{"record":{"id":"6866b21313c11d0c","repo":"Tencent/WeKnora","slug":"cannot-revoke-your-own-system-admin-privileges","errorCode":null,"errorMessage":"cannot revoke your own system admin privileges","messagePattern":"cannot revoke your own system admin privileges","errorType":"error_code","errorClass":null,"httpStatus":403,"severity":"error","filePath":"internal/application/repository/user.go","lineNumber":17,"sourceCode":"package repository\n\nimport (\n\t\"context\"\n\t\"errors\"\n\n\t\"github.com/Tencent/WeKnora/internal/types\"\n\t\"github.com/Tencent/WeKnora/internal/types/interfaces\"\n\t\"gorm.io/gorm\"\n\t\"gorm.io/gorm/clause\"\n)\n\nvar (\n\tErrUserNotFound       = errors.New(\"user not found\")\n\tErrUserAlreadyExists  = errors.New(\"user already exists\")\n\tErrTokenNotFound      = errors.New(\"token not found\")\n\tErrCannotRevokeSelf   = errors.New(\"cannot revoke your own system admin privileges\")\n\tErrLastSystemAdmin    = errors.New(\"cannot revoke the last remaining system administrator\")\n\tErrUserNotSystemAdmin = errors.New(\"user is not a system administrator\")\n)\n\n// userRepository implements user repository interface\ntype userRepository struct {\n\tdb *gorm.DB\n}\n\n// NewUserRepository creates a new user repository\nfunc NewUserRepository(db *gorm.DB) interfaces.UserRepository {\n\treturn &userRepository{db: db}\n}\n\n// CreateUser creates a user\nfunc (r *userRepository) CreateUser(ctx context.Context, user *types.User) error {\n\t// users.tenant_id is nullable in both PostgreSQL and SQLite. GORM would\n\t// otherwise serialise the uint64 zero value as 0, which violates the","sourceCodeStart":1,"sourceCodeEnd":35,"githubUrl":"https://github.com/Tencent/WeKnora/blob/988cbb03305e055d8ebb7d46d9ac6cc0803cd074/internal/application/repository/user.go#L1-L35","documentation":"Sentinel ErrCannotRevokeSelf returned by RevokeSystemAdmin before any DB access when userID equals actorID — an administrator may not revoke their own system-admin privileges. A pure policy guard; the handler maps it to 400.","triggerScenarios":"Thrown at internal/application/repository/user.go:17 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Have a different system admin perform the revocation","Choose another target user id; self-revocation is intentionally blocked"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"988cbb03305e055d8ebb7d46d9ac6cc0803cd074","analyzedAt":"2026-09-02T14:41:08.344Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-08T10:18:20.063Z"}