unbridled-41 opened a new pull request, #5983:
URL: https://github.com/apache/rocketmq-dashboard/pull/5983

   ### Which Issue(s) This PR Fixes
   Fixes #5982
   ### Problem / Evidence
   `METRICS_QUERY_HISTORY_STORAGE_KEY` was one global key; 
`authStorage.clearAuthSession` removes only the token/user keys, so the history 
survived a logout:
   ```
   metricsExplorerDiagnostics: does not hand one account the query history of 
another
   AssertionError: expected [ { ...(17) } ] to deeply equal []
   ```
   (with an unscoped key; the entry is rendered in the drawer and re-runnable).
   ### Root cause / Fix
   Account-scoped data under an account-independent key. Derive the key from 
the signed-in account (user id, else the username, else `anonymous`) and export 
the key builder so the panel's tests seed and assert against the current 
account's store.
   ### Priority and scoring
   **PRIORITY 55** - impact 20/40 (cross-account disclosure of query content), 
blast radius 10/20 (shared browsers), reproducibility 18/20 (pinned by the new 
test), maintenance value 4/20. **FIX_CONFIDENCE 75**.
   ### Tests
   `cd web && npx vitest run src/utils/metricsExplorerDiagnostics.test.ts 
src/components/__tests__/MetricsExplorer.test.tsx` -> `Tests 46 passed`; the 
new case fails with an unscoped key and passes with the scoped one; the six 
explorer cases that seeded the raw key now use the exported builder; `npx 
eslint` and `npx tsc -b` pass.
   ### Risk
   A history written before this change is not visible after it (the key 
changes) - acceptable for scratch history, and the same trade the 
account-scoping work elsewhere makes.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to