all: delete the code nothing calls
CI & Build / Python lint (push) Successful in 2s
CI & Build / Build now, or wait for Android? (push) Successful in 2s
Android / Build, or is the channel already serving this? (push) Successful in 3s
Desktop (Tauri) / Build, or is the channel already serving this? (push) Successful in 2s
CI & Build / Web typecheck and unit tests (push) Successful in 8s
CI & Build / Python tests (push) Successful in 10s
CI & Build / integration (push) Failing after 1m21s
CI & Build / Build & push image (push) Skipped
Desktop (Tauri) / Web tests, clippy, Rust tests and rustfmt (push) Successful in 2m47s
Desktop (Tauri) / Windows installer (cross-compiled) (push) Successful in 2m48s
Desktop (Tauri) / Tauri desktop (Linux) (push) Successful in 3m39s
Desktop (Tauri) / Update manifest (push) Successful in 3s
Android / Kotlin + Rust (APK) (push) Successful in 8m37s

From the audit (#5178). Each was unreachable from every client:

- Checklist add-item and delete-item: REST POST /items and DELETE /items/<id>,
  the Tauri commands, the store, rest and local adapters, the core's
  add_item/delete_item, set_item_text and remove_item, and the FFI exports.
  Adding, rewording and removing an item are body edits in every editor. The
  checked toggle stays, and its rewriter is simpler without the drop branch.
- Manual unfurl: POST /unfurl and its adapters. Previews arrive in the
  background after a save (unfurl_queue).
- The /api/config `android_client` key, android_release() and the
  APK_NAME/MANIFEST_NAME aliases. Phones poll /api/client/android.
- users.email_verified and users.avatar_path (migration 0037). Nothing set
  the first or read the second; the SMTP reset never checked verification.
- derive::extract_tags (only tests used it; the shared fixture now runs
  through extract_tag_spans), the unused check and link icons, and the
  unused editor_add_item string.
- The blob scheme is renamed tsblob -> inkblob. URLs are built as notes are
  read, so nothing stored carries the old one.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-07 19:00:44 -04:00
co-authored by Claude Opus 5.5
parent fd1d50662f
commit 7eacd0569c
26 changed files with 159 additions and 491 deletions
-13
View File
@@ -48,7 +48,6 @@ pub fn auth_me() -> User {
id: "local".to_string(),
email: "local@inkwell.app".to_string(),
display_name: "You".to_string(),
email_verified: true,
is_admin: false,
}
}
@@ -99,12 +98,6 @@ pub fn notes_set_labels(
store::set_labels(&conn, &id, &label_ids).map_err(|e| e.to_string())
}
#[tauri::command]
pub fn notes_add_item(id: String, text: String, db: State<'_, Db>) -> Result<Note, String> {
let conn = db.0.lock().map_err(|e| e.to_string())?;
store::add_item(&conn, &id, &text).map_err(|e| e.to_string())
}
#[tauri::command]
pub fn notes_update_item(
id: String,
@@ -116,12 +109,6 @@ pub fn notes_update_item(
store::update_item(&conn, &id, &item_id, &changes).map_err(|e| e.to_string())
}
#[tauri::command]
pub fn notes_delete_item(id: String, item_id: String, db: State<'_, Db>) -> Result<Note, String> {
let conn = db.0.lock().map_err(|e| e.to_string())?;
store::delete_item(&conn, &id, &item_id).map_err(|e| e.to_string())
}
/// Attach a file to a note, online or not (#5168).
///
/// The file's bytes are the raw IPC body — a JSON number array would be several
-2
View File
@@ -180,9 +180,7 @@ pub fn run() {
commands::local::notes_complete_reminder,
commands::local::notes_snooze_reminder,
commands::local::notes_set_labels,
commands::local::notes_add_item,
commands::local::notes_update_item,
commands::local::notes_delete_item,
commands::local::notes_add_attachment,
commands::local::notes_export,
commands::local::notes_import,