all: delete the code nothing calls
CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 8s
CI & Build / Python tests (push) Successful in 10s
CI & Build / integration (push) Failing after 1m21s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m47s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m48s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m39s
Desktop (Tauri) / Update manifest (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Successful in 8m37s
CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 8s
CI & Build / Python tests (push) Successful in 10s
CI & Build / integration (push) Failing after 1m21s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m47s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m48s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m39s
Desktop (Tauri) / Update manifest (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Successful in 8m37s
From the audit (#5178). Each was unreachable from every client: - Checklist add-item and delete-item: REST POST /items and DELETE /items/<id>, the Tauri commands, the store, rest and local adapters, the core's add_item/delete_item, set_item_text and remove_item, and the FFI exports. Adding, rewording and removing an item are body edits in every editor. The checked toggle stays, and its rewriter is simpler without the drop branch. - Manual unfurl: POST /unfurl and its adapters. Previews arrive in the background after a save (unfurl_queue). - The /api/config `android_client` key, android_release() and the APK_NAME/MANIFEST_NAME aliases. Phones poll /api/client/android. - users.email_verified and users.avatar_path (migration 0037). Nothing set the first or read the second; the SMTP reset never checked verification. - derive::extract_tags (only tests used it; the shared fixture now runs through extract_tag_spans), the unused check and link icons, and the unused editor_add_item string. - The blob scheme is renamed tsblob -> inkblob. URLs are built as notes are read, so nothing stored carries the old one. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -40,7 +40,6 @@
|
||||
<string name="editor_back">Back to notes</string>
|
||||
<string name="editor_add_checklist">Add a checklist</string>
|
||||
<string name="editor_body_hint">Take a note…</string>
|
||||
<string name="editor_add_item">Add item</string>
|
||||
<string name="editor_remove_item">Remove item</string>
|
||||
<string name="editor_remove_label">Remove tag</string>
|
||||
<string name="editor_reminder">Set a reminder</string>
|
||||
|
||||
+24
-87
@@ -224,53 +224,29 @@ impl Inkwell {
|
||||
}
|
||||
|
||||
// ──────────────────────────── checklist items ────────────────────────────
|
||||
//
|
||||
// Every one of these returns the whole reloaded note rather than the item it
|
||||
// touched. That is the core's shape, and it is the right one for a UI: ticking
|
||||
// a box changes `updated_at` and can change what the board shows, so handing
|
||||
// back only the item would leave Kotlin to guess at the rest.
|
||||
|
||||
pub fn add_item(&self, note_id: String, text: String) -> Result<Note, CoreError> {
|
||||
let conn = self.db.conn().map_err(CoreError::store)?;
|
||||
local::store::add_item(&conn, ¬e_id, &text)
|
||||
.map(Note::from)
|
||||
.map_err(CoreError::store)
|
||||
}
|
||||
|
||||
/// Retitle one item.
|
||||
/// Tick or untick one item. Adding, rewording and removing items are edits to
|
||||
/// the body, which the editor makes like any other.
|
||||
///
|
||||
/// Split from `set_item_checked` rather than exposing the core's
|
||||
/// `{text?, checked?}` patch, for the same reason `NoteEdit` exists: an
|
||||
/// optional-field struct cannot say "leave this alone" in Kotlin without
|
||||
/// colliding with "set it to null", and two unambiguous calls beat one
|
||||
/// ambiguous one when each is three lines.
|
||||
pub fn set_item_text(
|
||||
&self,
|
||||
note_id: String,
|
||||
item_id: String,
|
||||
text: String,
|
||||
) -> Result<Note, CoreError> {
|
||||
self.patch_item(¬e_id, &item_id, serde_json::json!({ "text": text }))
|
||||
}
|
||||
|
||||
/// Returns the whole reloaded note rather than the item it touched. That is the
|
||||
/// core's shape, and it is the right one for a UI: ticking a box changes
|
||||
/// `updated_at` and can change what the board shows, so handing back only the
|
||||
/// item would leave Kotlin to guess at the rest.
|
||||
pub fn set_item_checked(
|
||||
&self,
|
||||
note_id: String,
|
||||
item_id: String,
|
||||
checked: bool,
|
||||
) -> Result<Note, CoreError> {
|
||||
self.patch_item(
|
||||
let conn = self.db.conn().map_err(CoreError::store)?;
|
||||
local::store::update_item(
|
||||
&conn,
|
||||
¬e_id,
|
||||
&item_id,
|
||||
serde_json::json!({ "checked": checked }),
|
||||
&serde_json::json!({ "checked": checked }),
|
||||
)
|
||||
}
|
||||
|
||||
pub fn delete_item(&self, note_id: String, item_id: String) -> Result<Note, CoreError> {
|
||||
let conn = self.db.conn().map_err(CoreError::store)?;
|
||||
local::store::delete_item(&conn, ¬e_id, &item_id)
|
||||
.map(Note::from)
|
||||
.map_err(CoreError::store)
|
||||
.map(Note::from)
|
||||
.map_err(CoreError::store)
|
||||
}
|
||||
|
||||
// ─────────────────────────────── reminders ───────────────────────────────
|
||||
@@ -721,22 +697,6 @@ pub fn body_tags(body: String) -> Vec<BodyTag> {
|
||||
/// Helpers, deliberately NOT exported — uniffi only binds what an `#[uniffi::export]`
|
||||
/// block names, so these stay Rust-side.
|
||||
impl Inkwell {
|
||||
/// Apply a `{text}` or `{checked}` patch to one checklist item.
|
||||
///
|
||||
/// The two public setters differ only in the key they write, and the lock +
|
||||
/// convert + map-error dance around it is identical, so it lives once here.
|
||||
fn patch_item(
|
||||
&self,
|
||||
note_id: &str,
|
||||
item_id: &str,
|
||||
changes: serde_json::Value,
|
||||
) -> Result<Note, CoreError> {
|
||||
let conn = self.db.conn().map_err(CoreError::store)?;
|
||||
local::store::update_item(&conn, note_id, item_id, &changes)
|
||||
.map(Note::from)
|
||||
.map_err(CoreError::store)
|
||||
}
|
||||
|
||||
/// The server URL + token, or the `NotLinked` state. Every networked call needs
|
||||
/// exactly this, and none of them may hold the lock past it.
|
||||
fn credentials(&self) -> Result<(String, String), CoreError> {
|
||||
@@ -868,55 +828,32 @@ mod tests {
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
/// The editor's whole checklist loop, in one pass: add a row, tick it, retitle
|
||||
/// it, drop it. Each call returns the reloaded note, which is what the UI
|
||||
/// splices back into the board rather than re-querying.
|
||||
/// Ticking a box returns the reloaded note, which is what the UI splices back
|
||||
/// into the board rather than re-querying, and leaves the item's text alone.
|
||||
#[test]
|
||||
fn checklist_items_can_be_added_ticked_retitled_and_removed() {
|
||||
fn ticking_an_item_rewrites_only_its_box() {
|
||||
let dir = scratch_dir();
|
||||
let app = Inkwell::new(dir.clone()).expect("a fresh data dir should open");
|
||||
let note = app
|
||||
.create_note(NoteDraft {
|
||||
body: "Packing".to_string(),
|
||||
items: Some(vec!["socks".to_string()]),
|
||||
items: Some(vec!["socks".to_string(), "charger".to_string()]),
|
||||
})
|
||||
.expect("create");
|
||||
assert_eq!(note.items.len(), 1);
|
||||
assert_eq!(note.items.len(), 2);
|
||||
|
||||
let with_two = app
|
||||
.add_item(note.id.clone(), "charger".to_string())
|
||||
.expect("add");
|
||||
assert_eq!(with_two.items.len(), 2);
|
||||
// Appended, not prepended — a new row belongs at the bottom of the list the
|
||||
// user is looking at.
|
||||
assert_eq!(with_two.items[1].text, "charger");
|
||||
|
||||
let item_id = with_two.items[1].id.clone();
|
||||
let item_id = note.items[1].id.clone();
|
||||
let ticked = app
|
||||
.set_item_checked(note.id.clone(), item_id.clone(), true)
|
||||
.expect("tick");
|
||||
assert!(ticked.items[1].checked);
|
||||
assert_eq!(
|
||||
ticked.items[1].text, "charger",
|
||||
"ticking a box must not disturb its text — both setters rewrite the \
|
||||
same line of the body now, so one clobbering the other is a live risk \
|
||||
rather than a theoretical one"
|
||||
);
|
||||
assert!(!ticked.items[0].checked);
|
||||
assert_eq!(ticked.items[1].text, "charger");
|
||||
|
||||
let renamed = app
|
||||
.set_item_text(note.id.clone(), item_id.clone(), "usb-c cable".to_string())
|
||||
.expect("rename");
|
||||
assert_eq!(renamed.items[1].text, "usb-c cable");
|
||||
assert!(
|
||||
renamed.items[1].checked,
|
||||
"and the same in the other direction"
|
||||
);
|
||||
|
||||
let trimmed = app
|
||||
.delete_item(note.id.clone(), item_id)
|
||||
.expect("delete item");
|
||||
assert_eq!(trimmed.items.len(), 1);
|
||||
assert_eq!(trimmed.items[0].text, "socks");
|
||||
let unticked = app
|
||||
.set_item_checked(note.id.clone(), item_id, false)
|
||||
.expect("untick");
|
||||
assert_eq!(unticked.body, note.body);
|
||||
|
||||
std::fs::remove_dir_all(&dir).ok();
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user