mirror of
https://github.com/tiennm99/ccs.git
synced 2026-10-11 03:13:12 +00:00
fix(bar): resolve pre-dev review findings (security gate, honesty, correctness)
Gate /api/bar/* behind the localhost-when-auth-disabled guard (single DRY choke point) so native quota/tier/cost can't leak on a non-loopback bind with auth disabled; add a guard test. Delete the dishonest maxRedirections test that asserted the opposite of the production redirect hardening. Key per-account today-cost on the local day (matching analytics) instead of UTC. Stop the inner 429 retry in the Claude usage fetch so the outer cache + circuit breaker honor Retry-After. Narrow the usage-transformer map type and fix stale doc-comments; clarify the one-alert-per-reset-window quota rule; gitignore the local demo scaffolding.
This commit is contained in:
1 parent
ce98a69830
commit
7d3a11a452
13 files changed
+385
-81
No files matched your search
@@ -64,7 +64,7 @@ final class BarNotifier: NotificationDelivering {
|
||||
return
|
||||
}
|
||||
|
||||
// Already requested: post only when authorized; a denied state is a no-op.
|
||||
// Already requested: post when authorized or still-unknown; a denied state is a no-op.
|
||||
if authState == .authorized || authState == .unknown {
|
||||
post(notification, on: center)
|
||||
}
|
||||
|
||||
@@ -164,7 +164,7 @@ struct BarSubscriptionCard: View {
|
||||
/// Terse window label for the bar list, at most 4-5 chars:
|
||||
/// five_hour → "5h"
|
||||
/// seven_day → "wk"
|
||||
/// seven_day_opus → "Son" (sic — this is the Opus sub-budget inside the week)
|
||||
/// seven_day_opus → "Opus"
|
||||
/// seven_day_sonnet → "Son"
|
||||
///
|
||||
/// Fall back to the backend-supplied label truncated to 5 chars so unknown
|
||||
|
||||
@@ -147,6 +147,11 @@ public enum BarAlertEngine {
|
||||
let name = row.displayName ?? row.provider
|
||||
|
||||
// (1) quotaRemainingBelow — fire the SINGLE most-severe crossed level.
|
||||
// One alert per reset window (anti-spam): the fired-key embeds the reset
|
||||
// bucket (row.nextReset ?? "noreset" below), so once an account crosses a
|
||||
// level the alert is suppressed for the rest of that window even if quota
|
||||
// recovers and then drops again. It re-arms automatically when nextReset
|
||||
// rolls to a new window.
|
||||
if prefs.quotaEnabled, row.quotaStatus == "ok", let pct = row.quotaPercentage {
|
||||
let remaining = Int(pct.rounded())
|
||||
// levels sorted desc; the most-severe crossed level is the smallest L
|
||||
|
||||
Reference in new issue
Block a user