Files
rplace/plans/260510-0232-fix-do-migration-followups/plan.md
T
tiennm99 3c1263add6 fix(canvas): make multi-chunk pixel writes atomic and refund cooldown on failure
- wrap writePixels in state.storage.transactionSync so a partial multi-chunk
  failure doesn't leave the canvas half-written or out of sync with the WS
  broadcast
- size new chunk buffer against chunkSize(chunkId) instead of the persisted
  blob's length so writes after a canvas-grow no longer silently drop OOB
  bytes in the formerly-last short chunk
- refund the cooldown row when writePixels throws so transient storage
  errors stop soft-DOSing the user (and halving image-uploader throughput)
- bound readAllChunks by chunk_id < CHUNK_COUNT and trim oversized blobs so
  orphan rows from a future shrink no longer crash GET /api/canvas
- require a positive Content-Length on /api/place (411) and reject above the
  pre-parse cap (413); previously a missing or zero header bypassed the cap
- drop String(err) from the 500 response body
- drain the INSERT cursor symmetrically with the UPDATE branch in tryAcquire
- assert CHUNK_BYTES <= 2 MB at module load (DO SQLite per-cell BLOB cap)
- correct the inverted webSocketClose comment and guard the re-close call
- add tests for missing / zero / oversized Content-Length

Plan: plans/260510-0232-fix-do-migration-followups/phase-01-do-storage-atomicity.md
2026-05-10 02:57:30 +07:00

3.3 KiB
Raw Blame History

title, status, priority, created, phases, source, sourceReports, blockedBy, blocks
title status priority created phases source sourceReports blockedBy blocks
Fix critical bugs and security gaps from DO migration code review in-progress P1 2026-05-10 5 skill
../reports/code-reviewer-260510-0211-rplace-do-migration.md
../reports/debugger-260510-0211-rplace-edge-cases.md
../reports/docs-manager-260510-0211-rplace-docs-drift.md

Plan: Fix DO Migration Code-Review Follow-ups

Goal

Close the 3 Critical + 5 High findings from the post-migration triple-review (code-reviewer, debugger, docs-manager). Add full DO surface test coverage. Scrub stale Upstash references from README.md and .env.example.

Decisions Locked (from validation Q&A)

  • Identity: Cookie + IP fallback. Issue opaque per-browser cookie on first /api/canvas; rate-limit by cookie when present, fall back to IP otherwise.
  • Daily pixel cap: Deferred to a follow-up plan (product input needed).
  • Test scope: Full DO surface coverage (chunk-storage, cooldown-store, WS hub, get-user-id, integration).

Phases

# File Title Status Priority Blocks
1 phase-01-do-storage-atomicity.md DO storage atomicity & correctness pending P1 4
2 phase-02-cookie-ip-identity.md Cookie+IP identity & broadcast sequence pending P1 4
3 phase-03-ws-hardening-client-race.md WebSocket hardening & client race fix pending P1 4
4 phase-04-do-surface-tests.md Full DO surface test coverage pending P2 —
5 phase-05-docs-cleanup.md Docs cleanup & legacy plan archival pending P2 —

Phases 1, 2, 3 are independent and can ship in any order or in parallel. Phase 4 depends on the API surfaces stabilized in 1–3. Phase 5 is independent — can land first.

Findings Coverage Map

Phase Critical High Medium
1 C2 (review C3 BLOB-grow), C2 (debugger atomicity), C1 (debugger cooldown burn) review-H1, H2, H3, H5 review-M1
2 C3 (debugger NAT) debugger-H2, H3 review-M4
3 C2 (review WS race) review-H4, debugger-H5 review-M2, M3, M7
4 — L7 test gap —
5 C1 (review stale docs) — —

Out of Scope

  • Per-IP daily pixel quota (deferred per Q&A).
  • Edge-cache strategy change (s-maxage tuning) — needs product call on live-fresh vs cheap.
  • Multi-room sharding (idFromName('main') stays single-DO).
  • Signed cookie / HMAC identity — opaque cookie is sufficient for this round.

Success Criteria

  • All listed Critical + High findings resolved with file:line citations in PR description.
  • npm test passes; new DO tests cover write atomicity, BLOB-grow, cooldown refund, WS hub, identity.
  • README + .env.example purged of Upstash refs; docs/ verified accurate.
  • Production deploy + 24h soak shows no new error class in CF logs.
  • Migration plan 260509-2309-canvas-on-do-storage/plan.md marked status: completed.
  • plans/reports/code-reviewer-260510-0211-rplace-do-migration.md
  • plans/reports/debugger-260510-0211-rplace-edge-cases.md
  • plans/reports/docs-manager-260510-0211-rplace-docs-drift.md