fix: user created in the same second as the first admin takes over its protection (#32157)

Account creation times are stored in whole seconds. On Postgres, a user created in the same second as the first admin, which is normal when a script sets up an instance, could be picked as the primary admin. Other admins could then demote or delete the real first admin, nobody could edit, lock or delete that user, and pending users were shown that user as the admin contact. An admin account now wins a same-second tie against a regular one.
This commit is contained in:
Classic298 2026-10-10 18:01:41 +02:00 • committed by GitHub
parent e056b29685
commit 7f3749ed6b
No known key found for this signature in database
GPG key ID: B5690EEEBB952194

View file

@ -709,7 +709,9 @@ class UsersTable:
async def get_first_user(self, db: AsyncSession | None = None) -> UserModel | None:
"""Return the earliest-created user (bootstrap admin detection)."""
async with get_async_db_context(db) as session:
stmt = select(User).order_by(User.created_at).limit(1)
# created_at has 1s resolution; admin wins ties
admin_first = case((User.role == 'admin', 0), else_=1)
stmt = select(User).order_by(User.created_at, admin_first, User.id).limit(1)
row = (await session.execute(stmt)).scalars().first()
return UserModel.model_validate(row) if row else None