Adversarial re-review of df275bb found the two-guard ready-flip fix still left a
narrow double-race open, plus test-hygiene drift from the banUser param removal.
MED — residual stale-keepsake race the `export_released_at` guard alone missed
The flip relied on two guards defeating two clearers: the `release_seq` EXISTS
check (vs a re-release bump) and `export_released_at IS NOT NULL` (vs open_event's
clear). But release_gallery re-arms `export_released_at = NOW()` and bumps
`release_seq` as SEPARATE statements, so a stale worker's flip landing in the gap
between them satisfies BOTH guards (released re-armed, seq not yet bumped) and
resurrects a pre-reopen keepsake — the next re-release then skips regeneration and
serves an archive missing the reopen-window uploads.
Root-cause fix: `open_event` now bumps every `export_job.release_seq`, making a
reopen a supersession point symmetric with a re-release. A worker that captured the
pre-reopen seq can never match its `release_seq`-guarded finalize/flip again,
regardless of when the re-release re-arms `export_released_at`. The released-anchor
guard stays as defense-in-depth. Added a deterministic e2e asserting the reopen
bumps the seq (the invariant that closes the race without depending on
sub-millisecond worker timing).
LOW
- Gate the `export-progress: 100` SSE + `prune_stale_export_files` on the ready-flip
actually flipping (rows_affected > 0). A superseded worker no longer advertises a
misleading 100% or prunes on a fresh generation's behalf.
- moderation.spec.ts: the two ban tests had become byte-identical after the
hide_uploads param removal; drop the one whose "hide_uploads=true" title no longer
matched what it exercised, keep the accurate "always hides" test.
- host-dashboard page-object: drop the dead `banUser(hideUploads)` param + its
checkbox branch (the UI no longer renders that checkbox — a latent hang trap).
- sse-eviction.spec.ts: rename the test whose title referenced the removed flag.
Verified: backend 40 tests, e2e 156 passed / 1 skipped on chromium-desktop
(incl. the new reopen-supersession regression).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
76 lines
2.6 KiB
TypeScript
76 lines
2.6 KiB
TypeScript
/**
|
|
* Regression for the review's H3: self-deleting an upload and banning a user with
|
|
* hide_uploads mutated visibility server-side but broadcast nothing, so the
|
|
* content lingered on every other viewer's feed (and the projector diashow) until
|
|
* a manual reload. Both now emit SSE so clients evict live.
|
|
*/
|
|
import { test, expect } from '../../fixtures/test';
|
|
import { seedUpload } from '../../helpers/seed';
|
|
import { SseListener } from '../../helpers/sse-listener';
|
|
|
|
const BASE = process.env.E2E_FRONTEND_URL ?? 'http://localhost:3101';
|
|
|
|
test.describe('Host — live SSE eviction (H3)', () => {
|
|
test('self-deleting an upload broadcasts upload-deleted', async ({ guest }) => {
|
|
const g = await guest('SelfDeleter');
|
|
const uploadId = await seedUpload(g.jwt, { caption: 'delete me' });
|
|
|
|
const sse = new SseListener();
|
|
await sse.start(g.jwt);
|
|
|
|
const res = await fetch(`${BASE}/api/v1/upload/${uploadId}`, {
|
|
method: 'DELETE',
|
|
headers: { Authorization: `Bearer ${g.jwt}` },
|
|
});
|
|
expect(res.status).toBe(204);
|
|
|
|
await sse.waitForEvent(
|
|
'upload-deleted',
|
|
(e) => e.data.upload_id === uploadId
|
|
);
|
|
});
|
|
|
|
test('banning a user broadcasts user-hidden', async ({
|
|
api,
|
|
host,
|
|
guest,
|
|
}) => {
|
|
const target = await guest('HideTarget');
|
|
await seedUpload(target.jwt, { caption: 'should vanish' });
|
|
|
|
const sse = new SseListener();
|
|
await sse.start(host.jwt);
|
|
|
|
await api.banUser(host.jwt, target.userId);
|
|
|
|
await sse.waitForEvent(
|
|
'user-hidden',
|
|
(e) => e.data.user_id === target.userId
|
|
);
|
|
});
|
|
|
|
// Frontend regression: the broadcasts above are inert if the client never
|
|
// registers the event name (the KNOWN_EVENTS gap that shipped both eviction
|
|
// handlers as dead code). Drive a real browser feed and assert LIVE eviction —
|
|
// this fails if 'user-hidden' is missing from KNOWN_EVENTS, unlike the
|
|
// backend-only SseListener checks above.
|
|
test('a hidden user is evicted from an open feed without reload (frontend)', async ({
|
|
page,
|
|
api,
|
|
host,
|
|
guest,
|
|
signIn,
|
|
}) => {
|
|
const viewer = await guest('LiveEvictViewer');
|
|
const target = await guest('LiveEvictTarget');
|
|
await seedUpload(target.jwt, { caption: 'evict-me-live-xyz' });
|
|
|
|
await signIn(page, viewer); // lands on the event-wide /feed
|
|
await expect(page.getByText('evict-me-live-xyz').first()).toBeVisible();
|
|
|
|
// Host hides the target — the viewer's feed must drop the card via SSE, no reload.
|
|
await api.banUser(host.jwt, target.userId);
|
|
await expect(page.getByText('evict-me-live-xyz')).toHaveCount(0, { timeout: 15_000 });
|
|
});
|
|
});
|