tju-yxq opened a new pull request, #5250:
URL: https://github.com/apache/rocketmq-dashboard/pull/5250
### Which Issue(s) This PR Fixes
- Fixes #5249
### Brief Description
Adds `DELETE /api/studio-users/{userId}` backed by a new
`AuthService.deleteUser`:
- The account row and its sessions are removed in **one transaction**
(`@Transactional`) — `rmq_studio_session` has no foreign key to
`rmq_studio_user`, so without the explicit delete the token-hash rows would
linger as unreachable entries until the expiry sweep.
- The operator's own account is rejected with **400** ("The current account
cannot delete itself; disable it instead") — deleting yourself mid-request
turns the response into a confusing session-expiry redirect.
- The last **enabled** administrator is rejected with **409** under the same
`FOR UPDATE` row lock the disable path uses (`SELECT ... WHERE admin = true AND
enabled = true FOR UPDATE`), so two concurrent deletes cannot strip a
deployment of every admin.
- A **disabled** administrator is deletable even when it is the only admin
account, because it is not part of the enabled-admin set that guards lockout
(mirrors the disable path's stale-read tolerance).
- Missing ids are rejected with the existing 404 "User not found" behavior.
The user management page adds a destructive `Popconfirm` on each row (red
button, `disabled` for the current account's own row) that calls the endpoint,
closes the account's session drawer if it was open, and reloads the list. New
UI text carries both Chinese and English entries under
`web/src/i18n/translations.ts`.
Existing endpoints and behaviors are unchanged.
### How Did You Test This Change?
Focused suites on the branch (Windows, Java 21, Node 20):
```
cd server && mvn '-Dtest=AuthServiceDatabaseTest,StudioUserControllerTest'
test
[INFO] Tests run: 36, Failures: 0, Errors: 0, Skipped: 0 -- in
...AuthServiceDatabaseTest
[INFO] Tests run: 6, Failures: 0, Errors: 0, Skipped: 0 -- in
...StudioUserControllerTest
[INFO] BUILD SUCCESS
```
Seven new service tests cover: success path (session delete wrapper scoped
to `user_id` + `deleteById`), self-delete 400, last-enabled-admin 409 with no
deletes, delete-with-other-admin-present succeeds, disabled admin skips the
guard entirely, missing user 404, plus one MockMvc test for the `DELETE` route.
One new frontend test pair covers the confirm-then-delete flow (asserts the
confirm copy, the `deleteStudioUser(7)` call and the list reload) and the
disabled delete button on the operator's own row.
```
cd web && npm test -- UserManagement.test.tsx --run
Test Files 1 passed (1)
Tests 14 passed (14)
```
```
cd web && npm run lint
✖ 10 problems (0 errors, 10 warnings) # all pre-existing warnings in files
this PR does not touch
```
```
cd web && npx tsc -b --force
src/components/__tests__/MetricsExplorer.test.tsx(516,38): error TS2353: ...
```
The single tsc error is the pre-existing trunk error in
`MetricsExplorer.test.tsx` (a file this PR does not touch); it reproduces on
every PR targeting `rocketmq-studio`, including other contributors'.
Full backend suite on this branch:
```
cd server && mvn test
[INFO] Tests run: 3329, Failures: 0, Skipped: 4
[ERROR] ... Errors: 22
```
All 22 errors are environmental on this Windows machine and none touch the
code this PR changes: 19 are Spring `Failed to load ApplicationContext`
failures across health-probe / alert-mapper / bootstrap / outbox integration
tests plus `claude` CLI availability errors in `ClaudeCodeAgentProviderTest`
and one H2 `ConcurrentModificationException`. The same ApplicationContext
failures reproduce identically on a clean `rocketmq-studio`-based worktree of
this fork whose PR (#5248) passes the CI "Backend Tests (Java 21)" job, which
runs the full suite on Linux and is the authoritative gate.
### Checklist
- [x] One coherent change; unrelated modifications are not bundled in
- [x] Commit subject follows Conventional Commits
- [x] Tests added or updated for non-trivial changes, test methods named
`...Test`
- [x] New UI text has both Chinese and English entries under `web/src/i18n/`
- [x] Architecture constraints stay green (`mvn test` runs the ArchUnit
checks)
- [x] New source files carry the ASF license header
- [ ] Documentation touched where behaviour changed (README / `docs/` /
in-app help)
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]