Repository navigation
Commit f0c1157
Fix two security holes, two data-loss bugs, and the cost leak
Pre-release review by three reviewers. Most of what they found was mine.
SECURITY (rules deployed)
`allow update` only checked that coupleId was UNCHANGED, never that the
record was yours — the other three verbs check ownership and this one
didn't. Any member knowing a document id could rewrite, cancel or
unschedule another couple's date. Reads being blocked made ids hard to
guess, which is obscurity, not a boundary.
onlyMyMemory() treated `after == null` as "memories untouched", but that
is also what nulling or deleting the field looks like. Either partner
could erase the other's rating with one field, which is the whole of
rate-blind-then-reveal. A create can no longer arrive pre-loaded with a
rating in the partner's name either.
DATA LOSS
"never mind" in the rating editor restored from `item.memory` — the
deprecated single-memory field that nothing writes any more. It reset to
empty, and the next save overwrote a real rating with blanks. Restores
from `mine` now.
The editor was also seeded once at mount, and this component is memoised
and keyed by id, so it survives every snapshot: rate a date on your
phone and an open card on your laptop still held the old values, ready
to write them back over the newer rating. It re-seeds when opened.
WRONG BEHAVIOUR
A date happening TODAY counted as past from midnight — it offered "we
went" and sat under "how did it go?" instead of "next up". The countdown
even had an unreachable branch that rendered the word "today", which is
what tipped the reviewer off that this was a slip rather than a choice.
Signing out terminated the Firestore client, and that instance is a
module singleton created once at import. Signing back in without a
reload hit a dead client and failed every read and write. Now reloads.
"Later" on the update pill destroyed the prompt rather than deferring
it: workbox only fires `waiting` when a NEW worker arrives, so a worker
already parked never announced itself again — the exact
stranded-on-an-old-build case that component exists to prevent.
The overflow sheet's last row, delete, sat under the iPhone home
indicator inside its swipe-up region. EditSheet already handled this.
COST
`photos` was requested on every Place Details lookup and the resulting
photoUrl was never rendered anywhere — a higher billing tier for a field
with no reader. Details are also cached per place per session: every tap
on a map POI fired a fresh billable lookup with no dedupe, so tapping
the same café three times while deciding cost three of them.
The map re-framed itself to fit all pins on every Firestore emission
rather than once per mount, throwing you away from the pin you had just
added. The multi-date card claimed to scroll but its parent disabled
pointer events, so any place with enough dates silently truncated.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>1 parent fe78744 commit f0c1157
11 files changed
Lines changed: 2380 additions & 18 deletions
File tree
- design_handoff_nct127
- src
- components
- lib
- screens
Large diffs are not rendered by default.
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
Large diffs are not rendered by default.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
34 | | - | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
35 | 39 | | |
36 | | - | |
37 | | - | |
38 | | - | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
39 | 45 | | |
40 | 46 | | |
41 | 47 | | |
| |||
55 | 61 | | |
56 | 62 | | |
57 | 63 | | |
58 | | - | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
59 | 68 | | |
60 | 69 | | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
61 | 75 | | |
62 | 76 | | |
63 | | - | |
| 77 | + | |
64 | 78 | | |
65 | 79 | | |
66 | 80 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
60 | 60 | | |
61 | 61 | | |
62 | 62 | | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
63 | 79 | | |
64 | 80 | | |
65 | 81 | | |
| |||
82 | 98 | | |
83 | 99 | | |
84 | 100 | | |
85 | | - | |
| 101 | + | |
86 | 102 | | |
87 | 103 | | |
88 | 104 | | |
| |||
345 | 361 | | |
346 | 362 | | |
347 | 363 | | |
348 | | - | |
| 364 | + | |
349 | 365 | | |
350 | 366 | | |
351 | 367 | | |
| |||
459 | 475 | | |
460 | 476 | | |
461 | 477 | | |
462 | | - | |
463 | | - | |
| 478 | + | |
| 479 | + | |
| 480 | + | |
| 481 | + | |
| 482 | + | |
| 483 | + | |
464 | 484 | | |
465 | 485 | | |
466 | 486 | | |
| |||
484 | 504 | | |
485 | 505 | | |
486 | 506 | | |
487 | | - | |
| 507 | + | |
| 508 | + | |
| 509 | + | |
| 510 | + | |
488 | 511 | | |
489 | 512 | | |
490 | 513 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | | - | |
| 1 | + | |
2 | 2 | | |
3 | 3 | | |
4 | 4 | | |
| |||
92 | 92 | | |
93 | 93 | | |
94 | 94 | | |
| 95 | + | |
95 | 96 | | |
96 | 97 | | |
97 | 98 | | |
98 | 99 | | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
99 | 106 | | |
100 | 107 | | |
101 | 108 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
28 | 33 | | |
29 | 34 | | |
30 | 35 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
57 | 57 | | |
58 | 58 | | |
59 | 59 | | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
60 | 65 | | |
61 | 66 | | |
62 | 67 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3 | 3 | | |
4 | 4 | | |
5 | 5 | | |
6 | | - | |
7 | | - | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
8 | 18 | | |
9 | 19 | | |
10 | 20 | | |
11 | 21 | | |
12 | 22 | | |
13 | | - | |
14 | 23 | | |
15 | 24 | | |
16 | 25 | | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
17 | 37 | | |
18 | 38 | | |
19 | 39 | | |
| |||
26 | 46 | | |
27 | 47 | | |
28 | 48 | | |
29 | | - | |
| 49 | + | |
| 50 | + | |
30 | 51 | | |
31 | 52 | | |
32 | 53 | | |
| |||
40 | 61 | | |
41 | 62 | | |
42 | 63 | | |
| 64 | + | |
| 65 | + | |
43 | 66 | | |
44 | 67 | | |
45 | 68 | | |
46 | | - | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
47 | 72 | | |
48 | 73 | | |
49 | 74 | | |
| |||
0 commit comments