{"record":{"id":"35b330ca52dfcfaf","repo":"Tencent/WeKnora","slug":"cannot-revoke-the-last-remaining-system-administra","errorCode":null,"errorMessage":"cannot revoke the last remaining system administrator","messagePattern":"cannot revoke the last remaining system administrator","errorType":"error_code","errorClass":null,"httpStatus":400,"severity":"error","filePath":"internal/application/repository/user.go","lineNumber":18,"sourceCode":"package repository\n\nimport (\n\t\"context\"\n\t\"errors\"\n\n\t\"github.com/Tencent/WeKnora/internal/types\"\n\t\"github.com/Tencent/WeKnora/internal/types/interfaces\"\n\t\"gorm.io/gorm\"\n\t\"gorm.io/gorm/clause\"\n)\n\nvar (\n\tErrUserNotFound       = errors.New(\"user not found\")\n\tErrUserAlreadyExists  = errors.New(\"user already exists\")\n\tErrTokenNotFound      = errors.New(\"token not found\")\n\tErrCannotRevokeSelf   = errors.New(\"cannot revoke your own system admin privileges\")\n\tErrLastSystemAdmin    = errors.New(\"cannot revoke the last remaining system administrator\")\n\tErrUserNotSystemAdmin = errors.New(\"user is not a system administrator\")\n)\n\n// userRepository implements user repository interface\ntype userRepository struct {\n\tdb *gorm.DB\n}\n\n// NewUserRepository creates a new user repository\nfunc NewUserRepository(db *gorm.DB) interfaces.UserRepository {\n\treturn &userRepository{db: db}\n}\n\n// CreateUser creates a user\nfunc (r *userRepository) CreateUser(ctx context.Context, user *types.User) error {\n\t// users.tenant_id is nullable in both PostgreSQL and SQLite. GORM would\n\t// otherwise serialise the uint64 zero value as 0, which violates the\n\t// PostgreSQL FK and loses the distinction between \"not provisioned yet\"","sourceCodeStart":1,"sourceCodeEnd":36,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/application/repository/user.go#L1-L36","documentation":"Sentinel ErrLastSystemAdmin returned inside the revoke transaction when, after the change, the system-admin count would drop to 1 or below — the platform must keep at least one system administrator. The transaction aborts and the handler maps it to 400.","triggerScenarios":"Thrown at internal/application/repository/user.go:18 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Promote another user to system admin first, then retry the revocation","Keep at least one system admin; refuse the operation otherwise"],"exampleFix":null,"handlingStrategy":"type-guard","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}