Fix bugs across app + server, optimize UI/UX, add Gitea CI
Bug fixes (Flutter): - Wrap multi-statement DB writes (insert/update/delete note, deleteDocument, deletePageData, OCR FTS merge, migrations) in transactions to prevent data loss on interruption and a read-modify-write FTS race. - Fix PdfDocument leaks on exception (try/finally dispose) and preserve image aspect ratio when stamping images onto PDF pages. - Guard file-picker against empty selection (was .single -> crash). - Fix eraser ConcurrentModificationError and unmodifiable-list crash on PDF pages; capture page synchronously on save to stop wrong-page data loss. - Fix Riverpod DB-not-ready races, broken pull-to-refresh, settings load race, and search N+1; transform stored annotations on PDF page rotation. - Normalize pen pressure for devices without a pressure range. - PPT: single source of truth for slide strokes so ink displays and exports. UI/UX: - Material 3 typography, theme-aware colors (dark-mode fixes), hover cursors and right-click/visible actions on desktop, keyboard shortcuts (undo/redo/ save/find), toolbar overflow handling, friendlier empty states, semantic OCR status badges, relative timestamps, 1-based page indicators, large-deck PPT navigation, and a scratchpad-scope label in split view. Server (optional backend): - Persist JWT secret (was per-process random), block path traversal in storage, fix CORS '*'+credentials, add OCR job ownership checks, last-writer-wins sync guard, constant-time login, and split out heavy OCR deps so the API/tests run without them. CI: Gitea workflows for format+analyze+test (Linux, system sqlite) and a Windows release build; pristine `flutter analyze`, all Flutter and server tests green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
55
server/badnote_server/main.py
Normal file
55
server/badnote_server/main.py
Normal file
@@ -0,0 +1,55 @@
|
||||
"""BadNote FastAPI server — main application."""
|
||||
|
||||
import os
|
||||
from contextlib import asynccontextmanager
|
||||
|
||||
from fastapi import FastAPI
|
||||
from fastapi.middleware.cors import CORSMiddleware
|
||||
|
||||
from .config import settings
|
||||
from .database import close_db, init_db
|
||||
from .routers.auth_router import router as auth_router
|
||||
from .routers.notes_router import router as notes_router
|
||||
from .routers.documents_router import router as documents_router
|
||||
from .routers.ocr_router import router as ocr_router
|
||||
from .routers.sync_router import router as sync_router
|
||||
|
||||
|
||||
@asynccontextmanager
|
||||
async def lifespan(app: FastAPI):
|
||||
"""Startup: create directories and init DB. Shutdown: close DB."""
|
||||
os.makedirs(settings.storage_path, exist_ok=True)
|
||||
for subdir in ("pending", "processing", "done", "failed"):
|
||||
os.makedirs(os.path.join(settings.queue_path, subdir), exist_ok=True)
|
||||
await init_db()
|
||||
yield
|
||||
await close_db()
|
||||
|
||||
|
||||
app = FastAPI(title="BadNote Server", version="1.0.0", lifespan=lifespan)
|
||||
|
||||
# Authentication is Bearer-token based, so cookies/credentials are not needed.
|
||||
# `allow_origins=["*"]` together with `allow_credentials=True` is an invalid and
|
||||
# insecure combination, so we keep credentials disabled. Set BADNOTE_CORS_ORIGINS
|
||||
# (comma-separated) to lock the API down to specific front-end origins.
|
||||
_cors_origins = settings.cors_origins or ["*"]
|
||||
|
||||
app.add_middleware(
|
||||
CORSMiddleware,
|
||||
allow_origins=_cors_origins,
|
||||
allow_credentials=False,
|
||||
allow_methods=["*"],
|
||||
allow_headers=["*"],
|
||||
)
|
||||
|
||||
app.include_router(auth_router, prefix="/api/auth", tags=["auth"])
|
||||
app.include_router(notes_router, prefix="/api/notes", tags=["notes"])
|
||||
app.include_router(documents_router, prefix="/api/documents", tags=["documents"])
|
||||
app.include_router(ocr_router, prefix="/api/ocr", tags=["ocr"])
|
||||
app.include_router(sync_router, prefix="/api/sync", tags=["sync"])
|
||||
|
||||
|
||||
@app.get("/api/ping")
|
||||
async def ping() -> dict:
|
||||
"""Health check endpoint."""
|
||||
return {"status": "ok"}
|
||||
Reference in New Issue
Block a user