Skip to content

Feature/admin user management - #1

Merged
Muimi272 merged 2 commits into
mainfrom
feature/admin-user-management
Sep 2, 2026
Merged

Muimi272 merged 2 commits into
mainfrom
feature/admin-user-management

Conversation

@Muimi272

@Muimi272 Muimi272 commented Sep 2, 2026

Copy link
Copy Markdown
Collaborator

No description provided.

Copilot AI lite review requested due to automatic review settings September 2, 2026 10:23

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

The new endpoints/service include API/operational issues (PATCH semantics vs required full payload, unconditional tokenVersion bump causing forced logout, and inefficient/racy username uniqueness check) that should be addressed before merge.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds admin-side user management capabilities (create/update/delete) to the existing admin user module, including password hashing and additional validation/guardrails.

Changes:

  • Added admin endpoints to create users, update user details, and delete users.
  • Implemented corresponding service-layer logic with password encoding, uniqueness checks, and audit logging.
  • Added DTOs for create/update requests and expanded unit tests for the new behaviors.
File summaries
File Description
src/main/java/club/muimi/backend/controller/admin/AdminUserController.java Exposes new admin REST endpoints for create/update/delete user operations.
src/main/java/club/muimi/backend/service/admin/AdminUserService.java Implements create/update/delete logic, password hashing, uniqueness validation, and audit logs.
src/main/java/club/muimi/backend/repository/UserRepository.java Adds findByUsername to support username conflict checks.
src/main/java/club/muimi/backend/dto/admin/CreateUserRequest.java Introduces request DTO + validation for creating users.
src/main/java/club/muimi/backend/dto/admin/UpdateUserRequest.java Introduces request DTO + validation for updating user info (including optional password change).
src/test/java/club/muimi/backend/service/admin/AdminUserServiceTest.java Adds unit tests covering create/update/delete constraints and password encoding behavior.
Review details
  • Files reviewed: 6/6 changed files
  • Comments generated: 3
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment on lines +59 to +65
@RequestMapping(value = "/{userId}", method = {RequestMethod.PUT, RequestMethod.PATCH})
public ApiResponse<AdminUserDetailVo> updateUser(
@PathVariable Long userId,
@Valid @RequestBody UpdateUserRequest request
) {
return ApiResponse.success(adminUserService.updateUser(userId, request), "用户信息更新成功");
}
Comment on lines +232 to +245
User user = getUserOrThrow(userId);
ensureUsernameAndEmailAvailable(request.username(), request.email(), userId);
if (request.password() != null && !request.password().isBlank()) {
validatePasswordPair(request.password(), request.confirmPassword());
validatePasswordStrength(request.password());
user.setPasswordHash(requirePasswordEncoder().encode(request.password()));
}
user.setUsername(request.username().trim());
user.setEmail(request.email().trim());
user.setRole(request.role());
user.setStatus(request.status());
user.setEmailVerified(Boolean.TRUE.equals(request.emailVerified()));
user.setTokenVersion(user.getTokenVersion() + 1);
try {
Comment on lines +291 to +303
private void ensureUsernameAndEmailAvailable(String username, String email, Long excludedUserId) {
userRepository.findByEmail(email.trim()).ifPresent(existing -> {
if (!Objects.equals(existing.getId(), excludedUserId)) {
throw new ConflictException("邮箱已被注册");
}
});
if (userRepository.existsByUsername(username.trim())) {
User existing = userRepository.findByUsername(username.trim()).orElse(null);
if (existing == null || !Objects.equals(existing.getId(), excludedUserId)) {
throw new ConflictException("用户名已存在");
}
}
}
@Muimi272
Muimi272 merged commit 4225d90 into main Sep 2, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants