From 63f9df0afb6026dfb8c7ebab1bd0ce3c69ee734e Mon Sep 17 00:00:00 2001 From: Schalli Date: Mon, 14 Sep 2026 10:37:40 +0200 Subject: [PATCH] =?UTF-8?q?docs(quick-260914-ebg):=20Kopfkommentar=20admin?= =?UTF-8?q?ResetPassword=20=E2=80=94=20Schwesterwege=20PATCH/DELETE=20/use?= =?UTF-8?q?rs/:id=20geschlossen=20(WINDOWS=20#29)?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit - auth.service.ts: letzter Satz des Kopfkommentars ueber adminResetPassword nennt T-FH9-05 nicht mehr als offen, sondern verweist auf den seit 260914-ebg (WINDOWS #29) identischen Riegel in UserController.update()/remove() - Falsifizierung: Rueckbau des Task-1-Commits (git apply -R) macht Test 9 und Test 13 rot (Tests 2 failed | 14 passed (16)), danach byte-identisch wiederhergestellt (git checkout --, git status --porcelain leer) - Rule 1 Nebenfund: acht neue Tests in user.controller.spec.ts trugen sechs ueberfluessige `as any`-Umschreibungen (UpdateUserDto ist vollstaendig optional, siehe planning_measurements), die die Biome-Warnungen dieser Datei von 25 auf 31 trieben — entfernt, damit die relative Biome-Schwelle der Baseline (25) wieder eingehalten wird, ohne die Schwelle anzuheben Co-Authored-By: Claude Opus 5 (1M context) Claude-Session: https://claude.ai/code/session_018N9CD3ebPKm1b32bPpBknY --- apps/api/src/auth/auth.service.ts | 5 +++-- apps/api/src/user/user.controller.spec.ts | 12 ++++++------ 2 files changed, 9 insertions(+), 8 deletions(-) diff --git a/apps/api/src/auth/auth.service.ts b/apps/api/src/auth/auth.service.ts index 0b1b508..32795ca 100644 --- a/apps/api/src/auth/auth.service.ts +++ b/apps/api/src/auth/auth.service.ts @@ -404,8 +404,9 @@ export class AuthService { * `BadRequestException` nennt weder Halter noch Mandanten. Der Riegel * unten schliesst zusaetzlich die Rechteausweitung INNERHALB des * Mandanten (T-FH9-04): ein Nicht-SUPER_ADMIN darf das Kennwort eines - * SUPER_ADMIN nicht setzen. Der Schwesterweg `PATCH /users/:id` hat - * dieselbe Luecke nicht geschlossen — offener Ledger-Eintrag T-FH9-05. + * SUPER_ADMIN nicht setzen. Die Schwesterwege `PATCH /users/:id` und + * `DELETE /users/:id` tragen seit 260914-ebg (WINDOWS #29) denselben + * Riegel in `UserController.update()`/`remove()`. */ async adminResetPassword( tenantId: string, diff --git a/apps/api/src/user/user.controller.spec.ts b/apps/api/src/user/user.controller.spec.ts index eeb6151..644d2fe 100644 --- a/apps/api/src/user/user.controller.spec.ts +++ b/apps/api/src/user/user.controller.spec.ts @@ -284,17 +284,17 @@ describe('UserController', () => { userService.findById.mockResolvedValue({ id: 'boss', tenantId: 't1', role: Role.SUPER_ADMIN }); await expect( - controller.update('boss', { password: 'fresh-password' } as any, admin), + controller.update('boss', { password: 'fresh-password' }, admin), ).rejects.toThrow('Cannot modify a SUPER_ADMIN user'); expect(userService.update).not.toHaveBeenCalled(); await expect( - controller.update('boss', { isActive: false } as any, admin), + controller.update('boss', { isActive: false }, admin), ).rejects.toThrow('Cannot modify a SUPER_ADMIN user'); expect(userService.update).not.toHaveBeenCalled(); await expect( - controller.update('boss', { role: Role.USER } as any, admin), + controller.update('boss', { role: Role.USER }, admin), ).rejects.toThrow('Cannot modify a SUPER_ADMIN user'); expect(userService.update).not.toHaveBeenCalled(); }); @@ -313,7 +313,7 @@ describe('UserController', () => { passwordHash: 'h', }); - const result = await controller.update('boss', { password: 'fresh-password' } as any, superAdmin); + const result = await controller.update('boss', { password: 'fresh-password' }, superAdmin); expect(userService.update).toHaveBeenCalledWith( 't1', @@ -328,7 +328,7 @@ describe('UserController', () => { userService.findById.mockResolvedValue({ id: 'u1', tenantId: 't1', role: Role.USER }); userService.update.mockResolvedValue({ id: 'u1', tenantId: 't1', role: Role.USER }); - await controller.update('u1', { displayName: 'Neu' } as any, admin); + await controller.update('u1', { displayName: 'Neu' }, admin); expect(userService.update).toHaveBeenCalledWith( 't1', @@ -342,7 +342,7 @@ describe('UserController', () => { userService.findById.mockResolvedValue({ id: 'boss2', tenantId: 't2', role: Role.SUPER_ADMIN }); await expect( - controller.update('boss2', { displayName: 'Neu' } as any, admin), + controller.update('boss2', { displayName: 'Neu' }, admin), ).rejects.toThrow('Cannot modify users from other tenants'); expect(userService.update).not.toHaveBeenCalled(); });