unbridled-41 opened a new issue, #5982:
URL: https://github.com/apache/rocketmq-dashboard/issues/5982

   ### Studio Version
   branch: `rocketmq-studio` @ `7e7aa344`
   ### Runtime Environment
   Frontend tests: `cd web && npx vitest run 
src/utils/metricsExplorerDiagnostics.test.ts`.
   ### Describe the Bug
   The metrics explorer keeps its query history in localStorage under one 
global key, loaded once when the panel mounts and cleared only by the explicit 
button. Logout clears the auth store's own keys only, so the next account on a 
shared browser sees the previous account's history: PromQL text, metric/profile 
names, instance ids, data-source keys and the queried windows are rendered in 
the drawer and can be re-run under the new session. `/ops/dashboard` has no 
admin gate, so any signed-in account reaches the panel. The sibling client 
stores (composer draft, prompt templates, trace-topic preference) already carry 
the account in their keys.
   ### Steps to Reproduce
   1. Sign in as A, run queries in the metrics explorer. 2. Sign out, sign in 
as B, open the explorer: A's history is listed.
   ### What Did You Expect to See?
   An empty history for B.
   ### What Did You See Instead?
   A's queries, re-runnable.
   ### Impact
   Cross-account disclosure of query content (including instance and 
data-source identifiers) on a shared workstation.
   ### Acceptance Criteria
   The history is stored per account, the key builder is exported for the 
panel's tests, and a regression test proves the isolation.
   **Corresponding PR:** #ISSUEPR#
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to