Brings the batch-2 security hardening into main (forked from the same base as
the UX batch; auto-merged cleanly — verified both sides' edits to social.rs /
main.rs coexist):
- Cross-event authorization: toggle_like / list_comments / add_comment now
event-scope the upload via Upload::find_by_id_and_event (404 on cross-event
access); delete_comment uses Comment::soft_delete_in_event. Closes the gap
where a guest could like/comment/list across events by upload UUID.
- Upload OOM backstop: the /upload route gets DefaultBodyLimit::max(576 MiB)
instead of disable(), so a multi-GB body can't be buffered before the
handler's per-class size checks run.
- upload.rs per-class size-limit refactor, XSS allowlist, deploy hardening
(Caddyfile, Dockerfiles, docker-compose, .env.example), and a data-mode
doc-comment clarifying the original-media route is capability-(UUID-)gated.
The event-scope checks sit before, and batch-3's best-effort count broadcasts
after, the like/comment mutations — both preserved.
Verified: cargo build clean, svelte-check 0 errors.
Address the two items from the adversarial re-review of batch-2.
- upload: remove image/heic + image/heif from ALLOWED_MEDIA. Neither the
`image` crate nor the bundled ffmpeg 6.1 (Alpine 3.21 — HEIF demuxer
only landed in ffmpeg 7.0) can decode them, so accepting them stored
posts that never got a thumbnail. iOS Safari transcodes HEIC->JPEG on
file-input selection, so this rejects only the rare HEIC-preserving
path, now with a clear error instead of a silently broken post.
- data-mode-store: correct the stale "auth-gated" comment — the
/original route is intentionally unauthenticated (UUID-as-capability)
so it works from plain <img src> / <video src>.
Re-verified: cargo build (only the pre-existing middleware.rs warning).
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
The plumbing layer the v0.16 UI features (and dark mode) build on.
Shared design tokens (Tailwind v4):
- tailwind-theme.css (new): @custom-variant dark (class-driven, beats OS
default) + @theme color/font/radius tokens + baseline html/html.dark
rules so any page that hasn't been re-themed still renders the right
body bg + color-scheme.
- src/app.css + export-viewer/src/app.css now import the shared theme.
- src/app.html: 6-line FOUC guard sets <html class="dark"> before paint
(mirrored from theme-store.ts) so dark reloads no longer flash white.
Adds <meta name="theme-color"> kept in sync by initTheme().
Cross-cutting stores (one per concern, per docs/FEATURES §2.9):
- data-mode-store.ts: 'saver' | 'original' per-device, plus pickMediaUrl
helper so feed cards / lightbox / diashow all resolve URLs the same way.
- privacy-note-store.ts: hydrated from /me/context, refreshed on SSE
event-updated.
- quota-store.ts: { enabled, used, limit, active_uploaders, free_disk },
refreshed after each upload completes.
- theme-store.ts: 'system' | 'light' | 'dark' preference + derived
appliedTheme + initTheme() that syncs <html class>, localStorage,
and the theme-color meta. Listens to prefers-color-scheme.
- auth.ts: currentPin writable mirror + clearPin() helper called from
the global pin-reset SSE handler — fixes the stale-PIN bug where the
localStorage copy survived a reset.
DTO mirror:
- types.ts: QuotaDto, MeContextDto, PinResetResponse, DeltaResponse each
carry a `// mirrors backend/...` comment per the lib README convention.
SSE client:
- sse.ts: KNOWN_EVENTS registry (one entry per server-emitted type),
synthetic feed-delta dispatched after foreground reconnect via the
/feed/delta?since= endpoint, exponential backoff (1 → 60 s + jitter)
on errors, attempt counter reset on user-initiated visibility resume.
Upload queue:
- upload-queue.ts: IDB schema bumped to v2 — entries tagged with userId;
loadQueue filters by current user (no cross-user leak on shared
devices); uploadItem refuses to upload an entry whose userId differs
from getUserId() (defense-in-depth); new clearQueue() called on
explicit logout. v2 upgrade wipes pre-v2 entries (no userId, can't
attribute safely).
Mobile primitives:
- actions/longpress.ts: 500 ms hold with 10 px move tolerance, swallows
the next click + the right-click contextmenu so the gesture doesn't
double-fire the inner button's onclick.
- actions/doubletap.ts: tap-pair detector that preventDefaults the
second tap so iOS Safari doesn't also zoom on double-tap.
- components/ContextSheet.svelte: generic bottom sheet driven by a
ContextAction[] prop. Reused by feed posts, comments, host user rows.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>