mirror of
https://github.com/navidrome/navidrome.git
synced 2026-10-08 10:27:08 +02:00
* fix(ui): make self-service profile edits report their outcome
When a non-admin user saved their own profile (e.g. changing their
password via EnableUserEditing), the data provider followed the user
update with a call to the admin-only PUT /api/user/{id}/library
endpoint, which always failed with 403. The save error handler then
crashed reading error.body.errors on the plain-text response, so the
user got no notification at all - while the profile change had in fact
already been applied. This made password changes look like they were
silently ignored, and follow-up attempts failed with 'password does not
match' since the current password had already changed. Present since
the multi-library support introduced in v0.58.0 (#4181).
Only call the user-library association endpoint when the logged-in user
is an admin (the server manages assignments for self-edits), and make
the save error handler tolerate error bodies without field errors,
notifying a generic error instead of crashing.
* fix(ui): tolerate nullish rejection values in user save handler
Address review feedback: use optional chaining on the error itself in
the UserEdit save handler, so a nullish rejection value also results in
the generic error notification instead of a TypeError.
90 lines
2.6 KiB
JavaScript
90 lines
2.6 KiB
JavaScript
import { describe, it, expect, vi, beforeEach } from 'vitest'
|
|
import wrapperDataProvider from './wrapperDataProvider'
|
|
|
|
const { mockProvider, mockHttpClient } = vi.hoisted(() => ({
|
|
mockProvider: {
|
|
update: vi.fn(),
|
|
create: vi.fn(),
|
|
getOne: vi.fn(),
|
|
},
|
|
mockHttpClient: vi.fn(),
|
|
}))
|
|
|
|
vi.mock('ra-data-json-server', () => ({ default: () => mockProvider }))
|
|
vi.mock('./httpClient', () => ({ default: mockHttpClient }))
|
|
|
|
describe('wrapperDataProvider', () => {
|
|
beforeEach(() => {
|
|
vi.clearAllMocks()
|
|
localStorage.clear()
|
|
mockProvider.update.mockResolvedValue({ data: { id: 'u1' } })
|
|
mockProvider.create.mockResolvedValue({ data: { id: 'u1' } })
|
|
mockHttpClient.mockResolvedValue({ json: [] })
|
|
})
|
|
|
|
describe('update user', () => {
|
|
it('sets library associations when an admin edits a non-admin user', async () => {
|
|
localStorage.setItem('role', 'admin')
|
|
|
|
await wrapperDataProvider.update('user', {
|
|
id: 'u1',
|
|
data: { name: 'Sam', isAdmin: false, libraryIds: [1] },
|
|
})
|
|
|
|
expect(mockProvider.update).toHaveBeenCalledWith(
|
|
'user',
|
|
expect.objectContaining({ id: 'u1' }),
|
|
)
|
|
expect(mockHttpClient).toHaveBeenCalledWith('/api/user/u1/library', {
|
|
method: 'PUT',
|
|
body: JSON.stringify({ libraryIds: [1] }),
|
|
})
|
|
})
|
|
|
|
it('does not call the admin-only library endpoint when a non-admin edits their own profile', async () => {
|
|
localStorage.setItem('role', 'regular')
|
|
|
|
await wrapperDataProvider.update('user', {
|
|
id: 'u1',
|
|
data: {
|
|
name: 'Sam',
|
|
isAdmin: false,
|
|
libraryIds: [1],
|
|
currentPassword: 'old',
|
|
password: 'new',
|
|
},
|
|
})
|
|
|
|
expect(mockProvider.update).toHaveBeenCalled()
|
|
expect(mockHttpClient).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('does not set library associations when the edited user is an admin', async () => {
|
|
localStorage.setItem('role', 'admin')
|
|
|
|
await wrapperDataProvider.update('user', {
|
|
id: 'u1',
|
|
data: { name: 'Sam', isAdmin: true, libraryIds: [1] },
|
|
})
|
|
|
|
expect(mockProvider.update).toHaveBeenCalled()
|
|
expect(mockHttpClient).not.toHaveBeenCalled()
|
|
})
|
|
|
|
it('strips libraryIds from the user update payload', async () => {
|
|
localStorage.setItem('role', 'admin')
|
|
|
|
await wrapperDataProvider.update('user', {
|
|
id: 'u1',
|
|
data: { name: 'Sam', isAdmin: false, libraryIds: [1] },
|
|
})
|
|
|
|
expect(mockProvider.update).toHaveBeenCalledWith(
|
|
'user',
|
|
expect.objectContaining({
|
|
data: { name: 'Sam', isAdmin: false },
|
|
}),
|
|
)
|
|
})
|
|
})
|
|
})
|