forked from wangziqi/gongxue-base
fix: audit remediation — SSE user scoping, FK transactional safety, UI error handling
- H4: scoped SSE import progress to exact userId match; non-HTTP events excluded from all subscribers - H2: moved PRAGMA foreign_key_check inside SQLite transaction before COMMIT; violations rollback preserving old tables - M1: removed dead axios-style error branch from extractErrorMessage (interceptor already unwraps) - M2: split handleSave try/catch — save errors vs reload errors shown distinctly - M3: added provider field validation before AI config test request - Added SSE scoping regression tests (import service + controller) - Added FK check failure rollback test (database-migrations.spec) - Updated controller spec expectations for userId parameter Co-authored-by: Code Review <branch-review>
This commit is contained in:
@@ -50,6 +50,21 @@ export class SyncController {
|
||||
return { success: true, data: tree };
|
||||
}
|
||||
|
||||
@Get('dingtalk/attendance-groups')
|
||||
@RequirePermission('sync:read')
|
||||
async getDingTalkAttendanceGroups() {
|
||||
return { success: true, data: await this.syncService.getDingTalkAttendanceGroups() };
|
||||
}
|
||||
|
||||
@Post('dingtalk/attendance-groups/delete-all')
|
||||
@RequirePermission('sync:trigger')
|
||||
async deleteAllDingTalkAttendanceGroups() {
|
||||
return {
|
||||
success: true,
|
||||
data: await this.syncService.deleteAllDingTalkAttendanceGroups(),
|
||||
};
|
||||
}
|
||||
|
||||
@Get('logs')
|
||||
@RequirePermission('sync:read')
|
||||
async getLogs(
|
||||
|
||||
Reference in New Issue
Block a user