tju-yxq opened a new pull request, #5250:
URL: https://github.com/apache/rocketmq-dashboard/pull/5250

   ### Which Issue(s) This PR Fixes
   
   - Fixes #5249
   
   ### Brief Description
   
   Adds `DELETE /api/studio-users/{userId}` backed by a new 
`AuthService.deleteUser`:
   
   - The account row and its sessions are removed in **one transaction** 
(`@Transactional`) — `rmq_studio_session` has no foreign key to 
`rmq_studio_user`, so without the explicit delete the token-hash rows would 
linger as unreachable entries until the expiry sweep.
   - The operator's own account is rejected with **400** ("The current account 
cannot delete itself; disable it instead") — deleting yourself mid-request 
turns the response into a confusing session-expiry redirect.
   - The last **enabled** administrator is rejected with **409** under the same 
`FOR UPDATE` row lock the disable path uses (`SELECT ... WHERE admin = true AND 
enabled = true FOR UPDATE`), so two concurrent deletes cannot strip a 
deployment of every admin.
   - A **disabled** administrator is deletable even when it is the only admin 
account, because it is not part of the enabled-admin set that guards lockout 
(mirrors the disable path's stale-read tolerance).
   - Missing ids are rejected with the existing 404 "User not found" behavior.
   
   The user management page adds a destructive `Popconfirm` on each row (red 
button, `disabled` for the current account's own row) that calls the endpoint, 
closes the account's session drawer if it was open, and reloads the list. New 
UI text carries both Chinese and English entries under 
`web/src/i18n/translations.ts`.
   
   Existing endpoints and behaviors are unchanged.
   
   ### How Did You Test This Change?
   
   Focused suites on the branch (Windows, Java 21, Node 20):
   
   ```
   cd server && mvn '-Dtest=AuthServiceDatabaseTest,StudioUserControllerTest' 
test
   [INFO] Tests run: 36, Failures: 0, Errors: 0, Skipped: 0 -- in 
...AuthServiceDatabaseTest
   [INFO] Tests run: 6, Failures: 0, Errors: 0, Skipped: 0 -- in 
...StudioUserControllerTest
   [INFO] BUILD SUCCESS
   ```
   
   Seven new service tests cover: success path (session delete wrapper scoped 
to `user_id` + `deleteById`), self-delete 400, last-enabled-admin 409 with no 
deletes, delete-with-other-admin-present succeeds, disabled admin skips the 
guard entirely, missing user 404, plus one MockMvc test for the `DELETE` route. 
One new frontend test pair covers the confirm-then-delete flow (asserts the 
confirm copy, the `deleteStudioUser(7)` call and the list reload) and the 
disabled delete button on the operator's own row.
   
   ```
   cd web && npm test -- UserManagement.test.tsx --run
    Test Files  1 passed (1)
         Tests  14 passed (14)
   ```
   
   ```
   cd web && npm run lint
   ✖ 10 problems (0 errors, 10 warnings)   # all pre-existing warnings in files 
this PR does not touch
   ```
   
   ```
   cd web && npx tsc -b --force
   src/components/__tests__/MetricsExplorer.test.tsx(516,38): error TS2353: ...
   ```
   
   The single tsc error is the pre-existing trunk error in 
`MetricsExplorer.test.tsx` (a file this PR does not touch); it reproduces on 
every PR targeting `rocketmq-studio`, including other contributors'.
   
   Full backend suite on this branch:
   
   ```
   cd server && mvn test
   [INFO] Tests run: 3329, Failures: 0, Skipped: 4
   [ERROR] ... Errors: 22
   ```
   
   All 22 errors are environmental on this Windows machine and none touch the 
code this PR changes: 19 are Spring `Failed to load ApplicationContext` 
failures across health-probe / alert-mapper / bootstrap / outbox integration 
tests plus `claude` CLI availability errors in `ClaudeCodeAgentProviderTest` 
and one H2 `ConcurrentModificationException`. The same ApplicationContext 
failures reproduce identically on a clean `rocketmq-studio`-based worktree of 
this fork whose PR (#5248) passes the CI "Backend Tests (Java 21)" job, which 
runs the full suite on Linux and is the authoritative gate.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [x] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [x] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to