mirror of
https://github.com/tiennm99/rplace.git
synced 2026-10-11 03:13:48 +00:00
- wrap writePixels in state.storage.transactionSync so a partial multi-chunk failure doesn't leave the canvas half-written or out of sync with the WS broadcast - size new chunk buffer against chunkSize(chunkId) instead of the persisted blob's length so writes after a canvas-grow no longer silently drop OOB bytes in the formerly-last short chunk - refund the cooldown row when writePixels throws so transient storage errors stop soft-DOSing the user (and halving image-uploader throughput) - bound readAllChunks by chunk_id < CHUNK_COUNT and trim oversized blobs so orphan rows from a future shrink no longer crash GET /api/canvas - require a positive Content-Length on /api/place (411) and reject above the pre-parse cap (413); previously a missing or zero header bypassed the cap - drop String(err) from the 500 response body - drain the INSERT cursor symmetrically with the UPDATE branch in tryAcquire - assert CHUNK_BYTES <= 2 MB at module load (DO SQLite per-cell BLOB cap) - correct the inverted webSocketClose comment and guard the re-close call - add tests for missing / zero / oversized Content-Length Plan: plans/260510-0232-fix-do-migration-followups/phase-01-do-storage-atomicity.md
3.3 KiB
3.3 KiB
title, status, priority, created, phases, source, sourceReports, blockedBy, blocks
| title | status | priority | created | phases | source | sourceReports | blockedBy | blocks | |||
|---|---|---|---|---|---|---|---|---|---|---|---|
| Fix critical bugs and security gaps from DO migration code review | in-progress | P1 | 2026-05-10 | 5 | skill |
|
Plan: Fix DO Migration Code-Review Follow-ups
Goal
Close the 3 Critical + 5 High findings from the post-migration triple-review (code-reviewer, debugger, docs-manager). Add full DO surface test coverage. Scrub stale Upstash references from README.md and .env.example.
Decisions Locked (from validation Q&A)
- Identity: Cookie + IP fallback. Issue opaque per-browser cookie on first
/api/canvas; rate-limit by cookie when present, fall back to IP otherwise. - Daily pixel cap: Deferred to a follow-up plan (product input needed).
- Test scope: Full DO surface coverage (chunk-storage, cooldown-store, WS hub, get-user-id, integration).
Phases
| # | File | Title | Status | Priority | Blocks |
|---|---|---|---|---|---|
| 1 | phase-01-do-storage-atomicity.md | DO storage atomicity & correctness | pending | P1 | 4 |
| 2 | phase-02-cookie-ip-identity.md | Cookie+IP identity & broadcast sequence | pending | P1 | 4 |
| 3 | phase-03-ws-hardening-client-race.md | WebSocket hardening & client race fix | pending | P1 | 4 |
| 4 | phase-04-do-surface-tests.md | Full DO surface test coverage | pending | P2 | — |
| 5 | phase-05-docs-cleanup.md | Docs cleanup & legacy plan archival | pending | P2 | — |
Phases 1, 2, 3 are independent and can ship in any order or in parallel. Phase 4 depends on the API surfaces stabilized in 1–3. Phase 5 is independent — can land first.
Findings Coverage Map
| Phase | Critical | High | Medium |
|---|---|---|---|
| 1 | C2 (review C3 BLOB-grow), C2 (debugger atomicity), C1 (debugger cooldown burn) | review-H1, H2, H3, H5 | review-M1 |
| 2 | C3 (debugger NAT) | debugger-H2, H3 | review-M4 |
| 3 | C2 (review WS race) | review-H4, debugger-H5 | review-M2, M3, M7 |
| 4 | — | L7 test gap | — |
| 5 | C1 (review stale docs) | — | — |
Out of Scope
- Per-IP daily pixel quota (deferred per Q&A).
- Edge-cache strategy change (
s-maxagetuning) — needs product call on live-fresh vs cheap. - Multi-room sharding (
idFromName('main')stays single-DO). - Signed cookie / HMAC identity — opaque cookie is sufficient for this round.
Success Criteria
- All listed Critical + High findings resolved with file:line citations in PR description.
npm testpasses; new DO tests cover write atomicity, BLOB-grow, cooldown refund, WS hub, identity.- README +
.env.examplepurged of Upstash refs; docs/ verified accurate. - Production deploy + 24h soak shows no new error class in CF logs.
- Migration plan
260509-2309-canvas-on-do-storage/plan.mdmarkedstatus: completed.
Related Reports
plans/reports/code-reviewer-260510-0211-rplace-do-migration.mdplans/reports/debugger-260510-0211-rplace-edge-cases.mdplans/reports/docs-manager-260510-0211-rplace-docs-drift.md