Frun1na opened a new pull request, #5654:
URL: https://github.com/apache/rocketmq-dashboard/pull/5654

   ### Which Issue(s) This PR Fixes
   
   - Fixes #5653
   
   ### Brief Description
   
   The dry-run handshake cannot be completed for a tool whose input has an 
`x-client-default: NOW` field. The server signs the previewed business input 
into the confirm token (`ToolTokenService` → 
`canonicalInput(context.businessInput())`; `timestamp` is a business field), 
while the CLI fills a fresh `nowMillis()` on every invocation — so the replay 
that the server's own hint asks for ("without changing the operation input") 
carries a different timestamp and always fails with 
`CONFIRMATION_TOKEN_INVALID`.
   
   `applyClientDefaults` now returns the fields it filled, and `runTool` 
refuses a call that combines an auto-filled NOW field with a `--confirm-token`, 
before anything is sent:
   
   ```
   error [INVALID_ARGUMENT]: --confirm-token cannot replay an auto-filled 
--timestamp
   hint: The preview signed its own --timestamp into the token, and this call 
filled a new value, so the
     server would reject it as a preview mismatch. Pin the previewed value with 
--timestamp <value from
     the preview plan>, or drop --confirm-token to let --yes run the preview 
and the call together.
   ```
   
   Both working paths are untouched: dropping `--confirm-token` keeps the 
transparent preview-then-call run (same in-memory arguments, matching 
timestamp), and an explicitly supplied `--timestamp` keeps the token usable — 
which is what the new hint tells the caller to do. The check is generic over 
the catalog metadata rather than hard-coded to `timestamp`, so the next 
NOW-defaulted field inherits it.
   
   ### How Did You Test This Change?
   
   ```
   $ cd rmqctl && go test ./cmd/ -run 
'TestConfirmTokenReplay|TestExplicitTimestampStillReplays|TestClientDefaultNow' 
-v
   --- PASS: TestClientDefaultNowFillsMissingTimestamp (0.01s)
   --- PASS: TestClientDefaultNowKeepsExplicitTimestamp (0.00s)
   --- PASS: TestClientDefaultNowSatisfiesRequiredValidation (0.00s)
   --- PASS: TestConfirmTokenReplayWithAutoFilledTimestampIsRefused (0.00s)
   --- PASS: TestExplicitTimestampStillReplaysConfirmToken (0.00s)
   
   $ cd rmqctl && go test ./cmd/ && go vet ./cmd/
   ok   github.com/apache/rocketmq-dashboard/rmqctl/cmd 0.217s
   (gofmt -l and go vet print nothing)
   ```
   
   The new test fails without the guard, and shows what it prevents — the tool 
call reaches the server with the fresh fill:
   
   ```
   $ go test ./cmd/ -run TestConfirmTokenReplayWithAutoFilledTimestampIsRefused 
  # guard reverted
   --- FAIL: TestConfirmTokenReplayWithAutoFilledTimestampIsRefused (0.01s)
       a confirm-token replay with an auto-filled timestamp must be refused, 
request=types.ToolCallRequest{
         Name:"rmq.synthetic.confirmed-reset", Arguments:map[string]interface 
{}{
           "confirm_token":"server-issued", "groupName":"gid-orders",
           "instanceId":"instance-x", "timestamp":1.7576e+12}}
   ```
   
   Both tests use a new L2 fixture that combines the NOW field with 
`dry_run`/`confirm_token`, mirroring the real `rmq.group.reset_offset` schema.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [x] New source files carry the ASF license header
   - [ ] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to