Apply code-review fixes: identity/pagination, load races, TLS pin, leaks
Addresses a multi-agent code review (26 confirmed findings + a URLSession leak) across correctness, concurrency, security, and cleanup: - MongoDocument.id: deterministic fallback (was UUID() on every access) to stop SwiftUI List/ForEach identity churn; getAll pagination drives its cursor off the real _id via documentId, so a missing _id stops paging instead of looping on a fabricated cursor. - View models: per-load generation guard (+ captured-tab guard on ONU detail) so a cancelled or overlapping load can't commit stale results or land data on the wrong tab. - JSONValue.intValue: guard Int(d) against NaN/inf/out-of-range (crash). - ServerTrustEvaluator: hash the real SubjectPublicKeyInfo (prepend the algorithm-specific ASN.1 SPKI header) so a standard openssl-captured public-key pin actually matches; unknown key types fail closed. - AppEnvironment.configure: clear stale cookies + Keychain creds on host change. - FirmwareFile.isCompatible: empty metadata no longer passes as compatible-for-all. - APIClient: invalidate URLSession on deinit (per-configure/probe leak). - Dashboard best-effort sections keep last-good on transient failure; unified optical thresholds; LoginView prefill-once; populatedBuckets unique ForEach id; Format rounding rollover; dead-code/docstring/dedup cleanups. Verification pending on the Mac (no Swift toolchain on the Linux dev box). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
parent
8de962eeb8
commit
203465913c
21 changed files with 303 additions and 103 deletions
|
|
@ -13,17 +13,27 @@ final class OLTDetailViewModel {
|
|||
var isPerformingAction = false
|
||||
var actionMessage: String?
|
||||
|
||||
/// Bumped on every load; a load only commits if it's still the latest, so a
|
||||
/// stale/overlapping request (pull-to-refresh racing the .task) can't clobber
|
||||
/// newer results.
|
||||
private var loadGeneration = 0
|
||||
|
||||
init(connection: MCMSConnection, oltId: String) {
|
||||
self.connection = connection
|
||||
self.oltId = oltId
|
||||
}
|
||||
|
||||
func load() async {
|
||||
loadGeneration += 1
|
||||
let gen = loadGeneration
|
||||
phase = .loading
|
||||
do {
|
||||
olt = try await connection.olt.state(id: oltId)
|
||||
let fetched = try await connection.olt.state(id: oltId)
|
||||
guard gen == loadGeneration, !Task.isCancelled else { return }
|
||||
olt = fetched
|
||||
phase = .loaded
|
||||
} catch {
|
||||
guard gen == loadGeneration, !Task.isCancelled else { return }
|
||||
phase = .failed((error as? APIError)?.localizedDescription ?? error.localizedDescription)
|
||||
}
|
||||
}
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue