Files
plezy/lib/models/seerr/seerr_user.dart
T
edde746andClaude Fable 5.1 ce03857588 fix(seerr): take permissions from /auth/me, not the partial login body
A local Seerr account with request rights could sign in to Plezy but never
saw the Request action. POST /auth/local loads only the columns it needs to
check the password, so the entity it returns carries the class default
permissions of 0 (and the email as display name); the session stored that
snapshot and the detail screen gated Request on it.

Sign-in now ignores the login body and reads the user back through
GET /auth/me with the fresh cookie, for every method. SeerrUser.permissions
is required, so a user without a mask fails sign-in instead of persisting 0.

Two related gaps kept an affected session broken until a manual reconnect:

- Seerr answers an expired session with 403, never 401, so the silent
  re-auth never ran. A 403 now re-auths once GET /auth/me confirms the
  cookie is dead; a 403 from a live session stays a permission denial so a
  Quick Connect session is not unlinked over one.
- Nothing refreshed a stored session's permissions. The account provider
  now re-reads the user on bind, so sessions persisted with 0 by earlier
  builds, and admin-side permission changes, reach the Request action on
  the next launch.

close #2213

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-09-02 11:31:47 +02:00

23 lines
812 B
Dart

import 'package:json_annotation/json_annotation.dart';
part 'seerr_user.g.dart';
/// The signed-in Seerr user, as `GET /auth/me` reports it.
///
/// Not the shape of the `/auth/*` login bodies. Those return whatever `User`
/// instance the handler happened to build, and `POST /auth/local` loads only
/// the columns it needs to check the password, so its body carries the
/// entity's `permissions` default of 0 rather than the stored mask (#2213).
@JsonSerializable(createToJson: false)
class SeerrUser {
final int id;
final String? displayName;
/// Seerr permission bitmask — see `SeerrPermission`.
final int permissions;
const SeerrUser({required this.id, this.displayName, required this.permissions});
factory SeerrUser.fromJson(Map<String, dynamic> json) => _$SeerrUserFromJson(json);
}