spa hardening, offline logging, rate limit fixes

server:
- backup exporter, auth extractors, error shapes, CONTEXT (prior work)
- spa assets served outside the rate limit via route_layer
- requests_per_second went to per_second(), which takes an interval not a
  rate: 50 meant one request per 50s once burst was spent. now converted
  properly. 15/s, burst 60

spa fixes:
- account delete cleared snake_case token keys that were never written
- refresh interceptor could retry forever
- date ranges used local day boundaries stamped +00:00
- "all" period trend plotted one page; calendar days fabricated mood 3
- chart grid invisible: hsl(var(--border)) against rgba tokens
- blob url leak, orphaned media on failed save, devtools in prod bundle
- pt-safe/safe-area-pb classes never existed

spa features:
- offline outbox: entries queue to IndexedDB, replay with backoff, only
  server refusals count against an entry
- drafts persist, quick-log sheet, diary infinite scroll + filters
- route error boundary, stale-chunk recovery, no service worker in dev

a11y + perf:
- mood picker is a radiogroup, activity picker keyboard-operable,
  text alternatives for colour/emoji, locale week start
- dark glass over the bright photo: worst case 1.4:1 -> 4.9-9.6:1
- initial payload 1095->769kB raw, 306->230kB gzip; 38 unused components
  and 5 deps dropped; fonts 218->133kB

53 tests added (43 spa, 10 server)
This commit is contained in:
2026-08-28 14:59:21 +02:00
parent 23d052278a
commit bf148902ab
395 changed files with 13972 additions and 10635 deletions

View File

@@ -1,6 +1,6 @@
use std::sync::Arc;
use domain::api_token::ApiToken;
use domain::api_token::{ApiToken, TokenScope, TokenScopes};
use domain::ports::UserCommandPort;
use domain::provider::ProviderName;
use domain::testing::{FakeApiTokenSecret, InMemoryStore, test_user};
@@ -31,6 +31,14 @@ async fn a_user_with_no_tokens() -> Fixture {
impl Fixture {
async fn mint(&self, name: &str) -> Result<String, application::errors::ApplicationError> {
self.mint_granting(name, [TokenScope::WriteMetrics]).await
}
async fn mint_granting(
&self,
name: &str,
scopes: impl IntoIterator<Item = TokenScope>,
) -> Result<String, application::errors::ApplicationError> {
let deps = mint_api_token::Deps {
command: self.store.clone(),
secrets: self.secrets.clone(),
@@ -40,6 +48,7 @@ impl Fixture {
MintApiTokenCommand {
user_id: self.user.id().clone(),
name: ProviderName::new(name)?,
scopes: TokenScopes::new(scopes)?,
},
&deps,
)
@@ -49,13 +58,20 @@ impl Fixture {
}
async fn authenticate(&self, secret: &str) -> Option<ApiToken> {
self.authenticate_for(secret, TokenScope::WriteMetrics)
.await
}
async fn authenticate_for(&self, secret: &str, needed: TokenScope) -> Option<ApiToken> {
let deps = authenticate_api_token::Deps {
query: self.store.clone(),
command: self.store.clone(),
secrets: self.secrets.clone(),
};
authenticate_api_token::execute(secret, &deps).await.ok()
authenticate_api_token::execute(secret, needed, &deps)
.await
.ok()
}
async fn list(&self) -> Vec<ApiToken> {
@@ -181,3 +197,83 @@ async fn every_minting_produces_a_different_secret() {
assert_ne!(first, second);
}
#[tokio::test]
async fn a_token_authenticates_only_for_a_scope_it_grants() {
let fixture = a_user_with_no_tokens().await;
let secret = fixture
.mint_granting("widget", [TokenScope::ReadJournal])
.await
.unwrap();
assert!(
fixture
.authenticate_for(&secret, TokenScope::ReadJournal)
.await
.is_some(),
"the scope it was minted for must work"
);
for refused in [
TokenScope::WriteJournal,
TokenScope::WriteMetrics,
TokenScope::ReadProfile,
] {
assert!(
fixture.authenticate_for(&secret, refused).await.is_none(),
"a read-only token must not pass for {refused}"
);
}
}
#[tokio::test]
async fn a_token_can_grant_several_scopes_at_once() {
let fixture = a_user_with_no_tokens().await;
let secret = fixture
.mint_granting(
"widget",
[TokenScope::ReadJournal, TokenScope::WriteJournal],
)
.await
.unwrap();
assert!(
fixture
.authenticate_for(&secret, TokenScope::ReadJournal)
.await
.is_some()
);
assert!(
fixture
.authenticate_for(&secret, TokenScope::WriteJournal)
.await
.is_some()
);
assert!(
fixture
.authenticate_for(&secret, TokenScope::ReadProfile)
.await
.is_none()
);
}
#[tokio::test]
async fn the_scopes_a_token_grants_are_listed_back() {
let fixture = a_user_with_no_tokens().await;
fixture
.mint_granting(
"widget",
[TokenScope::ReadJournal, TokenScope::WriteJournal],
)
.await
.unwrap();
let listed = fixture.list().await;
assert_eq!(listed.len(), 1);
assert_eq!(
listed[0].scopes().names(),
vec!["readJournal", "writeJournal"],
"a client needs to see what a token it holds can do"
);
}