Fix #391: visibility save hardening #392
No reviewers
Labels
No labels
actions
bug
cli
duplicate
enhancement
fork
forum
git storage
help wanted
insights
invalid
issues
moderation
oidc
ownership transfer
packages
pr/merge protection rules
projects
pull requests
question
releases
sponsorships
tags
webhooks
wiki
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
crueber/walhub!392
Loading…
Reference in a new issue
No description provided.
Delete branch "fix/issue-391"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Follow-up to #381: the visibility select still bounced after save. The #381 HTTP-cache explanation no longer covers it (#382/#384/#385 moved every surface off stale-serve), so this instruments first and fixes the failure path with evidence.
Root cause (evidence, not inference). One-line access GET/PUT outcome logs added (internal/identity/access.go GetAccess source/version/visibility at Debug; routeAccess GET denied/error at Info, PUT denied/conflict/error/success with version-in → version-out at Info — e.g.
identity: access PUT conflict repo=acme/repo have=0 current=1). New handler-level evidence tests (internal/identity/access_visibility_391_test.go) run the real HTTP path against real memory + filesystem backends and show:So candidates #3 (store conditional staleness) and #4 (multi-instance disagreement) do NOT reproduce on these backend classes — the store contract suite pins the If-None-Match mapping they depend on. The defect is candidates #1+#2: the old Settings saveVisibility caught 403/409 into a small note and LEFT the user's chosen value in the select; the next refresh reseeded server truth = the bounce.
Fix.
Tests. Go: 3 new tests x2 backends, -race, count=5 clean; identity coverage 95.4% (gate holds); store contract suite green; gofmt/vet/build clean. Node: 7 new access-save tests + full unit suite 764/766 (2 failures are the pre-existing smoke dist-build tests, identical on clean main). No new deps. S3 rig skipped (not quick); S3 unsigned-header path unchanged, now contract-documented.