Repository navigation
A quarantined avatar or banner only replaces the old one once the worker has written it out (GRYT-1664) - #274
Merged
Conversation
…ker has written it out (GRYT-1664) Testing real uploads showed a refused file (a truncated MP4, HTML named .png) became the member's avatar at once, left them with a broken picture, and made every read wait the full 15 seconds. Now the old one stays until the worker's copy is ready, a refused file is deleted, and a read of one answers 404 at once. Co-Authored-By: Claude Opus 5.5 <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Found by uploading real and broken files to a local Docker server and to a server embedded in the dev app (GRYT-1664).
Before this, a quarantined avatar or banner became the member's the moment it was uploaded. If the worker then refused it (a truncated MP4, HTML named
.png, random bytes), three things went wrong:Now:
applyWhenSettledwaits for the worker's verdict (settleQuarantine, up to 10 minutes) and only then sets the avatar or banner. Only then is the old banner deleted. Then the member list is broadcast.media_refusedat once.getImageJobStatusForFileinsrc/db/sqlite/imageJobs.tsis the one database change; it's a read.broadcastMembersUpdate()insocket/utils/server.tsuses the refs REST routes already use.Tested:
uploadQuarantine.test.tshas the refusal case, the newer-upload-wins case, and the existing banner and video cases updated to wait for the worker. End to end in the dev app: the bad avatar was never applied, the good one stayed, and the refused row was deleted.What to look at:
users.processing: truewith the new id. The client shows it straight away and gets 503 until it's ready. A refusal doesn't reach the uploader yet: filed as GRYT-1667.Review-required:
src/db/sqlite/imageJobs.ts.🤖 Generated with Claude Code