fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling

- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers
- H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables
- M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps)
- M2: split handleSave try/catch — save errors vs reload errors shown distinctly
- M3: added provider field validation before AI config test request
- Added SSE scoping regression tests (import service + controller)
- Added FK check failure rollback test (database-migrations.spec)
- Updated controller spec expectations for userId parameter

Co-authored-by: Code Review <branch-review>
This commit is contained in:
2026-07-12 22:59:03 +08:00
parent b6fca99390
commit cc4f4dae4e
69 changed files with 6262 additions and 1980 deletions

View File

@@ -0,0 +1,65 @@
export type AttendanceExperience = 'teacher' | 'admin';
export type SchedulePhase = 'upcoming' | 'ongoing' | 'ended';
import { getRoleDomains } from '../../auth/menu-policy';
export function getAttendanceExperience(
permissions: readonly string[],
roles: readonly string[],
): AttendanceExperience {
const domains = getRoleDomains(roles, permissions);
if (
permissions.includes('attendance:manage') ||
domains.has('academic') ||
domains.has('super')
) {
return 'admin';
}
return 'teacher';
}
function toMinuteOfDay(time: string): number {
const [hour = 0, minute = 0] = time.split(':').map(Number);
return hour * 60 + minute;
}
export function getSchedulePhase(
startTime: string,
endTime: string,
now = new Date(),
): SchedulePhase {
const current = now.getHours() * 60 + now.getMinutes();
if (current < toMinuteOfDay(startTime)) return 'upcoming';
if (current <= toMinuteOfDay(endTime)) return 'ongoing';
return 'ended';
}
export function canPullAttendance(phase: SchedulePhase): boolean {
return phase !== 'upcoming';
}
export interface AttendanceSummary {
total: number;
present: number;
late: number;
absent: number;
leave: number;
pending: number;
}
export function summarizeAttendance(records: readonly { status: string }[]): AttendanceSummary {
const summary: AttendanceSummary = {
total: records.length,
present: 0,
late: 0,
absent: 0,
leave: 0,
pending: 0,
};
for (const record of records) {
if (record.status in summary && record.status !== 'total') {
summary[record.status as Exclude<keyof AttendanceSummary, 'total'>] += 1;
}
}
return summary;
}