Loyal-Young opened a new issue, #5358:
URL: https://github.com/apache/rocketmq-dashboard/issues/5358

   ### Summary
   
   The custom message trace topic is saved in browser local storage under a key 
containing only the instance ID. When two Studio accounts use the same browser 
and instance, the second account inherits the first account's trace topic. 
Their next trace lookup can silently query the wrong topic.
   
   ### Reproduction
   
   1. Sign in as account A, open Message Explorer for instance X, and enter a 
custom trace topic.
   2. Sign out and sign in as account B in the same browser.
   3. Open Message Explorer for instance X. The custom topic from account A is 
prefilled.
   
   `readMessageTraceTopic` and `writeMessageTraceTopic` in 
`web/src/utils/messageTraceTopicStorage.ts` key only on the instance ID. 
`MessagePage` initializes the field from that shared key.
   
   ### Expected behavior
   
   Store and read the preference under the authenticated account and instance. 
Anonymous local mode can use a separate anonymous scope. Do not migrate the 
existing unscoped key into any account, because its owner cannot be determined.
   
   ### Scope
   
   This is a browser preference isolation fix. It does not change server-side 
trace data or the message query API. A targeted storage test can reproduce the 
cross-account read before the fix and verify isolation after it.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to