fix(security): medium/low — event-lock, atomic config, a11y, diashow, hygiene
- social: likes/comments rejected on a closed event (e2e proven). - admin: patch_config validates-then-writes atomically; char-based length. - hashtag/comment models: atomic tag writes in edit + comment paths. - Modal: inert the background (modal-inert action) for screen readers. - sse.ts: idempotent visibilitychange listener (no duplicate reconnects). - diashow: videos advance on `ended` (transitions + page wiring). - docs/hygiene: README clone-case fix; removed stale committed .env.test and gitignored it; docker-compose.dev.yml tidy. Left documented as accepted-risk per plan: PIN-persist-after-logout, UUID-reachable hidden uploads, DECISION-media-auth.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -174,15 +174,31 @@ async function deltaFetchAndFan(since: string): Promise<void> {
|
||||
|
||||
// Page Visibility API: close while hidden, reopen on focus. On reopen `connectSse`'s
|
||||
// `onopen` runs the delta fetch.
|
||||
if (typeof document !== 'undefined') {
|
||||
document.addEventListener('visibilitychange', () => {
|
||||
if (document.hidden) {
|
||||
disconnectSse();
|
||||
} else {
|
||||
// User-initiated reconnect — clear backoff so we don't wait out a long
|
||||
// retry delay that was scheduled from a prior background error.
|
||||
reconnectAttempt = 0;
|
||||
connectSse();
|
||||
}
|
||||
});
|
||||
function handleVisibilityChange() {
|
||||
if (document.hidden) {
|
||||
disconnectSse();
|
||||
} else {
|
||||
// User-initiated reconnect — clear backoff so we don't wait out a long
|
||||
// retry delay that was scheduled from a prior background error.
|
||||
reconnectAttempt = 0;
|
||||
connectSse();
|
||||
}
|
||||
}
|
||||
|
||||
let visibilityBound = false;
|
||||
|
||||
/** Idempotent: safe to call more than once; only the first registration sticks. */
|
||||
function bindVisibility() {
|
||||
if (visibilityBound || typeof document === 'undefined') return;
|
||||
document.addEventListener('visibilitychange', handleVisibilityChange);
|
||||
visibilityBound = true;
|
||||
}
|
||||
|
||||
/** Remove the visibility listener (e.g. on teardown / test cleanup). */
|
||||
export function teardownVisibility() {
|
||||
if (!visibilityBound || typeof document === 'undefined') return;
|
||||
document.removeEventListener('visibilitychange', handleVisibilityChange);
|
||||
visibilityBound = false;
|
||||
}
|
||||
|
||||
bindVisibility();
|
||||
|
||||
Reference in New Issue
Block a user