btlqql opened a new pull request, #5849:
URL: https://github.com/apache/rocketmq-dashboard/pull/5849

   ## Why
   `POST /api/settings/general/save` is admin-only (AuthInterceptor 
READER_POST_PATHS does not include it), and GET `/api/settings/general` hands 
readers redacted webhook values. GeneralSettingsTab gates nothing on role, so 
for a reader (non-admin):
   - switching theme or compact mode fires a settings save that can only end in 
403 — showing `Failed to save settings` right after the preference visibly 
applied — and the attempted payload round-trips the redacted 
`dingtalkWebhook`/`smsWebhook` sentinel values,
   - the notification and session-timeout save/test buttons are all enabled but 
guaranteed to fail.
   Ops.tsx already models this correctly with `writeOperationEnabled`; this tab 
diverges from that twin.
   
   ## What changed
   - Derive `canWriteSettings = !userId || admin === true` from the auth store 
(same rule Ops uses).
   - Theme/compact changes stay local for readers (they already apply via 
useTheme) and skip the doomed server write, so no error toast.
   - The admin-only buttons (session-timeout save, notification save, the three 
test buttons, clear-secret) are disabled for readers, with matching handler 
guards.
   
   ## Validation
   - New test `GeneralSettingsTabReader.test.tsx` (reader store mocked): a 
theme switch must not call `saveGeneralSettings` nor show the save-failed 
toast, and the save/test buttons must be disabled. Both fail before the fix — 
the first one shows the redacted `******` webhook values being sent — and pass 
after.
   - Existing suites still pass: `GeneralSettingsTab.test.tsx`, 
`GeneralSettingsFormResidue.test.tsx`, `SettingsPage.test.tsx`; `tsc --noEmit` 
clean.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to