Fix account-editing bugs from real-world feedback, add editable group membership
- Edit form's Mobile Phone field was effectively required (stray validate
attribute) -- removed.
- Service account profiles always showed the literal filler name "Service
Account" -- hidden now, since it's not meaningful. Required computing
isServiceAccount in User.get(), not just listDetail().
- Fresh service accounts could look uncategorized (missing from the
Service Accounts tab, wrong isServiceAccount) for up to 5 minutes after
creation, due to a cache-staleness race in the create route -- the user
gets cached via User.get() before the route marks it as a service
account. Cleared and re-fetched after marking.
- memberOf came back as a bare string instead of a one-element array for
users in exactly one group, causing client-side permission checks to
iterate character-by-character and incorrectly deny access -- normalized
alongside the existing manager normalization.
- Added editable group membership on the profile page ("My groups"),
admin-only, using the existing per-group member endpoints.
Bumps to v1.1.8.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01KDEx8ghuZR61pqPXc6da9C
This commit is contained in:
@@ -25,7 +25,7 @@ router.post('/', async function(req, res, next){
|
||||
req.body.created_by = req.user.uid
|
||||
req.body.manager = [req.user.dn];
|
||||
|
||||
const user = await User.add(req.body);
|
||||
let user = await User.add(req.body);
|
||||
const verif = await UserVerification.getOrCreate(user.uid);
|
||||
const updates = { password_must_change: true };
|
||||
if (req.body.tosAgree) updates.tos_accepted = true, updates.tos_accepted_at = Date.now();
|
||||
@@ -38,6 +38,12 @@ router.post('/', async function(req, res, next){
|
||||
try {
|
||||
const group = await Group.get('app_sso_service_account');
|
||||
await group.addMember(user);
|
||||
// User.add() already cached `user` (via its own internal
|
||||
// User.get()) before this group membership existed, so the
|
||||
// cached isServiceAccount would be stuck wrong for 5 minutes
|
||||
// (the cache TTL) without this -- re-fetch after clearing.
|
||||
User.clearCache();
|
||||
user = await User.get(user.uid);
|
||||
} catch (error) {
|
||||
console.error(`user.add: failed to mark ${user.uid} as a service account:`, error.message);
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user