Comprehensive user-flow review across guest/host/admin roles, then fixes with
e2e regression guards. Highlights:
- Offline upload queue auto-resumes on reconnect: network errors keep items
pending (not error), 4xx are terminal (no infinite retry), quota exhaustion
returns a distinct 413; queue cap + dedup.
- Export lifecycle: release atomically locks uploads; reopen invalidates and
re-release regenerates the keepsake; workers claim their job atomically so a
reopen->re-release can't corrupt the ZIP; startup re-spawns interrupted
exports.
- Sessions slide on activity (no 30-day cliff); JWT expiry deferred to the
revocable session row; sign-out-everywhere + revoke-on-PIN-reset.
- Ban always hides content (v_feed / find_visible_media / export filter
is_banned) but stays a read-only ban per USER_JOURNEYS §10 — sessions are
not revoked, read access + keepsake download preserved.
- Realtime: server-clock SSE delta cursor; event-closed/opened drive the UI
live; feed_delta rate-limited; like returns {liked, like_count} to fix
multi-device drift; lightbox live comments; diashow delta backfill.
- Forgotten-PIN in-app request flow; simultaneous same-name join returns 409;
quota increment is transactional; operator floor.
Adds e2e/specs/10-flow-review/ (offline resume, export integrity, deterministic
anti-race guard) and updates existing specs for the new contracts.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
40 lines
1.6 KiB
SQL
40 lines
1.6 KiB
SQL
-- Ban now ALWAYS hides: exclude banned uploaders from the feed view. Previously ban and
|
|
-- hide were decoupled (a host could ban without hiding), leaving a banned user's photos on
|
|
-- the feed and baked into the export. `find_visible_media` and the export query get the
|
|
-- same `is_banned = FALSE` filter in code.
|
|
CREATE OR REPLACE VIEW v_feed AS
|
|
SELECT
|
|
u.id,
|
|
u.event_id,
|
|
u.user_id,
|
|
usr.display_name AS uploader_name,
|
|
usr.is_banned,
|
|
usr.uploads_hidden,
|
|
u.preview_path,
|
|
u.thumbnail_path,
|
|
u.mime_type,
|
|
u.caption,
|
|
u.created_at,
|
|
COUNT(DISTINCT l.user_id) AS like_count,
|
|
COUNT(DISTINCT c.id) AS comment_count
|
|
FROM upload u
|
|
JOIN "user" usr ON u.user_id = usr.id
|
|
LEFT JOIN "like" l ON l.upload_id = u.id
|
|
LEFT JOIN comment c ON c.upload_id = u.id AND c.deleted_at IS NULL
|
|
WHERE u.deleted_at IS NULL
|
|
AND usr.uploads_hidden = FALSE
|
|
AND usr.is_banned = FALSE
|
|
GROUP BY u.id, usr.display_name, usr.is_banned, usr.uploads_hidden;
|
|
|
|
-- pin_reset_request: a guest who forgot their PIN (localStorage was the only copy) can ask
|
|
-- a host to reset it in-app, instead of being permanently orphaned. One pending request per
|
|
-- user; cleared when the host resets the PIN or dismisses it, and cascades if the user/event
|
|
-- is removed.
|
|
CREATE TABLE pin_reset_request (
|
|
id UUID PRIMARY KEY DEFAULT gen_random_uuid(),
|
|
event_id UUID NOT NULL REFERENCES event(id) ON DELETE CASCADE,
|
|
user_id UUID NOT NULL REFERENCES "user"(id) ON DELETE CASCADE,
|
|
created_at TIMESTAMPTZ NOT NULL DEFAULT NOW(),
|
|
UNIQUE (user_id)
|
|
);
|