fix(translation): address review findings

Follow-up hardening from two review passes on the on-device translation
feature:

- Privacy (HIGH): the translation cache is decrypted message plaintext,
  but logout did not clear it (unlike the search index), leaving up to
  300 cleartext bodies in localStorage on shared devices. Add
  clearTranslationCache() and call it from both logout paths
  (logoutClient and the server-forced SessionLoggedOut handler).
- Edited messages (MEDIUM): the cache key was eventId:target with no
  content dependence, so an edit reused the pre-edit translation. Fold a
  content fingerprint into the key, and re-arm the auto-translate
  one-shot when the text changes.
- Settings (LOW): coerce a persisted translateTargetLang to a supported
  curated code so the hook never targets a language the engine can't
  produce (previously only the UI clamped it).
- Chinese (LOW): restore canonical BCP-47 case (zh-Hant / zh-Hans) at
  the Translator API boundary, since normalizeLang lowercases the script
  subtag for internal keys.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
2026-07-18 16:18:27 -04:00
co-authored by Claude Opus 4.8
parent ecb7b1a7fb
commit c77ab346d3
7 changed files with 60 additions and 13 deletions
+10 -3
View File
@@ -18,9 +18,16 @@ const entry = (key: string, translated = `t-${key}`, fromLang = 'de') => ({
fromLang,
});
test('makeCacheKey: eventId + normalized target', () => {
assert.equal(makeCacheKey('$abc', 'en-US'), '$abc:en');
assert.equal(makeCacheKey('$abc', 'EN'), '$abc:en');
test('makeCacheKey: eventId + normalized target + content fingerprint', () => {
// Same event + target + text is stable and prefixed by event:normalizedTarget.
const k1 = makeCacheKey('$abc', 'en-US', 'hola');
const k2 = makeCacheKey('$abc', 'EN', 'hola');
assert.equal(k1, k2);
assert.ok(k1.startsWith('$abc:en:'));
// Different body (an edit) => different key, so a stale translation misses.
assert.notEqual(makeCacheKey('$abc', 'en', 'hola'), makeCacheKey('$abc', 'en', 'adios'));
// Missing text arg still yields a stable key.
assert.ok(makeCacheKey('$abc', 'en').startsWith('$abc:en:'));
});
test('addTranslation: prepends, newest first', () => {