Repository navigation
fix: close the Phase 1-4 audit defects - #10
Merged
Merged
Conversation
- Password reset, password change and email confirmation cancel pending email changes and reset links; a requested email change warns the old address; account emails that fail are logged without the address and forgot-password answers the same either way. - SMTP errors keep code, status and command but drop the server response. - Digests count only refused recipients and rejected messages against a reader, treat sender and connection failures as outages, send only the releases a run claimed and requeue sends interrupted by a crash; new release markers, inbox rows and digest events are written together. - Notifications pause instead of following another source when a title's preferred source is switched off; unsubscribing a deleted account works. - Imports attach matches without overwriting stored titles, and saved titles are refreshed from their source weekly. - Progress fields accept values past stored totals; removing a game's last platform turns its notifications off; a concurrent first add retries. - Private ratings stay off public profiles; the review editor uses a Private switch that starts off. - Open reports stay in the admin queue when review text is cleared. - Import matches carry the adult flag, imports cannot be deleted while running and leftover uploads are removed at start-up. - IGDB release dates repeated per region are merged. - Security headers, including HSTS behind HTTPS; X-Powered-By is off.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the defects found in the Phase 1–4 audit against the unified media tracker plan. No migrations;
main(including #7, #8 and #9) is merged in.Changes
Accounts and email
MailDeliveryErrorwith code, status and command but without the server response, so logs never contain addresses. Forgot-password and resend verification answer the same whether or not the email could be sent; registration and email change answer 503.Release notifications
RCPT TO) and rejected messages count against a reader. Sender,DATAcommand and connection failures are outages that stop the run without blaming anyone.updateManyAndReturn), and only skips releases it evaluated.sentfor over an hour without a later digest (a crash mid-send) are queued again.Catalogue and library
Reviews, profiles and moderation
Imports
Other
Strict-Transport-Securitybehind HTTPS,X-Content-Type-Options,X-Frame-OptionsandReferrer-Policy;X-Powered-Byis off.Test expectations changed
These tests encoded the old behaviour:
admin.spec.ts: the open-report query no longer filters on review text.profiles.spec.ts: the activity rating query requires public visibility.account.spec.ts: token cleanup covers pending email changes and reset links.notifications.spec.ts: mocks follow the single transaction and the claim-and-return call; the skip query targets evaluated releases; the refused-reader case usesRCPT TOrefusals, since errors raised before contacting the server now count as outages.24 tests were added for the new behaviour.
Verification
npm run lint,npm test(242 server, 29 frontend) andnpm run buildpass on the merged branch.