fix(auth): always serialize User.Role so admin (role 0) is not omitted

The Role field used json:"role,omitempty". Admin is RoleAdmin = 0, so an
admin profile serialized without a `role` key. The admin-frontend gates the
admin menu (user management, settings) on `role === 0`, and its normalizeRole
helper defaults a missing role to non-admin, so admins lost the admin menu.

Drop omitempty so role 0 is always sent. Add a regression test.
This commit is contained in:
naiba
2026-05-31 12:05:11 +00:00
parent 34ab8a31bc
commit f7f8264ec0
2 changed files with 33 additions and 1 deletions
+1 -1
View File
@@ -25,7 +25,7 @@ type User struct {
Common
Username string `json:"username,omitempty" gorm:"uniqueIndex"`
Password string `json:"password,omitempty" gorm:"type:char(72)"`
Role Role `json:"role,omitempty"`
Role Role `json:"role"`
AgentSecret string `json:"agent_secret,omitempty" gorm:"type:char(32)"`
RejectPassword bool `json:"reject_password,omitempty"`
TokenVersion uint64 `json:"-" gorm:"not null;default:0"`
+32
View File
@@ -0,0 +1,32 @@
package model
import (
"encoding/json"
"testing"
)
// RoleAdmin is the zero value (0). The Role field must NOT use json:",omitempty"
// or an admin profile would serialize without a `role` key, and the frontend
// (which gates the admin menu on `role === 0`) would treat the admin as a
// regular user. Guard against a regression that drops the field for admins.
func TestUserRoleSerializedForAdmin(t *testing.T) {
u := User{Common: Common{ID: 1}, Username: "admin", Role: RoleAdmin}
b, err := json.Marshal(u)
if err != nil {
t.Fatalf("marshal user: %v", err)
}
var decoded map[string]json.RawMessage
if err := json.Unmarshal(b, &decoded); err != nil {
t.Fatalf("unmarshal user: %v", err)
}
raw, ok := decoded["role"]
if !ok {
t.Fatalf("admin user JSON must include the `role` field, got: %s", b)
}
if string(raw) != "0" {
t.Fatalf("admin user `role` must serialize as 0, got: %s", raw)
}
}