zjncs opened a new pull request, #5658:
URL: https://github.com/apache/rocketmq-dashboard/pull/5658
### Problem
`AuthenticatedUserContext` (the ThreadLocal behind
`AuthenticatedUserContext.currentUsernameOrSystem()`, used by the audit trail
and every `OperationAuditService.record` call) had **no test**. Its contracts
carry three subtleties a refactor could silently break:
| Contract | Subtlety |
| --- | --- |
| `setUser(username, admin)` with a blank username | clears the **whole**
context, including a previously set user id (the blank branch delegates to
`clear()`) |
| an unset (fresh-thread) context | reads as the system actor, which is
**privileged**: `currentUserIsAdminOrSystem()` is `true` while
`currentUserIsAdmin()` is `false` |
| `setUser(null id, username)` | removes the stored id but keeps the
username |
### Change
Add `AuthenticatedUserContextTest` with seven tests pinning: the
fresh-thread system read, the admin flag through both setters, the id
round-trip as a string, the null-id removal, the blank-username full clear, and
`clear()` itself. ThreadLocals are reset in `@AfterEach`.
### Verification
- New tests: **7/7 green** against unmodified code.
- Discriminating mutations on `AuthenticatedUserContext` (new tests red,
others green):
- blank username no longer clears (branch replaced): **1/7 red**
- `currentUsernameOrSystem` system fallback removed: **3/7 red**
- unset admin no longer counts as admin-or-system: **2/7 red**
- Restored: 7/7 green. Auth test neighbours pass
(`AuthServiceBootstrapIntegrationTest`'s context-load error is the pre-existing
local-baseline environment failure — needs a live DB, fails identically on
unmodified master).
- No product code changed.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]