tju-yxq opened a new pull request, #5248:
URL: https://github.com/apache/rocketmq-dashboard/pull/5248

   ### Which Issue(s) This PR Fixes
   
   - Fixes #5247
   
   ### Brief Description
   
   Adds `POST /api/studio-users/{userId}/role` taking `{ "admin": true|false 
}`, mirroring the existing status endpoint. `AuthService.setUserAdmin` reuses 
the row-locking guard from `setUserEnabled`: revoking the role from the last 
enabled administrator is refused with 409, so concurrent revokes cannot strip 
every administrator. Every actual role change revokes the user's sessions — the 
authenticated session snapshots the admin flag, so a re-login is required for 
the new role to take effect (the same reasoning `changePassword` applies) — 
while an idempotent no-op change writes and revokes nothing. The user 
management page replaces the static role tag with a role switch for 
administrator viewers (readers keep the tag, matching the admin-only mutation 
surface), confirmation-gated with copy that states the session-revocation 
consequence; revoking uses a danger-styled confirm.
   
   ### How Did You Test This Change?
   
   Run on the branch (`e3ae568f`, based on `master` @ `0228dad5`):
   
   ```
   cd server && mvn -B -ntp 
'-Dtest=AuthServiceDatabaseTest,StudioUserControllerTest' test
   AuthServiceDatabaseTest: 33, StudioUserControllerTest: 7
   Tests run: 40, Failures: 0, Errors: 0, Skipped: 0 — BUILD SUCCESS
   
   cd web && npm test -- UserManagement --run
   Test Files  1 passed (1)
        Tests  14 passed (14)
   
   cd web && npm run lint
   0 errors (11 pre-existing warnings in unrelated files)
   ```
   
   New coverage: the service tests pin granting (flag write + session 
revocation, no last-admin scan), last-admin rejection (no write, no 
revocation), multi-admin revoke, and idempotence; the controller tests pin the 
pass-through and the 400 on a missing `admin` field; the page tests pin both 
confirmation flows (grant and danger-styled revoke) with the reload. The two 
existing status-switch tests were disambiguated from the new role switch by 
their 启用/停用 copy and keep passing unchanged.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [x] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [x] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to