fix(wave-2): audit fixes — account-data races, search-cache wipe, export, media
Web fixes from the Wave-2 bug-hunt (findings in LOTUS_TODO): - F1 (security): wipe the decrypted-plaintext search index on SERVER-FORCED logout too (token expiry / remote sign-out) — only manual logout did before. F4: the delete no longer reports success while onblocked (waits, 3s cap). - M1/M2 (data-loss): useBookmarks + useUserNotes account-data writes are now serialized at MODULE scope (single queue + latestRef per client, echo-driven), fixing the cross-instance lost-update clobber (useBookmarks mounts per message row, so a per-instance queue was insufficient — caught in review). - M6: room-history export gets a 200-page cap + Cancel + unmount-abort + correct date-range early-break (raw paginated ts). M4: image compression skips PNG (was flattening transparency to black), bakes EXIF orientation via createImageBitmap, .jpg-renames, and falls back to the original on decode failure instead of dropping the file. M5: MediaGallery lightbox opens the right item (shared thumb guard). M8: audio speed survives async decrypt. - Desktop web wiring: D2 badge sums leaf rooms only (space double-count, like the favicon fix); D3 useTauriDnd re-hydrates from get_tray_dnd on mount; D5 updater has a terminal state. Reviewed; M7 reverted (past-time clamp is an intentional, tested contract). tsc/eslint/prettier clean, build OK, 678 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,7 @@
|
||||
export type CompressionResult = {
|
||||
blob: Blob;
|
||||
/** MIME type of the produced blob (currently always image/jpeg). */
|
||||
type: string;
|
||||
originalSize: number;
|
||||
compressedSize: number;
|
||||
width: number;
|
||||
@@ -17,22 +19,47 @@ export function isCompressible(file: File | Blob): boolean {
|
||||
return isCompressibleType(file.type);
|
||||
}
|
||||
|
||||
const JPEG_OUTPUT_TYPE = 'image/jpeg';
|
||||
|
||||
/**
|
||||
* Compress an image file via canvas.toBlob → JPEG at the given quality.
|
||||
* Returns null if the browser cannot render the image (e.g. unsupported codec).
|
||||
* Returns null if the browser cannot render the image (e.g. unsupported codec)
|
||||
* or if the source is left untouched to avoid data loss (see below).
|
||||
*
|
||||
* PNG is skipped entirely: it may carry an alpha channel, and re-encoding to
|
||||
* JPEG composites transparency onto an opaque (black) background, corrupting the
|
||||
* image. Returning null makes callers fall back to uploading the lossless
|
||||
* original. The image is decoded with `imageOrientation: 'from-image'` so any
|
||||
* EXIF orientation is baked into the pixels instead of being silently dropped.
|
||||
*/
|
||||
export async function compressImage(
|
||||
file: File | Blob,
|
||||
quality = 0.82,
|
||||
): Promise<CompressionResult | null> {
|
||||
if (!isCompressibleType(file.type)) return null;
|
||||
// Skip PNG (potential alpha) — re-encoding to JPEG would flatten transparency.
|
||||
if (file.type === 'image/png') return null;
|
||||
|
||||
const img = await loadImage(file);
|
||||
let bitmap: ImageBitmap;
|
||||
try {
|
||||
bitmap = await createImageBitmap(file, { imageOrientation: 'from-image' });
|
||||
} catch {
|
||||
// Corrupt/unsupported source: fall back to uploading the lossless original
|
||||
// (the caller uses the original file on a null result) rather than rejecting,
|
||||
// which would drop the file entirely from the Promise.allSettled upload.
|
||||
return null;
|
||||
}
|
||||
const { width, height } = bitmap;
|
||||
const canvas = document.createElement('canvas');
|
||||
canvas.width = img.naturalWidth;
|
||||
canvas.height = img.naturalHeight;
|
||||
const ctx = canvas.getContext('2d')!;
|
||||
ctx.drawImage(img, 0, 0);
|
||||
canvas.width = width;
|
||||
canvas.height = height;
|
||||
const ctx = canvas.getContext('2d');
|
||||
if (!ctx) {
|
||||
bitmap.close();
|
||||
return null;
|
||||
}
|
||||
ctx.drawImage(bitmap, 0, 0);
|
||||
bitmap.close();
|
||||
|
||||
return new Promise((resolve) => {
|
||||
canvas.toBlob(
|
||||
@@ -43,31 +70,19 @@ export async function compressImage(
|
||||
}
|
||||
resolve({
|
||||
blob,
|
||||
type: JPEG_OUTPUT_TYPE,
|
||||
originalSize: file.size,
|
||||
compressedSize: blob.size,
|
||||
width: img.naturalWidth,
|
||||
height: img.naturalHeight,
|
||||
width,
|
||||
height,
|
||||
});
|
||||
},
|
||||
'image/jpeg',
|
||||
JPEG_OUTPUT_TYPE,
|
||||
quality,
|
||||
);
|
||||
});
|
||||
}
|
||||
|
||||
function loadImage(file: File | Blob): Promise<HTMLImageElement> {
|
||||
return new Promise((resolve, reject) => {
|
||||
const url = URL.createObjectURL(file);
|
||||
const img = new Image();
|
||||
img.onload = () => {
|
||||
URL.revokeObjectURL(url);
|
||||
resolve(img);
|
||||
};
|
||||
img.onerror = reject;
|
||||
img.src = url;
|
||||
});
|
||||
}
|
||||
|
||||
export function formatFileSize(bytes: number): string {
|
||||
if (bytes < 1024) return `${bytes} B`;
|
||||
if (bytes < 1024 * 1024) return `${(bytes / 1024).toFixed(1)} KB`;
|
||||
|
||||
@@ -12,6 +12,8 @@ export async function scheduleMessage(
|
||||
content: IContent,
|
||||
sendAtMs: number,
|
||||
): Promise<string> {
|
||||
// A past/near target floors at 1000ms (send ~immediately) — an intentional,
|
||||
// tested contract; the ScheduleMessageModal already guards ≥60s in the future.
|
||||
const delayMs = Math.max(1000, Math.round(sendAtMs - Date.now()));
|
||||
const txnId = `sched_${Date.now()}_${Math.random().toString(36).slice(2)}`;
|
||||
const path = `/rooms/${encodeURIComponent(roomId)}/send/m.room.message/${txnId}`;
|
||||
|
||||
@@ -298,9 +298,23 @@ export const deleteSearchCacheDatabase = async (): Promise<void> => {
|
||||
return;
|
||||
}
|
||||
const req = indexedDB.deleteDatabase(DB_NAME);
|
||||
req.onsuccess = () => resolve();
|
||||
req.onerror = () => resolve();
|
||||
req.onblocked = () => resolve();
|
||||
let settled = false;
|
||||
const done = () => {
|
||||
if (!settled) {
|
||||
settled = true;
|
||||
resolve();
|
||||
}
|
||||
};
|
||||
req.onsuccess = done;
|
||||
req.onerror = done;
|
||||
req.onblocked = () => {
|
||||
// Another tab still holds the DB open, so the delete is QUEUED, not done —
|
||||
// resolving now would report a wipe that hasn't happened (plaintext still
|
||||
// on disk). Wait for the real onsuccess (fires once the other tab closes;
|
||||
// cross-tab logout reloads it shortly), but cap the wait so logout can't
|
||||
// hang forever if a tab never releases.
|
||||
setTimeout(done, 3000);
|
||||
};
|
||||
} catch {
|
||||
resolve();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user