fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling

- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers
- H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables
- M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps)
- M2: split handleSave try/catch — save errors vs reload errors shown distinctly
- M3: added provider field validation before AI config test request
- Added SSE scoping regression tests (import service + controller)
- Added FK check failure rollback test (database-migrations.spec)
- Updated controller spec expectations for userId parameter

Co-authored-by: Code Review <branch-review>
This commit is contained in:
2026-07-12 22:59:03 +08:00
parent b6fca99390
commit cc4f4dae4e
69 changed files with 6262 additions and 1980 deletions

View File

@@ -98,6 +98,29 @@ export class SyncService {
return this.dingTalkService.fetchOrgTreeWithUsers(rootDeptId);
}
async getDingTalkAttendanceGroups() {
return this.dingTalkService.queryAttendanceGroups();
}
async deleteAllDingTalkAttendanceGroups() {
const groups = await this.dingTalkService.queryAttendanceGroups();
const deleted: Array<{ groupId: number; groupName: string }> = [];
const failed: Array<{ groupId: number; groupName: string; error: string }> = [];
for (const group of groups) {
try {
await this.dingTalkService.deleteAttendanceGroup(group.group_id);
deleted.push({ groupId: group.group_id, groupName: group.group_name });
} catch (error: unknown) {
failed.push({
groupId: group.group_id,
groupName: group.group_name,
error: error instanceof Error ? error.message : String(error),
});
}
}
return { total: groups.length, deleted, failed };
}
// ── 排班同步 ──
/** 将本地排课同步到钉钉考勤排班 */