dorfteich/apps/api/src
Claude Opus 4.8 fa7ae033b5
All checks were successful
CD / Build and push images (push) Successful in 2m58s
CI / Lint, typecheck, test (push) Successful in 1m55s
CI / Auth e2e pack (push) Successful in 2m25s
CI / Build container images (push) Has been skipped
CD / Deploy to Test (push) Successful in 9s
CD / Smoke tests against Test (push) Successful in 1m12s
CD / Promote to Int (push) Successful in 11s
Add permission-revocation handling for live and offline sessions (#39)
Revoking write access must terminate live sessions and let a user with
pending offline edits export them rather than lose them silently.

Backend (generic, reused by M5 grants #53):
- packages/shared: POND_ACCESS_CHANGED_CHANNEL, the LISTEN/NOTIFY channel
  shared by api and collab.
- api: PondAccessNotifier emits pg_notify(pond_access_changed, pondId) on
  a permission-relevant change; the single generic seam for revocation.
  Wired into pond soft-delete as the interim trigger (see==modify until
  #53).
- collab: a dedicated-connection LISTEN listener (LISTEN is connection-
  bound, not pooled) that, on a notification, closes every open connection
  to the pond's open pages. Clients then reconnect and the api re-issues a
  token reflecting current access (downgrade to ro, or 403/404). Reconnects
  and re-LISTENs if its connection drops.

Frontend:
- use-collab-provider: a refused token (403/404) on (re)connect sets
  accessRevoked and stops the reconnect loop; exposes discardLocal.
- AccessRevokedDialog: keeps local content visible and offers Markdown
  copy/download (derived from the live editor doc, so offline edits are
  included) and an explicit discard that clears IndexedDB. de+en strings.

Tests: collab DB-backed integration test proves a direct NOTIFY closes a
live session within seconds (AC1) and leaves unrelated ponds untouched;
listener unit tests; api test asserts soft-delete fires the notifier;
web test for the export Markdown derivation.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PGdhRiwU1WRL4XxJfZYipY
2026-07-09 07:01:46 +02:00
..
admin Add account/session endpoints and typed instance settings with admin API 2026-07-05 05:26:45 +02:00
auth Ponds: data model, CRUD API, personal pond on verification (#21) 2026-07-05 11:08:16 +02:00
common Add page trash: soft delete, restore, and purge job (#31) 2026-07-08 12:48:17 +02:00
config Add NestJS API skeleton with config, logging, and /healthz 2026-07-04 19:10:07 +02:00
files Add page trash: soft delete, restore, and purge job (#31) 2026-07-08 12:48:17 +02:00
health Add authentication: signup, verification, sessions, password reset 2026-07-05 05:22:31 +02:00
i18n Add mail outbox with SMTP delivery worker and templates 2026-07-05 00:46:12 +02:00
mail Add mail outbox with SMTP delivery worker and templates 2026-07-05 00:46:12 +02:00
pages Switch the editor to live collaboration (#36) 2026-07-08 18:00:19 +02:00
ponds Add permission-revocation handling for live and offline sessions (#39) 2026-07-09 07:01:46 +02:00
prisma Add Prisma with PostgreSQL, automatic migrations, and /readyz 2026-07-04 19:16:44 +02:00
quotas Quota foundation: overrides, resolution, race-safe consumption (#22) 2026-07-05 20:55:59 +02:00
rate-limit Add DB-backed rate limiting with guard and decorator 2026-07-05 00:43:54 +02:00
scheduler Add page trash: soft delete, restore, and purge job (#31) 2026-07-08 12:48:17 +02:00
settings Add page trash: soft delete, restore, and purge job (#31) 2026-07-08 12:48:17 +02:00
testing Add file storage service and image upload API (#27) 2026-07-08 10:35:03 +02:00
trash Switch the editor to live collaboration (#36) 2026-07-08 18:00:19 +02:00
users Add account/session endpoints and typed instance settings with admin API 2026-07-05 05:26:45 +02:00
app.module.ts Add page trash: soft delete, restore, and purge job (#31) 2026-07-08 12:48:17 +02:00
main.ts Add page CRUD and Yjs state persistence (#23) 2026-07-05 22:25:41 +02:00