yx9o opened a new pull request, #6173:
URL: https://github.com/apache/rocketmq-dashboard/pull/6173

   ### Brief Description
   
   Validate Tencent ACL rule actions before creating or updating role 
permissions. Previously, unsupported actions were silently ignored. A typo such 
as `PBU` produced a `ModifyRole` request with both read and write permissions 
disabled, while a mixed list such as `["PUB", "PBU"]` applied only the 
recognized permission.
   
   Reject missing or empty action lists, null entries, blank values, and 
unsupported actions with business code 400 before any cloud API call. Preserve 
the existing case-insensitive `PUB`, `SUB`, and `ALL` mapping, including 
duplicate supported actions.
   
   The change reuses the rule validation shared by creation and update and adds 
regression coverage in `TencentAclServiceTest`.
   
   ### How Did You Test This Change?
   
   - `cd server && mvn -B -ntp 
-Dtest=TencentAclServiceTest,AclServiceTest,AclControllerTest test`
     - 132 tests passed, with zero failures, errors, or skipped tests.
     - Compilation and Checkstyle passed.
   - Seven invalid-action regression cases failed against the original code and 
passed after the fix.
   - Regression tests verify that both creation and update return business code 
400 without invoking the cloud client, and that valid mixed-case and duplicate 
actions retain their permission mapping.
   - `git diff --check` passed.
   
   Tencent SDK clients are mocked; no live Tencent Cloud integration test was 
run.
   
   ### Checklist
   
   - [x] One coherent change; unrelated modifications are not bundled in
   - [x] Commit subject follows Conventional Commits (`fix:`)
   - [x] Tests added or updated for non-trivial changes, test methods named 
`...Test`
   - [x] New UI text has both Chinese and English entries under `web/src/i18n/` 
— not applicable; no UI text added
   - [ ] Architecture constraints stay green — the focused suite did not run 
ArchUnit checks
   - [x] New source files carry the ASF license header — not applicable; no new 
source files
   - [x] Documentation touched where behaviour changed — no update needed; the 
existing API documentation already defines the supported actions


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to