Comprehensive user-flow review across guest/host/admin roles, then fixes with
e2e regression guards. Highlights:
- Offline upload queue auto-resumes on reconnect: network errors keep items
pending (not error), 4xx are terminal (no infinite retry), quota exhaustion
returns a distinct 413; queue cap + dedup.
- Export lifecycle: release atomically locks uploads; reopen invalidates and
re-release regenerates the keepsake; workers claim their job atomically so a
reopen->re-release can't corrupt the ZIP; startup re-spawns interrupted
exports.
- Sessions slide on activity (no 30-day cliff); JWT expiry deferred to the
revocable session row; sign-out-everywhere + revoke-on-PIN-reset.
- Ban always hides content (v_feed / find_visible_media / export filter
is_banned) but stays a read-only ban per USER_JOURNEYS §10 — sessions are
not revoked, read access + keepsake download preserved.
- Realtime: server-clock SSE delta cursor; event-closed/opened drive the UI
live; feed_delta rate-limited; like returns {liked, like_count} to fix
multi-device drift; lightbox live comments; diashow delta backfill.
- Forgotten-PIN in-app request flow; simultaneous same-name join returns 409;
quota increment is transactional; operator floor.
Adds e2e/specs/10-flow-review/ (offline resume, export integrity, deterministic
anti-race guard) and updates existing specs for the new contracts.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
69 lines
2.3 KiB
Rust
69 lines
2.3 KiB
Rust
use sqlx::PgPool;
|
|
use tokio::sync::broadcast;
|
|
|
|
use crate::config::AppConfig;
|
|
use crate::services::compression::CompressionWorker;
|
|
use crate::services::config::ConfigCache;
|
|
use crate::services::disk::DiskCache;
|
|
use crate::services::rate_limiter::RateLimiter;
|
|
use crate::services::sse_tickets::SseTicketStore;
|
|
|
|
#[derive(Clone, Debug)]
|
|
pub struct SseEvent {
|
|
pub event_type: String,
|
|
pub data: String,
|
|
}
|
|
|
|
impl SseEvent {
|
|
/// Standardised constructor. Prefer this over building the struct inline so the
|
|
/// event-type strings stay consistent across handlers.
|
|
pub fn new(event_type: impl Into<String>, data: impl Into<String>) -> Self {
|
|
Self {
|
|
event_type: event_type.into(),
|
|
data: data.into(),
|
|
}
|
|
}
|
|
}
|
|
|
|
#[derive(Clone)]
|
|
pub struct AppState {
|
|
pub pool: PgPool,
|
|
pub config: AppConfig,
|
|
pub sse_tx: broadcast::Sender<SseEvent>,
|
|
pub compression: CompressionWorker,
|
|
pub rate_limiter: RateLimiter,
|
|
pub sse_tickets: SseTicketStore,
|
|
/// In-memory cache in front of the `config` table. Reads go through here; the
|
|
/// admin PATCH handler and the test reseed invalidate it after committing.
|
|
pub config_cache: ConfigCache,
|
|
/// Cached total/free bytes for the media filesystem (quota + admin stats).
|
|
pub disk_cache: DiskCache,
|
|
}
|
|
|
|
impl AppState {
|
|
pub fn new(pool: PgPool, config: AppConfig) -> Self {
|
|
// Broadcast buffer for live SSE fan-out. Sized to absorb a burst (e.g. many
|
|
// uploads landing at once during a busy moment) before a slow consumer lags and
|
|
// has to `resync`. The resync path is a correctness backstop, not the happy path —
|
|
// a roomier buffer keeps ~1000 concurrent clients from all resyncing at once.
|
|
let (sse_tx, _) = broadcast::channel(1024);
|
|
let compression = CompressionWorker::new(
|
|
pool.clone(),
|
|
config.media_path.clone(),
|
|
config.compression_concurrency,
|
|
sse_tx.clone(),
|
|
);
|
|
let config_cache = ConfigCache::new(pool.clone());
|
|
Self {
|
|
pool,
|
|
config,
|
|
sse_tx,
|
|
compression,
|
|
rate_limiter: RateLimiter::new(),
|
|
sse_tickets: SseTicketStore::new(),
|
|
config_cache,
|
|
disk_cache: DiskCache::new(),
|
|
}
|
|
}
|
|
}
|