Frun1na opened a new pull request, #5686:
URL: https://github.com/apache/rocketmq-dashboard/pull/5686

   ### Which Issue(s) This PR Fixes
   
   No issue: documentation for endpoints the specification omits. Third area 
extracted from #4835 (the umbrella report #4831, "api-spec omits the auth 
status, password change and run speed endpoints", is already closed by the 
stale bot; the `POST /api/ai/runs/:runId/speed` endpoint it also names is left 
to an AI-section PR).
   
   ### Brief Description
   
   §1 documents login and logout but not the two endpoints the console calls on 
every page load and on every password change:
   
   - **1.3** `GET /api/auth/status` — the login policy and the current user, 
callable without a session (`authenticated: false`, `user: null`), which is 
what lets the frontend decide whether to show the login screen. Response 
carries `Cache-Control: no-store`.
   - **1.4** `POST /api/auth/password` — change the current user's password 
(`currentPassword`, `newPassword` 8-256), then all of that user's sessions are 
revoked.
   
   Both were read off the current code:
   
   | Section | Source |
   |---|---|
   | 1.3 | `AuthController.status`, `AuthStatusVO` (`loginRequired` / 
`authenticated` / `user`), `LoginVO.UserInfo`; the `loginRequired` fallback to 
the general settings toggle comes from `AuthController.isLoginRequired` |
   | 1.4 | `AuthController.changePassword` (`401` when unauthenticated, `503` 
when user management is uninitialized), `ChangePasswordDTO` (`@NotBlank` + 
`@Size(min = 8, max = 256)`), `AuthService.changePassword` → 
`revokeUserSessions` |
   
   ### How Did You Test This Change?
   
   Documentation only — no code, configuration or test changes.
   
   - Both paths matched against their `@GetMapping` / `@PostMapping` 
declarations in 
`server/src/main/java/org/apache/rocketmq/studio/auth/AuthController.java`; 
required flags and length bounds against `ChangePasswordDTO`'s validation 
annotations.
   - The response fields of 1.3 match `AuthStatusVO` field by field, including 
the nested `user` object (its `userId` note matches §1.1's existing wording for 
bootstrap users).
   - The session-revocation sentence follows `AuthService.changePassword`'s 
`revokeUserSessions(user.getId())`; the `401`/`503` codes come from the 
controller's own throws.
   - Markdown structure checked with `grep -n "^### 1\\."` (1.1-1.4 in order) 
and the two new quick-reference rows (`119`, `120`) are unique.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / 
`refactor:` / `chore:` / `docs:` / `perf:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [ ] New UI text has both Chinese and English entries under `web/src/i18n/`
   - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit 
checks)
   - [ ] New source files carry the ASF license header
   - [x] Documentation touched where behaviour changed (README / `docs/` / 
in-app help)
   
   ---
   
   Third area extracted from #4835 (after #5683 for the consumer-group 
endpoints and #5684 for LiteTopic), which no longer merges after the file moved 
100+ commits underneath it. The quick-reference rows are numbered 119-120 
because #5683 adds 108-113 and #5684 adds 114-118 to the same place; whichever 
merges last needs a one-line renumber, and I am happy to rebase instead.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to