Tencent/WeKnora · error
cannot revoke your own system admin privileges
Error message
cannot revoke your own system admin privileges
What it means
Sentinel ErrCannotRevokeSelf returned by RevokeSystemAdmin before any DB access when userID equals actorID — an administrator may not revoke their own system-admin privileges. A pure policy guard; the handler maps it to 400.
Source
Thrown at internal/application/repository/user.go:17
package repository
import (
"context"
"errors"
"github.com/Tencent/WeKnora/internal/types"
"github.com/Tencent/WeKnora/internal/types/interfaces"
"gorm.io/gorm"
"gorm.io/gorm/clause"
)
var (
ErrUserNotFound = errors.New("user not found")
ErrUserAlreadyExists = errors.New("user already exists")
ErrTokenNotFound = errors.New("token not found")
ErrCannotRevokeSelf = errors.New("cannot revoke your own system admin privileges")
ErrLastSystemAdmin = errors.New("cannot revoke the last remaining system administrator")
ErrUserNotSystemAdmin = errors.New("user is not a system administrator")
)
// userRepository implements user repository interface
type userRepository struct {
db *gorm.DB
}
// NewUserRepository creates a new user repository
func NewUserRepository(db *gorm.DB) interfaces.UserRepository {
return &userRepository{db: db}
}
// CreateUser creates a user
func (r *userRepository) CreateUser(ctx context.Context, user *types.User) error {
// users.tenant_id is nullable in both PostgreSQL and SQLite. GORM would
// otherwise serialise the uint64 zero value as 0, which violates theView on GitHub (pinned to 988cbb0330)
Solutions
- Have a different system admin perform the revocation
- Choose another target user id; self-revocation is intentionally blocked
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at internal/application/repository/user.go:17 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of Tencent/WeKnora@988cbb0330 (2026-09-02).
Data as JSON: /api/errors/6866b21313c11d0c.
Report an issue: GitHub.