fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling

- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers
- H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables
- M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps)
- M2: split handleSave try/catch — save errors vs reload errors shown distinctly
- M3: added provider field validation before AI config test request
- Added SSE scoping regression tests (import service + controller)
- Added FK check failure rollback test (database-migrations.spec)
- Updated controller spec expectations for userId parameter

Co-authored-by: Code Review <branch-review>
This commit is contained in:
2026-07-12 22:59:03 +08:00
parent b6fca99390
commit cc4f4dae4e
69 changed files with 6262 additions and 1980 deletions

View File

@@ -60,23 +60,17 @@ export function shouldAutoSwapBaseUrl(
return { baseUrl: currentBaseUrl, shouldSwap: false };
}
/** Extract a safe user-facing error message from any caught value */
/** Extract a safe user-facing error message from any caught value.
*
* The Axios interceptor at `api/index.ts` unwraps errors before rejection:
* `Promise.reject(err.response?.data || err)`. So server errors arrive as
* `{ message: '...' }` (the unwrapped data) and network errors as the raw
* `Error` object — never as a raw AxiosError with a `.response` property. */
export function extractErrorMessage(err: unknown, fallback: string = '操作失败'): string {
let msg = '';
// axios-style error: { response: { data: { message: string } } }
if (err && typeof err === 'object' && 'response' in err) {
const resp: unknown = err.response;
if (resp && typeof resp === 'object' && 'data' in resp) {
const data: unknown = resp.data;
if (data && typeof data === 'object' && 'message' in data && typeof data.message === 'string') {
msg = data.message;
}
}
}
// standard Error or any object with a string message property
if (!msg && err && typeof err === 'object' && 'message' in err && typeof err.message === 'string') {
if (err && typeof err === 'object' && 'message' in err && typeof err.message === 'string') {
msg = err.message;
}