btlqql opened a new pull request, #5849: URL: https://github.com/apache/rocketmq-dashboard/pull/5849
## Why `POST /api/settings/general/save` is admin-only (AuthInterceptor READER_POST_PATHS does not include it), and GET `/api/settings/general` hands readers redacted webhook values. GeneralSettingsTab gates nothing on role, so for a reader (non-admin): - switching theme or compact mode fires a settings save that can only end in 403 — showing `Failed to save settings` right after the preference visibly applied — and the attempted payload round-trips the redacted `dingtalkWebhook`/`smsWebhook` sentinel values, - the notification and session-timeout save/test buttons are all enabled but guaranteed to fail. Ops.tsx already models this correctly with `writeOperationEnabled`; this tab diverges from that twin. ## What changed - Derive `canWriteSettings = !userId || admin === true` from the auth store (same rule Ops uses). - Theme/compact changes stay local for readers (they already apply via useTheme) and skip the doomed server write, so no error toast. - The admin-only buttons (session-timeout save, notification save, the three test buttons, clear-secret) are disabled for readers, with matching handler guards. ## Validation - New test `GeneralSettingsTabReader.test.tsx` (reader store mocked): a theme switch must not call `saveGeneralSettings` nor show the save-failed toast, and the save/test buttons must be disabled. Both fail before the fix — the first one shows the redacted `******` webhook values being sent — and pass after. - Existing suites still pass: `GeneralSettingsTab.test.tsx`, `GeneralSettingsFormResidue.test.tsx`, `SettingsPage.test.tsx`; `tsc --noEmit` clean. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
