fix(auth): revoke sessions on library scope nil changes

This commit is contained in:
zZebrahz
2026-05-30 19:21:25 -07:00
parent 3f55440752
commit af2c54c8f0
2 changed files with 28 additions and 2 deletions
+7 -2
View File
@@ -792,8 +792,13 @@ func updateRequiresSessionRevocation(current *models.User, input models.UpdateUs
if input.Enabled != nil && *input.Enabled != current.Enabled {
return true
}
if input.LibraryIDs != nil && !slices.Equal(*input.LibraryIDs, current.LibraryIDs) {
return true
if input.LibraryIDs != nil {
if (*input.LibraryIDs == nil) != (current.LibraryIDs == nil) {
return true
}
if *input.LibraryIDs != nil && !slices.Equal(*input.LibraryIDs, current.LibraryIDs) {
return true
}
}
if input.Permissions != nil && !slices.Equal(*input.Permissions, current.Permissions) {
return true
+21
View File
@@ -13,6 +13,8 @@ func TestUpdateRequiresSessionRevocation(t *testing.T) {
disabled := false
libraryIDs := []int{1, 2}
sameLibraryIDs := []int{1}
emptyLibraryIDs := []int{}
var allLibraryIDs []int
maxPlaybackQuality := "1080p"
sameMaxPlaybackQuality := "original"
password := "new-password"
@@ -74,6 +76,11 @@ func TestUpdateRequiresSessionRevocation(t *testing.T) {
in: models.UpdateUserInput{LibraryIDs: &sameLibraryIDs},
want: false,
},
{
name: "library ids nil differs from restricted",
in: models.UpdateUserInput{LibraryIDs: &allLibraryIDs},
want: true,
},
{
name: "max playback quality",
in: models.UpdateUserInput{MaxPlaybackQuality: &maxPlaybackQuality},
@@ -108,4 +115,18 @@ func TestUpdateRequiresSessionRevocation(t *testing.T) {
}
})
}
unrestrictedCurrent := *current
unrestrictedCurrent.LibraryIDs = nil
t.Run("library ids empty differs from nil", func(t *testing.T) {
if got := updateRequiresSessionRevocation(&unrestrictedCurrent, models.UpdateUserInput{LibraryIDs: &emptyLibraryIDs}); !got {
t.Fatalf("updateRequiresSessionRevocation() = %v, want true", got)
}
})
t.Run("library ids nil unchanged", func(t *testing.T) {
if got := updateRequiresSessionRevocation(&unrestrictedCurrent, models.UpdateUserInput{LibraryIDs: &allLibraryIDs}); got {
t.Fatalf("updateRequiresSessionRevocation() = %v, want false", got)
}
})
}