fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling

- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers
- H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables
- M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps)
- M2: split handleSave try/catch — save errors vs reload errors shown distinctly
- M3: added provider field validation before AI config test request
- Added SSE scoping regression tests (import service + controller)
- Added FK check failure rollback test (database-migrations.spec)
- Updated controller spec expectations for userId parameter

Co-authored-by: Code Review <branch-review>
This commit is contained in:
2026-07-12 22:59:03 +08:00
parent b6fca99390
commit cc4f4dae4e
69 changed files with 6262 additions and 1980 deletions

View File

@@ -111,6 +111,11 @@ export class QueryAttendanceRecordsDto {
@Type(() => Number)
classId?: number;
@IsOptional()
@IsInt()
@Type(() => Number)
scheduleId?: number;
@IsOptional()
@IsDateString()
dateFrom?: string;
@@ -204,3 +209,15 @@ export class GenerateFromSchedulesDto {
@IsDateString()
endDate?: string;
}
export class LessonAttendanceQueryDto {
@IsDateString()
@IsNotEmpty()
date: string;
}
export class StartLessonAttendanceDto {
@IsDateString()
@IsNotEmpty()
date: string;
}

View File

@@ -47,6 +47,8 @@ export interface ImportProgressEvent {
message: string;
/** Error message (only when phase === 'error') */
error?: string;
/** ID of the user who triggered the import (undefined for non-HTTP callers) */
userId?: number;
}
/**