Skip to content

Group user info still available in "Account info" even if disabled in plugin config #12789 - #12796

Merged
allyoucanmap merged 3 commits into
geosolutions-it:masterfrom
rowheat02:group-user-info
Aug 17, 2026
Merged

allyoucanmap merged 3 commits into
geosolutions-it:masterfrom
rowheat02:group-user-info

Conversation

@rowheat02

Copy link
Copy Markdown
Contributor

Description

The "hideGroupUserInfo" option configured through:

{
  "name": "Login",
  "cfg": {
    "toolsCfg": [
      {
        "hideGroupUserInfo": true
      }
    ]
  }
}

was no longer propagated to the User Details modal. The regression was introduced on PR #10963.
This PR fixes the propagation of login toolsCgf to UserModal.
Now, if hideGroupUserInfo is true, then Groups can not be seen on the User Info modal.
image

Please check if the PR fulfills these requirements

What kind of change does this PR introduce? (check one with "x", remove the others)

  • Bugfix

Issue

What is the current behavior?

#12789

What is the new behavior?

when configured from toolsCfg of Login plugin, groups information of user can be hidden

Breaking change

Does this PR introduce a breaking change? (check one with "x", remove the other)

  • Yes, and I documented them in migration notes
  • No

Other useful information

Comment thread web/client/plugins/Login.jsx Outdated
showPasswordChange={showPasswordChange}
showAccountInfo={showAccountInfo}
isUsingLDAP={isUsingLDAP}
hideGroupUserInfo={toolsCfg?.[0]?.hideGroupUserInfo}

@allyoucanmap allyoucanmap Aug 14, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One clarification on how it was working before. Initially OmniBar and SidebarMenu were listing the component of the Login as tools into an array [UserDetails, PasswordReset, Login]:

OmniBar:     { ..., tools: [UserDetails, PasswordReset, Login], ... }
SidebarMenu: { ..., tools: [UserDetails, PasswordReset, Login], ... }

Then the toolsCfg was injected inside the plugin container, see:

The possibility to use toolsCfg was mentioned in the migration guide, but not documented on the Login.jsx plugin but only in the internal UserDetailsModal.

Now in the new Login.jsx structure toolsCfg?.[0]?.hideGroupUserInfo may act as a fallback for retro-compatibility but it should not be the new official property (note has mentioned in the migration guide this was working by array index so a different plugin configuration could break this config).

Proposed changes:

   className,
    toolsCfg,
    hideGroupUserInfo: hideGroupUserInfoProp
}, context) {
    const hideGroupUserInfo = !!(hideGroupUserInfoProp || toolsCfg?.[0]?.hideGroupUserInfo);
    const { loadedPlugins } = context;
                showPasswordChange={showPasswordChange}
                showAccountInfo={showAccountInfo}
                isUsingLDAP={isUsingLDAP}
                hideGroupUserInfo={hideGroupUserInfo}
  • add a new cfg.hideGroupUserInfo property and use toolsCfg?.[0]?.hideGroupUserInfo only as a fallback
  • document this new hideGroupUserInfo in the Login.jsx plugin, this should be visible in the JSDoc so future changes will keep this into account. Only the new hideGroupUserInfo should be officially documented while toolsCfg will be used internally as fallback for existing configurations.
  • add a new section in the migration guide where we should document that the new property hideGroupUserInfo also informing that will replace the index based configuration of toolsCfg (we cannot predict if some project changed the structure of the Login.jsx plugin)
  • review documentation in the component web/client/components/security/modals/UserDetailsModal.jsx and remove reference from the toolsCfg or plugins (this is an internal component and we should just inform about what the hideGroupUserInfo is doing)

@rowheat02

Copy link
Copy Markdown
Contributor Author

@allyoucanmap fixed as requested

  • Added cfg.hideGroupUserInfo for the Login plugin to decide whether to hide the user's group.
  • toolsCfg[0].hideGroupUserInfo is still supported for backward compatibility
  • Updated docs and migrations

@rowheat02
rowheat02 requested a review from allyoucanmap August 17, 2026 09:50
Comment on lines +507 to +522
### Login `hideGroupUserInfo` configuration

The `hideGroupUserInfo` option is now a direct configuration property of the `Login` plugin. Update all `Login` plugin configurations in `localConfig.json` as follows:

```diff
{
"name": "Login",
"cfg": {
- "toolsCfg": [{"hideGroupUserInfo": true}]
+ "hideGroupUserInfo": true
}
}
```

The previous `toolsCfg` configuration is still supported as a fallback for backward compatibility, but the direct `hideGroupUserInfo` property should be used for all new configurations.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

is this in the correct migration section?

I'm seeing this under ## Migration from 2026.01.01 to 2026.01.02 but the milestone for this PR is 2026.02.01.
Could you verify, please?

@rowheat02
rowheat02 requested a review from allyoucanmap August 17, 2026 10:51
@rowheat02

Copy link
Copy Markdown
Contributor Author

@allyoucanmap now the migration guideline is in the correct place for this.

@allyoucanmap
allyoucanmap merged commit 6923927 into geosolutions-it:master Aug 17, 2026
15 checks passed
@allyoucanmap

Copy link
Copy Markdown
Contributor

@ElenaGallo please test this fix on dev, thanks

@offtherailz

Copy link
Copy Markdown
Member

Request failed due to following response errors:

  • Pull request Pull request is a draft

rowheat02 added a commit that referenced this pull request Aug 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Group user info still available in "Account info" even if disabled in plugin config

4 participants