fix(user-flow): close offline-queue, export, session, ban & realtime gaps
Comprehensive user-flow review across guest/host/admin roles, then fixes with
e2e regression guards. Highlights:
- Offline upload queue auto-resumes on reconnect: network errors keep items
pending (not error), 4xx are terminal (no infinite retry), quota exhaustion
returns a distinct 413; queue cap + dedup.
- Export lifecycle: release atomically locks uploads; reopen invalidates and
re-release regenerates the keepsake; workers claim their job atomically so a
reopen->re-release can't corrupt the ZIP; startup re-spawns interrupted
exports.
- Sessions slide on activity (no 30-day cliff); JWT expiry deferred to the
revocable session row; sign-out-everywhere + revoke-on-PIN-reset.
- Ban always hides content (v_feed / find_visible_media / export filter
is_banned) but stays a read-only ban per USER_JOURNEYS §10 — sessions are
not revoked, read access + keepsake download preserved.
- Realtime: server-clock SSE delta cursor; event-closed/opened drive the UI
live; feed_delta rate-limited; like returns {liked, like_count} to fix
multi-device drift; lightbox live comments; diashow delta backfill.
- Forgotten-PIN in-app request flow; simultaneous same-name join returns 409;
quota increment is transactional; operator floor.
Adds e2e/specs/10-flow-review/ (offline resume, export integrity, deterministic
anti-race guard) and updates existing specs for the new contracts.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -9,7 +9,7 @@
|
||||
import { SlideQueue } from '$lib/diashow/queue';
|
||||
import { transitions, findTransition } from '$lib/diashow/transitions';
|
||||
import { acquireWakeLock, releaseWakeLock } from '$lib/diashow/wakelock';
|
||||
import type { FeedUpload, FeedResponse } from '$lib/types';
|
||||
import type { FeedUpload, FeedResponse, DeltaResponse } from '$lib/types';
|
||||
|
||||
const DWELL_OPTIONS = [3000, 6000, 10000];
|
||||
|
||||
@@ -100,6 +100,28 @@
|
||||
}
|
||||
}
|
||||
|
||||
// After an all-night projector reconnects (SSE drop, network blip), the live events
|
||||
// it missed are gone. The SSE client fans out a `feed-delta` of everything since the
|
||||
// last seen timestamp — merge it so the show backfills the gap instead of silently
|
||||
// stalling on a stale set.
|
||||
function handleFeedDelta(data: string) {
|
||||
try {
|
||||
const delta = JSON.parse(data) as DeltaResponse;
|
||||
for (const id of delta.deleted_ids) {
|
||||
const result = queue.remove(id, current?.id ?? null);
|
||||
if (result.wasCurrent) advance();
|
||||
}
|
||||
for (const upload of delta.uploads) {
|
||||
// Only enqueue displayable (processed) items; pushLive dedupes by id, so a
|
||||
// later `upload-processed` still refines anything that arrives raw.
|
||||
if (upload.preview_url || upload.thumbnail_url) queue.pushLive(upload);
|
||||
}
|
||||
if (!current) advance();
|
||||
} catch {
|
||||
// ignore — non-fatal; the next live event keeps the show moving
|
||||
}
|
||||
}
|
||||
|
||||
function handleUserHidden(data: string) {
|
||||
try {
|
||||
const payload = JSON.parse(data) as { user_id: string };
|
||||
@@ -164,6 +186,7 @@
|
||||
unsubs.push(onSseEvent('upload-processed', handleUploadProcessed));
|
||||
unsubs.push(onSseEvent('upload-deleted', handleUploadDeleted));
|
||||
unsubs.push(onSseEvent('user-hidden', handleUserHidden));
|
||||
unsubs.push(onSseEvent('feed-delta', handleFeedDelta));
|
||||
void loadInitial();
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user