pilichoumao opened a new pull request, #6021: URL: https://github.com/apache/rocketmq-dashboard/pull/6021
### Which Issue(s) This PR Fixes - Fixes #6020 - Related: #5452 ### Brief Description After a Topic update dry-run, another operator can change the Topic configuration while the original request token still authorizes execution. Bind `rmq.topic.update` confirmation to its stable before/after configuration and return HTTP 409 / `CONFLICT` with a fresh-preview hint when that configuration changes. This is a **draft for design review**, based directly on `rocketmq-studio` (`7e7aa344`). It contains no commits from #5452. Only Topic update opts in; presentation text and dynamic counters are excluded. Other tools retain their existing request-only confirmation. Old unbound Topic update tokens require a new dry-run after upgrading, while existing unbound token fixtures remain unchanged for other tools. The signed `v1p` representation demonstrates state binding independently of single-use tokens. Before marking this ready, reconcile the representation and final order with #5452: authenticate request, generate preview, verify state, consume token once, execute. Single-use consumption is not implemented here. Maintainer agreement on #6020 is still pending. The state comparison does not provide an atomic Broker compare-and-set: a concurrent change after the final comparison remains possible. ### How Did You Test This Change? Java 21.0.10, Maven offline with the existing dependency cache: - Regression on the unmodified base: preview a Topic with 8 read queues, change it to 16, apply the original write-queue update. The new assertion fails because the base writes instead of returning a conflict. - `cd server && mvn -o -B -ntp -Dmaven.repo.local=<local-cache> -Dspring.profiles.active=dev -Dtest=TopicUpdatePlanBindingTest,ToolTokenServiceTest,ToolMutationFilterTest,TopicMutationPlanTest,ToolControllerTest,ToolCatalogTest test`: **44 tests, zero failures/errors** before the two REST/MCP conflict-mapping tests were added. - `cd server && mvn -o -B -ntp -Dmaven.repo.local=<local-cache> -Dspring.profiles.active=dev test`: final rerun **3410 tests, zero failures/errors, 3 skipped**, Checkstyle **0 violations**. Covers state drift, Topic creation/deletion, valid execution, dynamic metrics and text exclusion, legacy rejection for Topic update, request/caller/instance binding, digest tampering, expiry and REST/MCP conflict hints. - First full run had one H2 concurrent-migration error in `ResourceOwnershipGuardTest.migrationConcurrentStartupIsIdempotentTest`. The same test reproduces `ConcurrentModificationException` on the unmodified base. The full rerun passes without skipping that test or changing its code. - `make -C rmqctl catalog-verify`: passed. No catalog, CLI, frontend, dependency or database schema changes. - `cd server && mvn -o -B -ntp -Dmaven.repo.local=<local-cache> -DskipTests package`: compilation and JAR packaging succeed; the release `binary-license-gate` fails, as reproduced on the unmodified base during #6019 verification. - `git diff --check`: passed. Real Broker concurrency/ACL/TLS and MySQL integration were not exercised. Three tests are skipped by the existing suite; no additional test exclusions were introduced. ### Checklist - [x] One coherent change; unrelated modifications are not bundled in - [x] Commit subject follows Conventional Commits - [x] Tests added for non-trivial changes; new test methods end in `Test` - [x] New source file carries the ASF license header - [x] Documentation explains behavior, upgrade and concurrency limits - [x] Backend test suite green on final rerun; catalog verification passed - [ ] Maintainer agreement on #6020 and reconciliation with #5452 before ready-for-review - [ ] Full CI green (release license gates currently fail on the base) No UI text or frontend changes. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
