Full-codebase review turned up five real correctness/security bugs and
a dozen smaller inconsistencies; all are fixed here with matching test
coverage:
- BMK uniqueness silently allowed German-umlaut duplicates ("Ä1" vs
"ä1") because the DB's normalized index only folds ASCII case. Added
a shared Unicode-aware pre-check used by every circuit/component
insert and rename path (one of which had no pre-check at all).
- CircuitDeviceRow.simultaneityFactor had no upper bound at the row
level (command model and snapshot/restore schema), unlike every
sibling entity, letting a bad value silently corrupt power totals.
- Grid cell editing silently misread German thousands-separator input
("1.500" parsed as 1.5); "." is now rejected outright with a clear
message instead of guessing.
- The editor's shared command runner (runCommand/applyHistory) had no
re-entrancy guard, so a double click/drop could fire the same
command twice and race a BMK collision or revision conflict. Added a
synchronous ref guard plus isSaving on the buttons that lacked it.
- GET .../next-identifier leaked circuit-numbering state for sections
in other projects (no ownership check, 400 instead of 404). Moved
under /projects/:projectId and scoped it.
Also: added the missing circuits.section_id / circuit_device_rows.
circuit_id indexes (migration 0006), gave FormModal a focus trap /
Escape-to-close / focus restore and rebuilt ProjectSettingsModal on
top of it instead of duplicated markup, removed dead code (3 orphaned
domain model files, an unused persistence helper, a wrapper only used
by its own test), pointed the project page at GET /projects/:id
instead of listing+filtering client-side, closed the gap between the
documented 18 MB CSV limit and the ~17.17 MiB actually enforced, added
missing upper bounds on several free-text fields, filled in nine
missing German labels in the revision timeline, replaced a
key-order-fragile JSON.stringify equality check with a real field
comparison, made an implicit sort-order assumption in three
renumbering helpers explicit, cleared the sidebar's target selection
when it no longer resolves after a tree reload, and fixed
updateGlobalDevice to check-then-write instead of write-then-check.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
41 lines
1.6 KiB
TypeScript
41 lines
1.6 KiB
TypeScript
import { eq } from "drizzle-orm";
|
|
import type { AppDatabase } from "../database-context.js";
|
|
import { circuitListEquipmentIdentifiers } from "../schema/circuit-list-equipment-identifiers.js";
|
|
|
|
export function normalizeEquipmentIdentifier(value: string): string {
|
|
return value.trim().toLowerCase();
|
|
}
|
|
|
|
/**
|
|
* The DB-level normalized unique index uses SQLite's built-in lower(),
|
|
* which only folds ASCII a-z and leaves German characters (Ä/Ö/Ü/ß/…)
|
|
* untouched, so it alone would let e.g. "Ä1" and "ä1" coexist. This check
|
|
* normalizes with JS's Unicode-aware toLowerCase() against every
|
|
* identifier already registered for the circuit list (circuits and
|
|
* distribution-board components share one BMK namespace via
|
|
* circuit_list_equipment_identifiers), catching what the DB index cannot.
|
|
*/
|
|
export function assertEquipmentIdentifierAvailable(
|
|
database: AppDatabase,
|
|
circuitListId: string,
|
|
equipmentIdentifier: string,
|
|
excludeOwnerId?: string
|
|
): void {
|
|
const candidate = normalizeEquipmentIdentifier(equipmentIdentifier);
|
|
const existing = database
|
|
.select({
|
|
ownerId: circuitListEquipmentIdentifiers.ownerId,
|
|
equipmentIdentifier: circuitListEquipmentIdentifiers.equipmentIdentifier,
|
|
})
|
|
.from(circuitListEquipmentIdentifiers)
|
|
.where(eq(circuitListEquipmentIdentifiers.circuitListId, circuitListId))
|
|
.all();
|
|
const duplicate = existing.some(
|
|
(row) =>
|
|
row.ownerId !== excludeOwnerId &&
|
|
normalizeEquipmentIdentifier(row.equipmentIdentifier) === candidate
|
|
);
|
|
if (duplicate) {
|
|
throw new Error("Duplicate equipmentIdentifier in circuit list.");
|
|
}
|
|
}
|