messere1 opened a new pull request, #6138:
URL: https://github.com/apache/rocketmq-dashboard/pull/6138

   ### What problem does this PR solve?
   
   `persistAuthSession` in `web/src/stores/authStorage.ts` writes the user, 
user-id and admin keys one by one, and each `writeLocalStorage` call swallows 
storage failures on its own. When an earlier write succeeds and a later one 
fails (quota exceeded, storage disabled by browser policy), the browser is left 
with a partial session: a reload restores a display identity whose id or admin 
flag is missing, so the auth UI and authorization state degrade inconsistently.
   
   Original report: #1598 (issue closed as not planned by the stale sweep, not 
invalidated as fixed).
   
   ### What is changed and how it works?
   
   `persistAuthSession` now checks each 
`writeLocalStorage`/`removeLocalStorage` result; when any of them fails it 
calls `clearAuthSession()`, so either every session key is written or none 
remains from the failed attempt. The in-memory store is untouched and keeps 
working while storage is unavailable, exactly as today.
   
   Scope is the auth storage helper and its unit test only.
   
   ### Verifies
   
   - [x] `npx vitest run src/stores/authStorage.test.ts` — 6/6 pass; the new 
regression test fails on the unpatched tip (the user key stays behind after a 
later `setItem` throws).
   - [x] `npx eslint` on the touched files — clean.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to