unbridled-41 opened a new pull request, #5981: URL: https://github.com/apache/rocketmq-dashboard/pull/5981
### Which Issue(s) This PR Fixes Fixes #5980 ### Problem / Evidence ```java // UpsertPlainAccessConfigDTO / PlainAccessConfigVO private boolean admin; // MybatisPlusAclRepository.createAndUpdatePlainAccessConfig entity.setAdmin(config.isAdmin()); ``` `updateById` writes `Boolean.FALSE` (only null is skipped), so an update that omitted the flag demoted the account; the console's own model (`aclService.ts`) and the sibling user update (`UpdateAclUserDTO` javadoc: preserve when null) both preserve it. ``` MybatisPlusAclRepositoryTest: updateWithOmittedAdminShouldKeepStoredAdminFlagTest Expecting value to be true but was false ``` ### Root cause / Fix Optionality modelled with a primitive. Make the flag nullable on the request/response VO and resolve the effective value in the repository: omitted keeps an existing account's stored value, a new account defaults to false, an explicit value always wins; the response carries the effective value so the web contract is unchanged. ### Priority and scoring **PRIORITY 58** - impact 24/40 (a silent privilege downgrade on a security surface), blast radius 12/20 (any partial update of an existing account), reproducibility 16/20 (pinned by two new tests), maintenance value 6/20. **FIX_CONFIDENCE 72**. ### Tests `cd server && mvn -o -B -ntp test -Dtest='MybatisPlusAclRepositoryTest,AclServiceTest,AclControllerTest'` -> `Tests run: 134, Failures: 0, Errors: 0`. The preservation case fails before the resolution step and passes after it; an explicit-false case guards the other direction; `checkstyle:check` passes. ### Risk The write response now always carries the effective boolean, so JSON consumers see the preserved value instead of an absent field; the read-back views are unchanged. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
