Skip to content

Prevent assigning Super Administrator as the registration default role - #10357

Open
ruibaby wants to merge 1 commit into
halo-dev:mainfrom
ruibaby:fix/prevent-super-admin-default-role
Open

ruibaby wants to merge 1 commit into
halo-dev:mainfrom
ruibaby:fix/prevent-super-admin-default-role

Conversation

@ruibaby

@ruibaby ruibaby commented Oct 2, 2026

Copy link
Copy Markdown
Member

What type of PR is this?

  • Feature
  • Bug fix
  • Improvement
  • Cleanup
  • Documentation

What this PR does / why we need it:

The registration default-role selector currently allows selecting Super Administrator, which can give newly created users unrestricted permissions.

Add an optional excludedNames list to roleSelect and exclude super-role from the registration default-role options. Reject this role before user creation through password registration, OAuth2 registration, and the Console user creation endpoint, including when it is already present in persisted settings.

Reproduction covered by regression tests: configure user.defaultRole as super-role and invoke these creation paths. Before the fix, they accept the role; after the fix, they return the existing default-role configuration error before creating a user.

Which issue(s) this PR fixes:

None.

Special notes for your reviewer:

Developed with Codex assistance.

Validation passed:

  • 113 focused backend tests covering UserServiceImpl, OAuth2RegistrationService, and UserEndpoint.
  • 5 roleSelect tests covering omitted, empty, single-role, and multiple-role exclusions.
  • Frontend application type checking and targeted ESLint.
  • Java Spotless and frontend formatting checks.
  • git diff --check.

Browser validation and the full test suite were not run.

Does this PR introduce a user-facing change?

action required: 注册默认角色不再支持选择超级管理员。若此前已将默认角色设为超级管理员,请改选其他角色,否则注册和使用默认角色创建用户将被阻止。

@sonarqubecloud

sonarqubecloud Bot commented Oct 2, 2026

Copy link
Copy Markdown

@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 67.30%. Comparing base (42c374d) to head (a6c9777).
⚠️ Report is 812 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main   #10357      +/-   ##
============================================
+ Coverage     59.55%   67.30%   +7.74%     
- Complexity     3812     5437    +1625     
============================================
  Files           677      769      +92     
  Lines         23248    27336    +4088     
  Branches       1500     1918     +418     
============================================
+ Hits          13846    18399    +4553     
+ Misses         8764     8021     -743     
- Partials        638      916     +278     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant