fix(ui): make self-service profile edits report their outcome (#5699)

* fix(ui): make self-service profile edits report their outcome

When a non-admin user saved their own profile (e.g. changing their
password via EnableUserEditing), the data provider followed the user
update with a call to the admin-only PUT /api/user/{id}/library
endpoint, which always failed with 403. The save error handler then
crashed reading error.body.errors on the plain-text response, so the
user got no notification at all - while the profile change had in fact
already been applied. This made password changes look like they were
silently ignored, and follow-up attempts failed with 'password does not
match' since the current password had already changed. Present since
the multi-library support introduced in v0.58.0 (#4181).

Only call the user-library association endpoint when the logged-in user
is an admin (the server manages assignments for self-edits), and make
the save error handler tolerate error bodies without field errors,
notifying a generic error instead of crashing.

* fix(ui): tolerate nullish rejection values in user save handler

Address review feedback: use optional chaining on the error itself in
the UserEdit save handler, so a nullish rejection value also results in
the generic error notification instead of a TypeError.
This commit is contained in:
Deluan Quintão 2026-07-01 21:31:29 -04:00 • committed by GitHub
commit e80a7937e8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
4 changed files with 167 additions and 10 deletions

View file

@ -137,8 +137,9 @@ const updateUser = async (params) => {
data: userData,
})
// Then handle library associations for non-admin users
if (!userData.isAdmin && libraryIds !== undefined) {
// Then handle library associations for non-admin users. Only admins can call
// this endpoint; for self-edits the server manages library assignments
if (isAdmin() && !userData.isAdmin && libraryIds !== undefined) {
await handleUserLibraryAssociation(userId, libraryIds)
}