mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-11 11:57:12 +02:00
fix(ui): make self-service profile edits report their outcome (#5699)
* fix(ui): make self-service profile edits report their outcome
When a non-admin user saved their own profile (e.g. changing their
password via EnableUserEditing), the data provider followed the user
update with a call to the admin-only PUT /api/user/{id}/library
endpoint, which always failed with 403. The save error handler then
crashed reading error.body.errors on the plain-text response, so the
user got no notification at all - while the profile change had in fact
already been applied. This made password changes look like they were
silently ignored, and follow-up attempts failed with 'password does not
match' since the current password had already changed. Present since
the multi-library support introduced in v0.58.0 (#4181).
Only call the user-library association endpoint when the logged-in user
is an admin (the server manages assignments for self-edits), and make
the save error handler tolerate error bodies without field errors,
notifying a generic error instead of crashing.
* fix(ui): tolerate nullish rejection values in user save handler
Address review feedback: use optional chaining on the error itself in
the UserEdit save handler, so a nullish rejection value also results in
the generic error notification instead of a TypeError.
This commit is contained in:
parent
b405252f51
commit
e80a7937e8
4 changed files with 167 additions and 10 deletions
90
ui/src/dataProvider/wrapperDataProvider.test.js
Normal file
90
ui/src/dataProvider/wrapperDataProvider.test.js
Normal file
|
|
@ -0,0 +1,90 @@
|
|||
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
||||
import wrapperDataProvider from './wrapperDataProvider'
|
||||
|
||||
const { mockProvider, mockHttpClient } = vi.hoisted(() => ({
|
||||
mockProvider: {
|
||||
update: vi.fn(),
|
||||
create: vi.fn(),
|
||||
getOne: vi.fn(),
|
||||
},
|
||||
mockHttpClient: vi.fn(),
|
||||
}))
|
||||
|
||||
vi.mock('ra-data-json-server', () => ({ default: () => mockProvider }))
|
||||
vi.mock('./httpClient', () => ({ default: mockHttpClient }))
|
||||
|
||||
describe('wrapperDataProvider', () => {
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks()
|
||||
localStorage.clear()
|
||||
mockProvider.update.mockResolvedValue({ data: { id: 'u1' } })
|
||||
mockProvider.create.mockResolvedValue({ data: { id: 'u1' } })
|
||||
mockHttpClient.mockResolvedValue({ json: [] })
|
||||
})
|
||||
|
||||
describe('update user', () => {
|
||||
it('sets library associations when an admin edits a non-admin user', async () => {
|
||||
localStorage.setItem('role', 'admin')
|
||||
|
||||
await wrapperDataProvider.update('user', {
|
||||
id: 'u1',
|
||||
data: { name: 'Sam', isAdmin: false, libraryIds: [1] },
|
||||
})
|
||||
|
||||
expect(mockProvider.update).toHaveBeenCalledWith(
|
||||
'user',
|
||||
expect.objectContaining({ id: 'u1' }),
|
||||
)
|
||||
expect(mockHttpClient).toHaveBeenCalledWith('/api/user/u1/library', {
|
||||
method: 'PUT',
|
||||
body: JSON.stringify({ libraryIds: [1] }),
|
||||
})
|
||||
})
|
||||
|
||||
it('does not call the admin-only library endpoint when a non-admin edits their own profile', async () => {
|
||||
localStorage.setItem('role', 'regular')
|
||||
|
||||
await wrapperDataProvider.update('user', {
|
||||
id: 'u1',
|
||||
data: {
|
||||
name: 'Sam',
|
||||
isAdmin: false,
|
||||
libraryIds: [1],
|
||||
currentPassword: 'old',
|
||||
password: 'new',
|
||||
},
|
||||
})
|
||||
|
||||
expect(mockProvider.update).toHaveBeenCalled()
|
||||
expect(mockHttpClient).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('does not set library associations when the edited user is an admin', async () => {
|
||||
localStorage.setItem('role', 'admin')
|
||||
|
||||
await wrapperDataProvider.update('user', {
|
||||
id: 'u1',
|
||||
data: { name: 'Sam', isAdmin: true, libraryIds: [1] },
|
||||
})
|
||||
|
||||
expect(mockProvider.update).toHaveBeenCalled()
|
||||
expect(mockHttpClient).not.toHaveBeenCalled()
|
||||
})
|
||||
|
||||
it('strips libraryIds from the user update payload', async () => {
|
||||
localStorage.setItem('role', 'admin')
|
||||
|
||||
await wrapperDataProvider.update('user', {
|
||||
id: 'u1',
|
||||
data: { name: 'Sam', isAdmin: false, libraryIds: [1] },
|
||||
})
|
||||
|
||||
expect(mockProvider.update).toHaveBeenCalledWith(
|
||||
'user',
|
||||
expect.objectContaining({
|
||||
data: { name: 'Sam', isAdmin: false },
|
||||
}),
|
||||
)
|
||||
})
|
||||
})
|
||||
})
|
||||
Loading…
Add table
Add a link
Reference in a new issue