unbridled-41 opened a new issue, #5982: URL: https://github.com/apache/rocketmq-dashboard/issues/5982
### Studio Version branch: `rocketmq-studio` @ `7e7aa344` ### Runtime Environment Frontend tests: `cd web && npx vitest run src/utils/metricsExplorerDiagnostics.test.ts`. ### Describe the Bug The metrics explorer keeps its query history in localStorage under one global key, loaded once when the panel mounts and cleared only by the explicit button. Logout clears the auth store's own keys only, so the next account on a shared browser sees the previous account's history: PromQL text, metric/profile names, instance ids, data-source keys and the queried windows are rendered in the drawer and can be re-run under the new session. `/ops/dashboard` has no admin gate, so any signed-in account reaches the panel. The sibling client stores (composer draft, prompt templates, trace-topic preference) already carry the account in their keys. ### Steps to Reproduce 1. Sign in as A, run queries in the metrics explorer. 2. Sign out, sign in as B, open the explorer: A's history is listed. ### What Did You Expect to See? An empty history for B. ### What Did You See Instead? A's queries, re-runnable. ### Impact Cross-account disclosure of query content (including instance and data-source identifiers) on a shared workstation. ### Acceptance Criteria The history is stored per account, the key builder is exported for the panel's tests, and a regression test proves the isolation. **Corresponding PR:** #ISSUEPR# -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
