fix(security): medium/low — event-lock, atomic config, a11y, diashow, hygiene

- social: likes/comments rejected on a closed event (e2e proven).
- admin: patch_config validates-then-writes atomically; char-based length.
- hashtag/comment models: atomic tag writes in edit + comment paths.
- Modal: inert the background (modal-inert action) for screen readers.
- sse.ts: idempotent visibilitychange listener (no duplicate reconnects).
- diashow: videos advance on `ended` (transitions + page wiring).
- docs/hygiene: README clone-case fix; removed stale committed .env.test and
  gitignored it; docker-compose.dev.yml tidy.

Left documented as accepted-risk per plan: PIN-persist-after-logout,
UUID-reachable hidden uploads, DECISION-media-auth.md.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
fabi
2026-07-01 21:25:58 +02:00
parent f08d858281
commit 91ff961850
15 changed files with 188 additions and 90 deletions

View File

@@ -7,9 +7,11 @@
src: string;
isVideo: boolean;
durationMs: number;
/** Fired when a video slide finishes so the parent can advance early. */
onended?: () => void;
}
let { src, isVideo, durationMs }: Props = $props();
let { src, isVideo, durationMs, onended }: Props = $props();
</script>
<div
@@ -23,6 +25,7 @@
autoplay
muted
playsinline
{onended}
class="h-full w-full object-contain"
></video>
{:else}

View File

@@ -25,6 +25,8 @@ export interface TransitionProps {
src: string;
isVideo: boolean;
durationMs: number;
/** Fired when a video slide finishes so the parent can advance early. */
onended?: () => void;
}
export const transitions: SlideTransition[] = [

View File

@@ -6,9 +6,11 @@
src: string;
isVideo: boolean;
durationMs: number;
/** Fired when a video slide finishes so the parent can advance early. */
onended?: () => void;
}
let { src, isVideo, durationMs }: Props = $props();
let { src, isVideo, durationMs, onended }: Props = $props();
// Mild random pan so each slide feels different. Range chosen so the image never
// pans out of frame given the object-fit: cover.
@@ -27,6 +29,7 @@
autoplay
muted
playsinline
{onended}
class="h-full w-full object-contain"
></video>
{:else}