Frun1na opened a new pull request, #5686: URL: https://github.com/apache/rocketmq-dashboard/pull/5686
### Which Issue(s) This PR Fixes No issue: documentation for endpoints the specification omits. Third area extracted from #4835 (the umbrella report #4831, "api-spec omits the auth status, password change and run speed endpoints", is already closed by the stale bot; the `POST /api/ai/runs/:runId/speed` endpoint it also names is left to an AI-section PR). ### Brief Description §1 documents login and logout but not the two endpoints the console calls on every page load and on every password change: - **1.3** `GET /api/auth/status` — the login policy and the current user, callable without a session (`authenticated: false`, `user: null`), which is what lets the frontend decide whether to show the login screen. Response carries `Cache-Control: no-store`. - **1.4** `POST /api/auth/password` — change the current user's password (`currentPassword`, `newPassword` 8-256), then all of that user's sessions are revoked. Both were read off the current code: | Section | Source | |---|---| | 1.3 | `AuthController.status`, `AuthStatusVO` (`loginRequired` / `authenticated` / `user`), `LoginVO.UserInfo`; the `loginRequired` fallback to the general settings toggle comes from `AuthController.isLoginRequired` | | 1.4 | `AuthController.changePassword` (`401` when unauthenticated, `503` when user management is uninitialized), `ChangePasswordDTO` (`@NotBlank` + `@Size(min = 8, max = 256)`), `AuthService.changePassword` → `revokeUserSessions` | ### How Did You Test This Change? Documentation only — no code, configuration or test changes. - Both paths matched against their `@GetMapping` / `@PostMapping` declarations in `server/src/main/java/org/apache/rocketmq/studio/auth/AuthController.java`; required flags and length bounds against `ChangePasswordDTO`'s validation annotations. - The response fields of 1.3 match `AuthStatusVO` field by field, including the nested `user` object (its `userId` note matches §1.1's existing wording for bootstrap users). - The session-revocation sentence follows `AuthService.changePassword`'s `revokeUserSessions(user.getId())`; the `401`/`503` codes come from the controller's own throws. - Markdown structure checked with `grep -n "^### 1\\."` (1.1-1.4 in order) and the two new quick-reference rows (`119`, `120`) are unique. ### Checklist - [x] One coherent change; unrelated modifications are not bundled in - [x] Commit subject follows Conventional Commits (`feat:` / `fix:` / `refactor:` / `chore:` / `docs:` / `perf:`) - [x] Tests added or updated for non-trivial changes, test methods named `...Test` - [ ] New UI text has both Chinese and English entries under `web/src/i18n/` - [ ] Architecture constraints stay green (`mvn test` runs the ArchUnit checks) - [ ] New source files carry the ASF license header - [x] Documentation touched where behaviour changed (README / `docs/` / in-app help) --- Third area extracted from #4835 (after #5683 for the consumer-group endpoints and #5684 for LiteTopic), which no longer merges after the file moved 100+ commits underneath it. The quick-reference rows are numbered 119-120 because #5683 adds 108-113 and #5684 adds 114-118 to the same place; whichever merges last needs a one-line renumber, and I am happy to rebase instead. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
