the user's 
permissions.
   
   The logout route moved from `POST` to `DELETE` in #889 (April 2024), a year 
before the Web UI was brought into this repo in #1739, and the type list was 
never updated. None of these entries is used yet: the Edit user modal is a 
placeholder, and nothing calls logout or the permissions route. They would fail 
once user editing is built on them.
   
   Separately, the Web UI's logout (`authStore.logout()` in 
`web/src/lib/auth/authStore.svelte.ts`) only clears the token cookie and never 
calls the server, so the server-side session stays open. The server's logout 
ends the session but doesn't revoke the token, which stays valid until it 
expires. Is calling `DELETE /users/logout` on logout wanted?
   
   This should wait until #4212 is merged. It adds `core/server/openapi.json`, 
a description of every HTTP route that is kept in step with the server by a 
test, so the fix can check the Web UI's entries against it, or generate them 
from it, rather than reading the Rust code.
   
   ### Affected area / component
   
   Web UI
   
   ### Deployment
   
   Not applicable
   
   ### Versions
   
   The current default branch.
   
   ### Reproduction
   
   Compare the entries in `web/src/lib/api/ApiSchema.ts` with the routes in 
`core/server/src/http.rs` and the request types in 
`core/common/src/http/users/`.
   
   ### Contribution
   
   - [ ] I'm willing to submit a pull request to fix this bug
   
   ### Good first issue
   
   - [x] I think this could be a good first issue for a new contributor
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to