Tencent/WeKnora · error

cannot revoke your own system admin privileges

Error message

cannot revoke your own system admin privileges

What it means

Sentinel ErrCannotRevokeSelf returned by RevokeSystemAdmin before any DB access when userID equals actorID — an administrator may not revoke their own system-admin privileges. A pure policy guard; the handler maps it to 400.

Source

Thrown at internal/application/repository/user.go:17

package repository

import (
	"context"
	"errors"

	"github.com/Tencent/WeKnora/internal/types"
	"github.com/Tencent/WeKnora/internal/types/interfaces"
	"gorm.io/gorm"
	"gorm.io/gorm/clause"
)

var (
	ErrUserNotFound       = errors.New("user not found")
	ErrUserAlreadyExists  = errors.New("user already exists")
	ErrTokenNotFound      = errors.New("token not found")
	ErrCannotRevokeSelf   = errors.New("cannot revoke your own system admin privileges")
	ErrLastSystemAdmin    = errors.New("cannot revoke the last remaining system administrator")
	ErrUserNotSystemAdmin = errors.New("user is not a system administrator")
)

// userRepository implements user repository interface
type userRepository struct {
	db *gorm.DB
}

// NewUserRepository creates a new user repository
func NewUserRepository(db *gorm.DB) interfaces.UserRepository {
	return &userRepository{db: db}
}

// CreateUser creates a user
func (r *userRepository) CreateUser(ctx context.Context, user *types.User) error {
	// users.tenant_id is nullable in both PostgreSQL and SQLite. GORM would
	// otherwise serialise the uint64 zero value as 0, which violates the

View on GitHub (pinned to 988cbb0330)

Solutions

  1. Have a different system admin perform the revocation
  2. Choose another target user id; self-revocation is intentionally blocked
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at internal/application/repository/user.go:17 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of Tencent/WeKnora@988cbb0330 (2026-09-02). Data as JSON: /api/errors/6866b21313c11d0c. Report an issue: GitHub.