A comprehensive role-based E2E audit (guest/host/admin, across browser sessions) surfaced one critical and several smaller issues; this addresses them and hardens the tests that missed them. Critical - The client upload pipeline was fully broken: the IndexedDB v1->v2 upgrade opened a *new* transaction inside the upgrade callback, which throws during a version-change transaction and aborted the whole upgrade, leaving the queue object store uncreated -- so no UI upload ever fired. Reuse the version-change transaction the callback provides, and bump the DB to v3 with a contains() guard so installs already corrupted by the shipped bug self-heal on next load. Re-enabled the previously-fixme'd UI upload E2E test. High / Medium - Event lock is uploads-only again: likes, comments and browsing stay open while the event is locked (USER_JOURNEYS 9.3 / FEATURES) -- it was wrongly freezing social interaction. Updated the event-lock spec accordingly. - get_original now excludes soft-deleted and ban-hidden uploads, and direct /media/originals/** serving is blocked, so a hidden user's originals can no longer be pulled by UUID (all originals go through the checked alias). - The upload handler reads the file field with an early-abort size cap chosen from the declared content-type, instead of buffering the entire body before the size check. Low - unban_user mirrors the ban role guard (a host can no longer unban a host/admin banned by an admin). - reset_user_pin's UPDATE is event-scoped. - Admin login returns and stores a real identity (user_id + display name) instead of a blank session. - The host user list no longer renders target-actions (ban/promote/demote/PIN) on the caller's own row, where the backend always rejected them. - /diashow gains a client-side auth guard like the other protected routes. - The join page shows the event name via a new public GET /api/v1/event. Verified: backend cargo build clean, frontend svelte-check 0 errors, full Playwright E2E suite 144 passed / 1 skipped. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
25 lines
792 B
Rust
25 lines
792 B
Rust
//! Unauthenticated, read-only endpoints safe to expose before a user has joined.
|
|
|
|
use axum::extract::State;
|
|
use axum::Json;
|
|
use serde::Serialize;
|
|
|
|
use crate::state::AppState;
|
|
|
|
#[derive(Serialize)]
|
|
pub struct PublicEventDto {
|
|
pub name: String,
|
|
pub slug: String,
|
|
}
|
|
|
|
/// Public event identity, used by the pre-auth join/recover screens so a guest can
|
|
/// see *which* event they're joining. Only the display name and slug are exposed —
|
|
/// nothing user-scoped — so this is safe without a token. Served straight from the
|
|
/// instance config (no DB round-trip needed).
|
|
pub async fn get_public_event(State(state): State<AppState>) -> Json<PublicEventDto> {
|
|
Json(PublicEventDto {
|
|
name: state.config.event_name.clone(),
|
|
slug: state.config.event_slug.clone(),
|
|
})
|
|
}
|